Main Menu
Home
Bookmark
Contact Us



 
QPHS.293 Viruses Information

Name: QPHS.293
Category: Viruses
Description: Details
QPHS.2931

It is not a dangerous memory resident multipartite virus. While executing an infected file the virus infects the MBR of the hard drive, hooks INT 9, 13h, 21h and stays memory resident. While infecting the hard drive the virus encrypts the original Partition Table. On reading the MBR the virus calls the stealth routine and returns the Partition Table in its original form.
While loading from infected MBR the virus hooks INT 8, 9, 12h, 13h, waits for DOS loading, and then hooks INT 21h. The virus uses INT 12h to hide itself in the system memory during the DOS installation procedure.
By hooking INT 21h the virus intercepts COM and EXE files opening, execution and searching. The virus writes itself to the end of the files on A: and B: drives only, and disinfects the infected files on other disks.
The virus pays special attention to the execution of LOGIN.EXE file, and saves the command line and entered from keyboard symbols during execution of LOGIN.EXE. By using that trick the virus allows to intercept login commands (user names and passwords).
The virus intercepts the symbols entered from keyboard. On entering the "QPHS" string the virus display the intercepted login commands. On entering the "PERFECT" string the virus disinfects itself in the MBR of the hard drive.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Einstein.87
Executioner famil
Gorb.467
Fire.268
Artem.216
Mantra.71
Win95.Powerfu
Macro.Word97.Trojan.Thie
Airwalker.38
Macro.Word.Nuclear.


 


© 2006-2008 spyware32.com - Privacy Policy