Main Menu
Home
Bookmark
Contact Us



 
Harrier.460 Viruses Information

Name: Harrier.460
Category: Viruses
Description: Details
Harrier.4602

It is not a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. The virus infects the files with the length less than 57K, while infecting EXE files the virus converts them to COM format. The virus also encrypts a random selected block within files while infecting them.
The virus does not infect the files: COMMAND.COM, IBMBIO.COM, IBMDOS.COM. While executing the programs AIDS*.*, WEB*.*, ADINF*.*, DRWEB*.* the virus terminates execution and displays one of the messages:
Program too big to fit in memory
Division by 0
Error in EXE file
Memory allocation error!
Bad command or file name
Cannot load COMMAND.COM . . .
Internal stack overflow!
Incorrect DOS version
This program requires Microsoft Windows.

While infecting a file the virus hooks INT 1, 3 (debugger) and uses these interrupts in its anti-debugging routines. The virus also hooks INT 8 (timer) and on each 256th tick checks CRC sum of its code. In case of wrong CRC sum the virus reboots the computer.
While installing memory resident the virus with probability 1/8 hooks INT 17h and while printing a text replaces it with the message:
Hey, Ugly User, You could be my . . .
I promise You! Death to all CHAINIKS!!!
Cause I am Harrier from DarkLand . . .

If a file is executed with command line starting with "@@", the virus displays the string:
(c) 1996y by TechnoRat "HDL" GenNo:

followed with the number of virus generation.
The virus overwrites the MBR of the hard drive with a program that depending on the system timer displays the message:
I am the ¦ DARKLAND is the
- - +-+ --+ --+ - --+ --+ ¦ kingdom of Hackers
¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦
+-¦ +-¦ +-+ +-+ ¦ +- +-+ ¦ I come from darkall
¦ ¦ ¦ ¦ ¦++ ¦++ ¦ ¦ ¦++ ¦ I invade Your PC...
- - - - - - - - - --+ - - ¦ I am Your death...
from DARKLAND ¦

The virus also contains the text strings:
.COM.EXECOMMANDIBMBIOIBMDOSAIDSWEBADINFDRWEBALLE:WP
?VirMON-I-Virus has been installed successfully!
?VirMON-W-execution 0 error!
(C)reated by HARD WISDOM!!! (hacker)



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
TEH.64
Glemp.87
Sentinel Famil
Macro.Word.Slo
Rape.188
Yosha.44
Telstra.110
Solar.9
Backdoor.FTP.Casus.1
Judgement.39


 


© 2006-2008 spyware32.com - Privacy Policy