Main Menu
Home
Bookmark
Contact Us



 
Kaczor.4444. Viruses Information

Name: Kaczor.4444.
Category: Viruses
Description: Details
Kaczor.4444.a

It is not a dangerous memory resident polymorphic stealth multipartite virus. It traces and hooks INT 13h, 21h and writes itself to the MBR of the hard drive and to EXE files that are accessed on the floppy disks. On accessing to the infected files on the hard drive the virus disinfects them.
While installing memory resident from infected hard drive the virus also temporary hooks INT 12h, 1Ch. On DOS loading it cuts the block of system memory, hooks INT 13h, 21h and resets INT 12h, 1Ch.
That virus is encrypted in memory as well as in the files. The INT 13h, 21h handlers decrypt the code of subroutines before processing them, and then encrypt before return to the original interrupt handlers.
On loading if the keyboard buffer contains the word "kaczor" the virus disinfects MBR and displays:
Zrobione.

If the keyboard buffer contains the word "test", the virus displays the message:
Wersjaall.......
Kodowanie.......
Licznik HD......

and adds corresponding numbers to the ends of these strings.
On March, 3rd the virus hooks INT 8 (timer) and "shakes" the screen.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Luce.462
Trojan.Win32.AnnoyingSave
Damir.87
Frida.53
Macro.Word.Sido
I-Worm.Mimail.
HH.1024.
Die_Lamer.109
Azatoth.99
Macro.Word97.GoodLuck-base


 


© 2006-2008 spyware32.com - Privacy Policy