harmware.348
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
HarmWare.3483
These are memory resident parasitic polymorphic viruses. They hook INT 21h and write themselves to the beginning of COM and EXE files that are executed. While infecting a file the viruses compress its body by an internal compression routine, as a result the file length does not grow. The viruses delete the anti-virus data files CHKLIST.MS, CHKLIST.CPS.
The viruses use on-the-fly encryption: the virus' subroutines are encrypted not only in files, but also in its TSR copy. The viruses decrypt them in case of need, execute, and then encrypt with new key. The viruses also use anti-debugging tricks.
HarmWare.3515
It is a very dangerous virus. Under debugger it erases disk data. It contains the text:
- HarmWare v1.06 by Ak Kort [SOS group] -
Hi! I'm still alive :) Let me introduce my new release.
There are none distruction. Just another way of anti-heuristicall
HarmWare.3716
It is not a dangerous virus. It also hooks INT 8, 9 (timer and keyboard) and by hooking these interrupts runs its video effect - if there are no keystrokes within 10 minutes, the virus "shifts" the screen. When the ADINF anti-virus integrity checker is executed, the virus stuffs the ENTER key into keyboard buffer and blacks the top half of the screen.
The virus contains the text strings:
- HarmWare v1.05 by Ak Kort [SOS group] -
Final version. Wait new releases.
Diskinfoscope ADinf
Copyright @2006 harmware.348