zorm.643.
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Zorm.643.a
These are not dangerous nonmemory resident parasitic encrypted viruses. They searches executable files, then write themselves to the end of the file.
Zorm.643 and 648 infect EXE files only, Zorm.1123 infects both COM and EXE files. Zorm.1123 deletes the antivirus database files:
ANTI-VIR.DAT, CHKLIST.MS, CHKLIST.CPS.
The viruses do not manifest themselves in any other way, they contain the text strings:
"Zorm.643,648": (c)zorm-a,from dr L.
"Zorm.1123": (c)Zorm-b by Dr.L
Zorm.1404
This virus infects COM and EXE files that are executed. On file creating it also creates the file dropper WIN.GPF in the current directory, and appends to the end of the AUTOEXEC.BAT file the instructions that rename this file to A.COM, and execute the A.COM file.
The virus contains the text strings:
KZorm-c01 (c) DrL. From France.July/December 98
I hate holidays,Marie M comes back!
Zorm.1863
---------
It is an encrypted and stealth parasitic virus. It contains the strings:
KZorm-d1.8 (c) DrL. From France.FEB 99
AVP dont forget to send money for what you know!
Copyright @2006 zorm.643.