Main Menu
Home
Bookmark
Contact Us



 
Weak.125 Viruses Information

Name: Weak.125
Category: Viruses
Description: Details
Weak.1253

Weak.1253 is a memory resident dangerous parasitic stealth virus. It is compressed by utility PKLITE and after installation it reads its compressed body, saves it in memory and then uses while infection. The virus writes itself into file beginning when the file is created (when file is copied): the virus hooks DOS function Create, creates the file, writes into file the virus body and then returns to DOS. Then DOS appends the file to virus body. Therefore it is not necessary to check INT 24h, the file' date, time and attributes.
While access to file the virus uses the stealth algorithm: it hooks DOS function Lseek (ah=42h) and corrects the read/write pointer so that file looks like a clear. The virus also hooks DOS functions FindFirst and FindNext ASCII and correct the returned length of infected file. But the virus not checks the FCB Find functions and can break some utilities.
During installation into the system memory the virus uses the legal method - int 27h. The virus also corrects the Environment area: sets the owner name to COMMAND.COM. With this method the virus hides itself in memory. It also hooks INT 21h, 22h, 23h, 24h.
The virus contains the text: "Et tu vulneratus es sicut et nos, nostri similis effectus esall".



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Saboteur.139
Macro.Excel.Sof
Backdoor.Executor.
Dura
Dragon
I-Worm.Energy.
Worm.Linux.Rame
Macro.Word97.Dreams.
MtE.Coffeesho
Xing.130


 


© 2006-2008 spyware32.com - Privacy Policy