Main Menu
Home
Bookmark
Contact Us



 
Urphin.162 Viruses Information

Name: Urphin.162
Category: Viruses
Description: Details
Urphin.1621

It is not a dangerous memory resident parasitic virus. It hooks INT 21h, 28h and writes itself to the end of COM and EXE files. It infects EXE files that are executed. COM files get infection only on FindNext ASCII DOS call and only on a floppy drive. The virus does not infect the files: *AI?.*, *WEB?.*, *ES?.*, *RA?.*.
When the TPC.EXE file is executed (TurboPascal compiler), the virus also intercepts .PAS files opening (Pascal source files), searches for "BEGIN" line in these files (subroutine header) and writes to there its hexadecimal dump with necessary Pascal instructions. When .PAS files are closed, the virus removes its hex-dump from Pascal source files. As a result, when source Pascal files are being compiled, the virus inserts its code into these files, and the result executable files become the virus droppers.
The virus contains the text strings:
BEGINbegin
URPHIN
ASM
END;



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Darek.43
Hiperion.15
Slovakia.105
Backdoor.Nethie
Winsurf.Skim.145
DogPaw.72
AWME.121
F1.33
XEP.135
Pusher.37


 


© 2006-2008 spyware32.com - Privacy Policy