Main Menu
Home
Bookmark
Contact Us



 
Jerusalem. Viruses Information

Name: Jerusalem.
Category: Viruses
Description: Details
Jerusalem.a

Jerusalem family.
This virus hooks INT 9, 16h, and 21h. Upon a 'warm' reboot (Alt-Ctrl-Del), according to the current time, the virus decrypts (XOR AFh) and displays the following text:
The world will hear from me again!

Depending on the date, it corrects the text entered from a keyboard. If a user types "fu manchu", the virus adds "virus 3/10/88 - latest in the new fun line!". If a user types "thatcher", "reagan", "botha" or "waldheim", the virus adds some rude words: "thatcher is a #@$&*", "reagan is an @$$%$##", "botha is a &%$#@#$%", "waldheim is a $%#@&*". When entering the unflattering words, the virus erases them from the screen.
Jeru.Math
"Jerusalem" family. On Fridays, it also hooks INT 9 (keyboard), and when Alt-Ctrl-Del keys are struck, it runs itself with a video effect. It also contains the text string:
sUMATHS

Jeru.Miky.2350
This is a dangerous virus that hooks INT 8, 16h, and 21h, and infects .COM and .EXE files. It sets the disk label to 'Miky', shifts the screen and displays:
MIKY 786290 B livia

Jeru.Plastique
"Jerusalem" family. These viruses hook INT 8, 9, 13h, and 21h, and erase the contents of the logical drives when file ACAD.EXE is started. Then they play a tune, and slow down the computer (delay loop in INT 8 handler). On the 4000th key entered on a keyboard, the virus erases one randomly selected sector on the current disk.
These viruses contain the encrypted strings:
ACAD.EXECOMMAND.COM.COM.EXE
Program: Plastique 4.51 (plastic bomb), Copyright (C) 1988, 1989 by ABT Group.Thanks to: Mr. Lin (IECS 762??), Mr. Cheng (FCU Inf-Center)
Jeru.Raquel
This is a variant of the "Jeru.Plastique" virus. Depending on its internal counter, it erases the CMOS memory. It contains the encrypted text:
Copyright (C) 1988, 1989 by ABT Group
Virus RAQUEL v.9 (c) IMV Galicia '94

Jeru.Roger
"Jerusalem" family. This is a benign virus. On the 11th and 23th of any month, it hooks INT 13h, and displays the following message:
+------------------------------------+
| ROGER ESPEJO M. |
| Telef. 45-1838 |
| Lima - Per£ |
+------------------------------------+

Taiwan.2576,3088
"Jerusalem" family. "Taiwan.2576" is dangerous - as ACAD.EXE is executed, the virus overwrites this file with the text (see below), and then deletes this file. The text is:
To Whom see this: Shit! As you can see this document, you may know what this program is. But I must tell you: DO NOT TRY to WRITE ANY ANTI-PROGRAM to THIS VIRUS.This is a test-program, the real dangerous code will implement on November. I use MASM to generate varius virus easily and you must use DEBUG aginst my virus hardly, that is foolish. Save your time until next month. OK? Your Sincerely, ABT Group., Oct 13th, 1989 at FCU.
This virus also contains the text "ACAD.EXECOMMAND.COM", and plays a tune.
"Taiwan.3088 and 3454" contain the text:
To Whom see this: Shit! As you can see this document, you may know what this program is. But I must tell you: DO NOT TRY to WRITE ANY VACCINE against THIS VIRUS.This is a test-program, the real dangerous code (combines Disk Killer & Dark Friday) will be implemented before long.I use MASM to generate various virus easily and it is vain to DEBUG my virus, it is a fool to do that. You(S.I.R) will try to challenge to me?, you are stupid to do this.Your Sincerely, ABT Group., Lee. S.W. Oct 13th, 1989 at FCU. PS: 1. To FCU Info-Center, Please update new carbon ink belt. 2. Fuck you Mechanic Eng., do not speak so loudly in the Computer Lab. 3. Confound you, Mr.President, I wish you go to Hell ! ============= , and anotherall Endanger declaraction : This is a hacker who want to rule the computer technology as the Golden game rule, namely, everyone who frunk me is a "son of bitch". How can teacher do such crue thing as to hurt a timid soul and taking this as funny play-game.
Taiwan.2900
"Jerusalem" family. It hooks INT 8,9,13h,16h, and 21h, and infects files that are executed or opened.
When the ACAD.EXE file is executed, the virus erases information on all available disks. Approximately once a month, after about 10 hours of uninterrupted operation, the virus plays a rather a dull tune. If at this time one presses Alt-Ctrl-Del, then the same effect as upon executing ACAD.EXE occurrs.
The virus contains the encrypted strings:
ACAD.EXE
COMMAND.COM.COM.EXE
Copyright (C) 1988, 1989 by ABT Group

Tobacco.2900
"Jerusalem" family. It hooks INT 8,9,13h,16h, and 21h, and runs itself in the same way as "Taiwan.2900". This virus contains the strings:
ACAD.EXE COMMAND.COM.COM.EXE Copyright (C) 1988, 1989 by ABT Group
Tobacco v2
AntiDacha. We don't want gypsies in our world. We don't want DACHAs.
1991 2nd Tabacalera gana siempre. Tobacco Ver. 2.0

"Jerusalem.Tobacco.c" contains the strings:
Virus RAQUEL vK&S (c) IMV Galicia '95.
Exercito Guerrilheiro forever Id Software are the Best.
Buy DOOM2:Hell on Earth.
Take my Tobacco box! CLRG loves danger. 3rd

Totoro.1536
"Jerusalem" family. On Saturday, it hooks INT 8 (timer), and sometimes displays the message:
+----------------------+
| Totoro Dragon |
|Hello! I am TOTORO CAT|
| Written by Y.T.J.C.T |
| in Ping Tung. TAIWAN |
| Don't Worry,be Happy |
+----------------------+



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
PL0006.48
Matura.162
Macro.Word.Chil
Jd Famil
Airwalker.38
Storm.115
I-Worm.Ivali
Backdoor.RA-base
TypoBoo
Rajaat.14


 


© 2006-2008 spyware32.com - Privacy Policy