Main Menu
Home
Bookmark
Contact Us



 
Hero.39 Viruses Information

Name: Hero.39
Category: Viruses
Description: Details
Hero.394

These are not dangerous memory resident parasitic viruses. They copy themselves to the Interrupt Vectors Table at the address 0000:0200, hook INT 21h, and write themselves to the end of the files that are executed.
"Hero.394" infects only EXE files, "Hero.506" infects both EXE and COM files. As a read/write buffer these viruses use video memory.
While setting Interrupt Vector (INT 21h, AH=25h) with a number greater than 7Fh, "Hero.506" disinfects itself in the memory.
On the 1st of any month these viruses decrypts and display the following messages in Russian: "GLORY TO HEROES!" or "The author of the virus is a cretin" depending on the version of the virus.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Fgt.65
I-Worm.Navida
WMA.67
Macro.Word.Junk.
Trojan.PSW.Logmod.
LX.199
Froll.166
Win32.HLLW.Bezilo
Macro.Word.T
I-Worm.Mimail.


 


© 2006-2008 spyware32.com - Privacy Policy