Virus Database


I-Worm.Bagle.ah

Description I-Worm.Bagle.ah

This worm is almost identical to I-Worm.Bagle.ai.
It differs from Bagle.ai only in its size, the name of the file it creates, and the corresponding registry key. It creates a file named sysxp.exe, rather than winxp.exe.

Check other viruses! Be aware! Use Antiviral Software

APME.Demo.620

Description APME.Demo.620
APME is an ordinary polymorphic generator such as MtE and TPE. There is only one known virus APME.Demo that is included in APME.ZIP distribution package as APME.COM file. The virus opens APME.COM file, and overwrites it with new virus copy. Then the virus displays:
[_PME] Alpha PolyMorphic Engine by ViKing - Version 1.04b

Apo.2108

Description Apo.2108

It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the beginning of .COM and end of .EXE files that are executed. While infection of the files the virus renames them to the name X$X$$X$X.$X$, infects and then renames back to original name.
While infecting .EXE files the virus corrects several fields in EXE header: the virus increases the length of EXE header to cover original contents of the file. As a result the original file body is defined as EXE header, and while loading such file info the memory DOS loads only the virus body. Then the virus opens the host file, restores the fields in EXE header, executes host file, and then writes "infected" fields back to EXE header.
The virus also hooks INT 1Ch and some time after installation erases the disk sectors. The virus has the bugs, and in some cases halts the computer. The virus contains the encrypted text string:
ApoVir

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com