Main Menu
Home
Bookmark
Contact Us



 
Mbd.125 Viruses Information

Name: Mbd.125
Category: Viruses
Description: Details
Mbd.1258

These are not dangerous memory resident encrypted parasitic viruses. They hook INT 8, 21h and write themselves to the end of COM and EXE files that are executed. The viruses do not infect the files: DRWE*, AIDS*, AV*, ADIN*, COMM* (DRWEB, AIDSTEST, AVP, ADINF, COMMAND.COM).
The virus TSR copy occupies just 232 bytes of the memory - while installing memory resident the virus saves its complete code to reserved hard drive sectors (on zero track) and reads that code from there in case of need (on infecting). The virus leaves its TSR copy (INT 8 and INT 21h handlers) in DOS data area at address 0060:0000. As a result, the virus is active, but it does not occupy conventional memory and it is not visible by any memory browser.
Depending on their internal counters the viruses dial the phone number 02 (police line in Russia) or 113. The viruses contain the text string:
Virus-MENT, v1.0 (C) MBD Poccuu. XI.1996 #

"Mbd.1317" has several strings in Russian, "Mbd.1258" contains they translated to English:
# HELLO, POLICE ! I`M, DIRTY USER, HAVE STEAL BILLY`S WINDOWS !
# POLICE OF THE WORLD, HANDS OFF FROM CYBERSPACE !



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Mal famil
Jesus Famil
Inch Famil
Comsysexe Famil
Tchantches.330
VirDem.46
GD.53
Realize.49
Macro.Word97.Unha
Hider.216


 


© 2006-2008 spyware32.com - Privacy Policy