Main Menu
Home
Bookmark
Contact Us



 
Bombe Viruses Information

Name: Bombe
Category: Viruses
Description: Details
Bomber

It's a harmless memory resident polymorphic virus. It hooks INT 21h and infects COM-file except COMMAND.COM on their running. It contains the internal text messages "COMMANDER BOMBER WAS HERE" and "[DAME]".
The characteristic feature of this infector consist of a new polymorphic algorithm. Upon infection the virus reads 4096 bytes from the random selected offset and writes this code at the and of the file. Then it writes into this 'hole' its code and starts to polymorphism. This virus contains several subroutines which generate the random (but successfully executed!) code. TRhe virus inserts those parts of random code into the random chosen position into the host file. About 90% of all the i8086 instructions are present in those parts. The part of code takes the control from the previous part by JMP, CALL, RET, RET xxxx instructions. The first part is inserted into the file beginning and jumps to next part, the next part jumps the third etc. The last part returns control to the main virus body. At the end the infected file looks like at 'spots' of inserted code.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Zmt.25
Win.VfW.98
Comvirus.321.
Win32.Henky.Rotten.140
Beethove
Nop.35
Win32.Benny.3219.
Staf.208
I-Worm.Troo
Geek.45


 


© 2006-2008 spyware32.com - Privacy Policy