Virus Database


Spy.1089

Description Spy.1089

It is not a dangerous memory resident parasitic virus. It hooks INT 9, 21h, 28h, 2Fh and writes itself to the end of EXE files that are executed. By hooking INT 9, 28h the virus tries to save to the C:IO.IO file all keys that are entered, but fails because of a bug. On INT 2Fh call with AX=CX=CECEh the virus displays the message:
I'm SPY by Costin,what's up ?
c:io.io

Check other viruses! Be aware! Use Antiviral Software

Kreg.1405

Description Kreg.1405

It is a harmless memory resident parasitic polymorphic virus. It hooks INT 10h, 21h and writes itself to the end of COM and EXE files that are executed or renamed. The virus does not infects the files: *CA?.*, *AN?.*, *ES?.*, *WE?.*, *IN?.* (SCAN, COMMAND, AIDSTEST, WEB, ADINF).
While installing the virus uses a trick that hides the virus on the memory map: the virus copies its INT 21h handler (49 bytes) to BIOS data area at address 0000:04D0, sets INT 21h to there and hooks INT 10h. When any program calls DOS function (INT 21h), the virus compares it with Execute and Rename functions (4Bh, 56h) and calls INT 10h with AX=DEADh. This is an "infect-it" call, and virus INT 10h handler intercepts it and infects a file.
The virus contains the text strings:
[ Gremlin 1.04 / AVL ]
[ KREG 1.01 / AVL !

KrK.800

Description KrK.800

It is a harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. The virus does not manifest itself, it contains the text:
(c) KrK'96

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Dedicated Hosting
Holzterrasse Bangkirai
Private Krankenversicherung
Unblock Websites In School
Terra Nova

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com