Main Menu
Home
Bookmark
Contact Us



 
Crazy.140 Viruses Information

Name: Crazy.140
Category: Viruses
Description: Details
Crazy.1402

These are harmless memory-resident stealth viruses that infect COM-files as a program is terminated (the Exit and Keep DOS functions), files are being searched (FindFirst and FindNext) or a file is closed. The viruses decreases the memory area allocated for DOS (the word at the address 0000:0413). They hook 12 DOS functions and use stealth mechanism: recover infected files as they are accessed. Upon installation the viruses create in RAM two own copies: operational and backup ones. On every call to the 1Ch interrupt (Timer Tick) "Crazy" viruses write their backup copies at the address of its operational copies and in such a way gets rid of debuggers. The viruses hook INT 1Ch, 21h and contain the text:
"Crazy.1402" - Crazy imp. v1.5
"Crazy.1445" - Crazy imp. v2.0



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.Word97.NightShad
Claire.82
BootExe.Stalker.31
VirTool.Macro.Word.Dem
Rael.321
Deathrider.72
Zaneto.176
Rape.74
ScreenMixer.107
Mini.60.


 


© 2006-2008 spyware32.com - Privacy Policy