Main Menu
Home
Bookmark
Contact Us



 
Zohra.416 Viruses Information

Name: Zohra.416
Category: Viruses
Description: Details
Zohra.4160

These are not dangerous memory resident parasitic polymorphic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed. They do not infect files, if file name contains one of sub-strings: TB, AV, SC, IV (TBAV, AVP, NAV, SCAN, all). The viruses also remove themselves from memory if WIN.EXE file is executed and "hide" their TSR code when MEM.EXE is executed.
The viruses use quite complex way to get original address of INT 21h handler - they disassemble code of INT 21h handlers up to the original handler in DOS kernel.
On April 14th the viruses display the message:
Zohra will live forever ! Necromancy with her...

They also contain the text:
[Zohra] virus by Wintermute/29A, dedicated to the best Necromancer of the
Forgotten Realms,... I assure you will live forever, my love... ;)



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.Word97.Claud.
Trojan.Win32.Xombe.
Doperland.49
Vesna.1614.
Macro.Word97.Anthra
Macro.Word.Shado
Riot.Dial.152
Exploit.HTML.ObjDat
Line.90
4Seasons.153


 


© 2006-2008 spyware32.com - Privacy Policy