Main Menu
Home
Bookmark
Contact Us



 
8ball. Viruses Information

Name: 8ball.
Category: Viruses
Description: Details
8ball.a

It is not a dangerous memory resident multipartite virus. While executing an infected file the virus copies itself into HMA, hooks INT 40h, and then overwrites boot sectors of the floppy disks. While loading from an infected disk the virus hooks INT 1Ah, waits for DOS loading, and hooks INT 21h. On first call to INT 21h the virus creates on C: drive the file with a random selected name, and writes the virus copy to that file. Then the virus adds the string:
INSTALL=C:
to the end of the C:CONFIG.SYS file. As a result while loading from infected C: drive the virus receives the control in the infected file. After infection the virus restores INT 21h (removes itself from the memory).
The virus uses anti-debugging tricks, performs some commands with keyboard ports, contains the text strings:
PK
INSTALL=C:c:config.sys
8_Ball -=Q=-



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Linux.Winte
Trojan.NetPatc
Game Famil
CriCri.461
Slovakia.II.3584.
Macro.Word.Fhd.
MemEate
Trojan.JS.Seeke
Win32.Sin
Hippie.


 


© 2006-2008 spyware32.com - Privacy Policy