|
|
Bebe.48 Viruses Information
| Name: |
Bebe.48 |
| Category: |
Viruses |
| Description:
|
Details
Bebe.486
These are nonresident dangerous viruses. They affect .COM-files in the current directory. They increase the size of infected file up to a paragraph, copy themselves at the file end and alter its first 14 bytes (PUSH AX; all ; JMP FAR Loc_Virus ). The viruses have an error - doesn't restore DTA. This might result in hanging up the computer. There is one more delicate error: they doesn't take into account that INTEL 80x80 processor has a conveyer, and modifies the command following the current one, the result is that the viruses work only on old IBM PC models. Apart from the above text the viruses contain the string "*.COM".
The viruses are nonresident, but they create a small memory-resident program. With this purpose they copy a part of viruses' body to the interrupt vector table at the address 0000:01CE and sets INT 1Ch or INT 21h to this program.
"Bebe.486" hooks INT 21h and while writing into file (INT 21h, f.40h) it changes '+' to '-' and '-' to '+' in buffer is writing.
"Bebe.1004" hooks INT 1Ch (timer) and some time later displays the following message:
+-------- VIRUS ! ------+
ƒ Skagi "bebe" > ƒ
+-----------------------+
After the word "bebe" is typed in from the keyboard, the virus answers: "Fig Tebe !". |
Top Viruses Visited Pages:
Invader. - 231 visits
not-a-virus:RiskWare.Tool.RegPatch. - 69 visits
Worm.P2P.Harex. - 63 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 55 visits
Small.58. - 55 visits
Coito.64 - 53 visits
I-Worm.Mapson. - 45 visits
Win32.Hidra - 41 visits
Win16.Klon.1177 - 40 visits
Marine.500 - 34 visits
Random Viruses Pages:
Joshi.
Vesna Famil
Svir.51
Macro.Word.Hade
Carnivore.50
Macro.Word97.Groovi
Ungame Famil
DSME.Apex.268
ExeBug.
Win32.Weir
|
|