Main Menu
Home
Bookmark
Contact Us



 
Coup.2052. Viruses Information

Name: Coup.2052.
Category: Viruses
Description: Details
Coup.2052.b

This is very dangerous memory resident multipartite virus. When an infected file is executed, the virus infects the MBR of the hard drive and then returns to DOS. While loading from infected MBR the virus cuts a block of the system memory, copies itself to there, hooks INT 13h, 1Ch and returns control to the original MBR code.
By hooking INT 13h the virus realizes a stealth routine while accessing to the infected MBR. By hooking INT 1Ch (timer) the virus waits for DOS loading process, hooks INT 21h and then writes itself to the end of .COM and .EXE files (except COMMAND.COM) that are executed. The virus checks the file names and corrupts several anti-virus scanners: SCAN, MSAV, PART*, CLEAN, VSAFE, TOOLKIT, GUARD, FINDVIRU. The virus overwrites them with a trojan program that displays the message:
If you are boy,go and play ball !!
Otherwise,Our "Blind Date" every day in "4-Bagh" at 6-9(pm).



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
HH&HH.433
Win32.Eta
MonteCarlo Famil
I-Worm.Tosse
BAT.Batalia
Zombie.ZCME.1638
Andryushka.353
BAT.Tus.168
Backdoor.Win32.Agobot.ab
Macro.Word97.Alej


 


© 2006-2008 spyware32.com - Privacy Policy