Main Menu
Home
Bookmark
Contact Us



 
UVR.391 Viruses Information

Name: UVR.391
Category: Viruses
Description: Details
UVR.3919

It's a dangerous memory resident parasitic virus. On execution of infected file it writes the string
C:UVR.COM

at the beginning of C:AUTOEXEC.BAT file. Then the virus creates C:UVR.COM file and writes itself into there. On execution of that dropper file (i.e. on loading with modified AUTOEXEC.BAT) the virus hooks INT 21h and writes itself at the end of COM-files are executed or opened.
On execution of dropper file under already infected system, the virus displays:
UVR Already installed.

Before infection the virus disinfect the files infected with some parasitic viruses. If some program tries disinfect the file infected with "UVR" virus, it drops "Trivial.59" overwriting virus into the C:PORNO file. The virus deletes the files *.CPS and *._NO on accessing to them. It also creates the file C:C:__ with two strings inside:
[Note "_" = ASCII 251]
Hai sbagliato!
-U.Vr-

On March, 19th the virus displays:
+-------------------+
¦ Vietato FUMARE! ¦
+-------------------+

then it hooks INT 10h and manifests itself with different video effects: on displaying the text strings it changes the case of characters, changes the cursor characteristics, and so on.
That virus contains the encrypted internal strings also:
- U.Vr, Professional version -
Non riuscirai MAI a sapere tutto quello che sono in grado di fare
MARZO 1993



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
I-Worm.Plexus.
I-Worm.Netsky.
BR.118
Macro.Word97.Beauty.
I-Worm.Mimail.
Win32.HLLP.Mince
Shoe.190
Galeocerdo.60
Pojer.402
Mutator Famil


 


© 2006-2008 spyware32.com - Privacy Policy