Main Menu
Home
Bookmark
Contact Us



 
XPEH Famil Viruses Information

Name: XPEH Famil
Category: Viruses
Description: Details
XPEH Family

These are very dangerous (except for the harmless "XPEH.3600") memory resident parasitic viruses. They trace INT 21h, hook INT 1Ch and 21h, and then write themselves to the end of COM, EXE, OVL files that are loaded into the memory or accessed by DOS functions FindFirst/Next ASCII.
The viruses are encrypted by a quite complex algorithm. They also use an error-correcting code (see Yankee viruses). The viruses "XPEH.3872 and 4048" write the texts "XPEH" to the address 0000:0004 (INT 1) and "????" to 0000:000C (INT 3). Since September 1991 (for "XPEH.3872"), or since December 1991 (for "XPEH.4048"), the viruses have encrypted .BAK, .TXT, and .LEX files - their data is XORed with the word "XPEH".
The "XPEH.4768" virus emulates the DIR command. For this purpose, it contains the following strings:
Directory of
File(s)
bytes free


If the current day coincides with the current month (January,1, February,2, etc.), this virus wipes out all data on the C: disk, displaying in advance the following message in Russian: "If you have a hard drive indicator and it is on, hard disk formatting is going to the end. Best wishes!".
"XPEH.5840" writes the byte C3h (RET) to the beginning of the *SAFE.* files. This virus also contain a text in Russia: "Because a work getting the producing new XPEHs is paused for some time. 1991- MFTI(77)". MFTI is Moscow Physical and Technical Institute.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Jerk.107
Warblade.105
Ohlala Famil
Ph33
Raubkopie.221
Writer.133
Steatoda famil
Indi
Macro.Word97.Typ
Die_Lamer.109


 


© 2006-2008 spyware32.com - Privacy Policy