|
|
|
|
ADI.143 Spyware/Adware Definition
| Name: |
ADI.143 |
| Category: |
Viruses |
| Description:
|
Details
ADI.1431
These are dangerous memory resident encrypted parasitic viruses. They write themselves to the end of COM files. While infecting a file the viruses encrypt not only its code, but whole contents of the file. The viruses have bugs and may halt the system while infecting a file.
When an infected file is executed, the virus decrypts itself, hooks INT 22h (DOS Terminate call), returns control to the host program, waits for termination call, then hooks INT 8, 1Ch, 21h, 24h. Timer interrupts (INT 8, 1Ch) are used by the virus to disable tracing and debugging. INT 21h is used to intercept access to COM files.
The viruses use several levels of anti-debugging tricks, they also contain the text string:
(c) Beast. Advanced Disk Infector. [ADinf v1.5] |
|
Top Viruses Visited Pages:
Macro.Word.Ord
Parity.44
Pathhunt.123
Perfume Famil
Permutan.54
Phantasmagori
Pieck.201
Ply.422
PME.Burglar.326
Poem.182
Polifemo Famil
Populizer Famil
Potpis.69
Predator.115
PrintDevil.71
|
|