Search:       

Saturday, 17 May 2008       

Billiard.265 Spyware/Adware Definition


Name: Billiard.265
Category: Viruses
Description: Details
Billiard.2658

It is not a dangerous memory resident partly encrypted parasitic virus. When an infected program is executed, the virus decrypts its encrypted block of code by using INT 1 (tracing) tricks, hooks INT 9 (keyboard) and stays memory resident. On INT 9 calls the virus releases INT 9 and hooks 2Fh. On INT 2Fh calls the virus releases INT 2Fh and hooks INT 9 (as a result at any moment the virus hooks either INT 9 or INT 2Fh).
On INT 2Fh calls the virus also intercepts the INSTALLATION CHECK (AX=AE00h) command that is executed when a copy of COMMAND.COM processor is run, checks the command line, and if command line begins with "DIR" string the virus searches for .COM amd .EXE files and writes itself to the end of the file. While working DIR command the virus temporary hooks INT 21h and "decreases" the length of infected files when they are accessed by FindFirst/Next DOS functions.
On 31st of months the virus manifests itself by a video effect - it runs the symbols on the screen like playing billiard.


Top Viruses Visited Pages:
ECW.57
Gorgan.271
Gorill
Guerilla.199
HLLP.Nover.771
Holiday Famil
HS.90
Hydra_II Famil
I-Worm.Mimail.
I-Worm.MyLife.
I-Worm.MyLife.
I-Worm.Sobig.
Ice Famil
IDEA.612
Imi.1536.

 


Main Menu
Home
Top Downloads
New Programs
Awards
Submit
Link to us
Spyware Definitions
Viruses Info
Recipes
Jokes
Contact us



Partners
Softs Land
Hotel Reservations
Computer Articles
Viruses Info
Free Downloads
Data Recovery Shareware Downloads Free Articles
Cooks Recipes
Download Programs
Windows Drivers
MySpace Generators

Check PageRank

 

 

- Privacy Policy -