Virus Protection > computer-virus-t-page1 > - thunder.154

thunder.154

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
Thunder.1543

It is a dangerous memory resident parasitic polymorphic virus. It hooks INT 13h, 21h and infects COM and EXE files that are executed. The virus encrypts and writes itself to the end of the file and places its decryption routine to the middle of file at random offset.
By hooking INT 13h the virus intercepts the read/write sector(s) calls and replaces the 'O', 'P' and 'M' letters with their Cyrillic analogues.
Starting from December 20th the virus also hooks INT 8 and depending on the system timer displays:
T H U N D E R

The virus also contains the text:
Thunder

Updated: 02/24/2006
Copyright @2006 thunder.154
Webroot Software Inc.