Main Menu
Home
Bookmark
Contact Us



 
CmosDead famil Viruses Information

Name: CmosDead famil
Category: Viruses
Description: Details
CmosDead family

These are very dangerous memory resident parasitic polymorphic and stealth viruses. They trace and hook INT 21h, stay memory resident and then write themselves to the end of COM and EXE files that are accessed. The viruses do not infect the anti-virus programs and several utilities:
AVG SYS SCAN CLEAN WIN TBAV PROT GUARD VS 286 386 DSK

When CHKDSK is run, the viruses disable their stealth routines. In some cases when listed above programs are executed, the viruses display the message and disable executing:
I don't like this program !

The viruses use anti-debug tricks. Under debugger they display the message and halt the computer:
BE CAREFUL !

Depending on their internal counters the viruses hook INT 9 (keyboard), corrupt the CMOS, display the message:
GRISOFT(c) SOFTWARE 1989,96

and manifest themselves with a video effect. If Ctrl-Alt-Del keys are pressed during effect, the viruses call disk formatting BIOS routine.
In some cases the viruses call the same effect routine, then they overwrite the MBR of the hard drive with a program that displays on booting:
CMOS-DEAD: DATA DESTROYED !

The viruses also contain the text string:
Hello Mr. Odehnal !

as well as:
"Odehnal.4792": EXECOM12/19/91
"Odehnal.5154": EXECOM06/12/95



Top Viruses Visited Pages:
Invader. - 231 visits
not-a-virus:RiskWare.Tool.RegPatch. - 69 visits
Worm.P2P.Harex. - 63 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 55 visits
Small.58. - 55 visits
Coito.64 - 53 visits
I-Worm.Mapson. - 45 visits
Win16.Klon.1177 - 41 visits
Win32.Hidra - 41 visits
Marine.500 - 34 visits

Random Viruses Pages:
Macro.Word.Dud
I-Worm.Shatri
Search.30
Mobius.23
Worm.Win32.Doomjuice.
Worm.P2P.Sddrop.
StoneHeart.149
SadFace.84
HLLP.Nover.771
TrojanDownloader.Win32.Ultimx.


 


© 2006-2008 spyware32.com - Privacy Policy