Main Menu
Home
Bookmark
Contact Us



 
TenBytes.141 Viruses Information

Name: TenBytes.141
Category: Viruses
Description: Details
TenBytes.1411

This is a dangerous, memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are loaded into the memory. While infecting COM files, the virus writes the 32-byte Jmp-Virus routine to the beginning of the file. In infected EXE files, there are two possible variants of the entry offset in the virus code.
The virus activates only when the interrupt handler contains the word FC80h (this condition is always met if INT 21h points in DOS to the original system handler). Then the virus patches the first five bytes of the INT 21h handler with JMP FAR Loc_Virus instruction, copies itself to the system memory at the address 9800:0000, and does not fix the MCB list. This might halt the computer. The virus also hooks INT 1 and 3, and disables the debugger.
Starting from September 1st, while writing to the disk (INT 21h,AH=40h), the virus changes the address of the data buffer, and as a result, corrupts the data that is saved on the disk.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.Word97.Christ
MzBoot.46
Pifpaf.76
Rajaat.51
Email-Worm.Win32.Doombot.
Hera.120
HooDoo.261
Zerobug.153
Experiment.41
Search.30


 


© 2006-2008 spyware32.com - Privacy Policy