| Description:
|
Details
VLAD.Hemlock.3183
It's not dangerous memory resident polymorphic stealth multipartite virus. It hooks INT 9, 13h, 21h and writes itself at the end of COM-, EXE, and SYS-files are accessed. On execution of infected files it hits MBR of hard drive. On accessing to floppy disks it overwrites their boot sectors.
On Alt-Ctr-Del it emulates rebooting and stays memory resident. On execution of some programs it disables its stealth routine. It contains the internal text strings:
TBSCAN WIN CHKDSK PKZIP ARJ NDD SCANDISK LHA
co nm /d:f
Hemlock by [qark/VLAD]
OSDATA
VLAD.MegaStealth
It's a not dangerous memory resident stealth multipartite virus. It hooks INT 13h, 21h, 76h and writes itself at the end of .COM-files, MBR of hard and floppy boot sectors are accessed. It displays '¯' character on each INT 21h calls. Interrupts 13h, 76h are used by stealth routine. It contains the internal test string:
[MegaStealth] by qark/VLAD |