Main Menu
Home
Bookmark
Contact Us



 
Kiuca famil Viruses Information

Name: Kiuca famil
Category: Viruses
Description: Details
Kiuca family

These are harmless memory resident multipartite viruses. They infect COM and EXE files as well as the boot sector of C: drive. When an infected file is executed, the viruses infect the hard drive - they write their code and the original boot sector of C: disk to the track/head 0/0 on the hard drive and overwrite the C: disk boot sector with their loading routine.
While loading from infected hard drive the virus copies itself to the top of system memory, hooks INT 1Ch, waits for DOS loading process, then hooks INT 21h and when any program is executed, completes installation routine - allocates a blocks of DOS memory and copies itself to there. As a result the virus does not decreases the total size of DOS memory, but places itself between DOS kernel and COMMAND.COM. The virus then writes itself to the end of COM and EXE files that are created and then closed.
The virus several tricks to avoid detection by integrity (CRC) checker. It infects only newly created files, or files that are restored from archives of backup, as a result there is no information about these files in CRC databases. To hide infected boot sector the virus disinfects it when any program (including anti-viruses) is executed, and re-infects on termination. As a result the disk boot sector is infected only when there are no programs in the system memory.
The virus contains the text strings in Russian and English:
(c) Light General.Kiev.KIUCA.1996.NOT for free use.



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.Word.Alie
Tver.30
Cuareim.80
TempVir.46
Macro.Word.KillSystem.
Macro.Word.FunFu
Trojan-Spy.HTML.Smitfraud.
Synergy.28
Gkchp.800.
Arale.152


 


© 2006-2008 spyware32.com - Privacy Policy