Main Menu
Home
Bookmark
Contact Us



 
Necropoli Viruses Information

Name: Necropoli
Category: Viruses
Description: Details
Necropolis

This is a dangerous memory resident stealth parasitic virus. It traces INT 13h, 21h, hooks INT 21h and then writes itself to the beginning of COM files and to the middle of EXE files (between the header of EXE file and the module body) when these files are accessed:
COM file EXE file
+-------+ +-------+ +--------+ +--------+
¦ ¦--+ ¦Virus ¦ ¦Header ¦ ¦Header ¦
¦- - - -¦ ¦ +-------¦ +--------¦ +--------¦
¦ ¦ ¦ ¦ ¦ ¦ ¦--+ ¦Virus ¦
¦ ¦ ¦ ¦ ¦ ¦- - - - ¦ ¦ +--------¦
+-------+ ¦ ¦- - - -¦ +--------+ ¦ ¦- - - - ¦
+->¦ ¦ +->¦ ¦
+-------+ +--------+

This virus uses the algorithm of the "Beast" virus: it writes a part of the file being saved to the free sectors of the last cluster of the file, and the file length does not grow.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
GraveLion.225
AEP.62
Svin.Boo
Worm.Qa
I-Worm.Chet.
Terminator.349
I-Worm.LoveLette
Holiday Famil
Win95.Ariann
Uracil.48


 


© 2006-2008 spyware32.com - Privacy Policy