Virus Protection > computer-virus-y-page1 > - yosha dos viruse

yosha dos viruse

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
Yosha DOS viruses

Yosha.745
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. This virus deletes the anti-virus data files CHKLIST.MS, ANTI-VIR.DAT if they exist. The virus also creates the C:\WIN.COM file and writes a program to there, this program only displays the message:
Windoze crashes your system.

The virus also contains the text strings:
Kein Mehrheit fr die Mitleid
KMFDM by Yosha/DC

Yosha.975,980
These are dangerous memory resident encrypted parasitic stealth viruses. They hook INT 8, 21h and write themselves to the end of COM files that are executed or closed. While opening an infected file, or loading a file for debugging, the virus disinfects it. While deleting any file the virus also deletes the ANTI-VIR.DAT file, if it exists. On creating a file the virus searches for the MSCD000 file (Microsoft CD?) in the current directory, and if that file exist, the virus in some way manipulates with CD driver (ejects a disk?) and displays the message:
Give Yosha cold Mountain Dew!

By hooking INT 8 the virus keeps the INT 21h handler pointing to the virus code. The virus also contains the text:
[Dew-Bug] (C) 1996 Yosha/DC

Yosha.LT
It is a dangerous memory resident parasitic virus. It copies itself into Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM files on reading/writing to/from them. While infecting the virus uses quite complex way to access System Files Table and may corrupt the files. The virus contains the text string:
Malaria by Yosha/LT

Yosha.MDK
It is a very dangerous encrypted memory resident overwriting virus. It copies its TSR copy to the DOS data area, hooks INT 21h and overwrites files that are executed. Depending on the system timer the virus also erases random selected sector on disks. The virus contains the text strings:
Murder-Death-Kill by Yosha/tCS/DC

Yosha.Smegma
It is a harmless memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed, opened or accessed with Get/Set File Attribute DOS call. The virus does not manifest itself, it contains the text string:
[Smegma] by Yosha

Yosha.Stercor
It is not a dangerous memory resident companion stealth virus. It hooks INT 21h and infects .EXE files - it creates companion .COM files when .EXE files are accessed (executed, opened, renamed, deleted, accessed by Get/Set Attribute DOS call). Stealth: on FindFirst/Next DOS calls "skips" infected COM files. Depending on the system timer the virus manifest itself by a video effect. The virus contains the text string:
Stercor by Yosha[LT/RSA]

Yosha.Zadig
It is a harmless memory resident polymorphic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. While infecting the virus writes the JMP_Virus instruction not to the file header, but into the middle of the file. To select address to write JMP_Virus code the virus loads file and traces it by using INT 1 hook.
The virus contains the text:
Zadig by Yosha[LT]

Updated: 02/24/2006
Copyright @2006 yosha dos viruse
Webroot Software Inc.