Prevent Online Threats

Level3.487

Details
Level3.4870

It is not a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or opened. While infecting it checks the file name and does not infect the files:
SCAN VSHIELD CLEAN FINDVIRU GUARD VIVERIFY TB -V
VIRSTOP NOD HIEW PASCA NETENVI F-PROT CHKDSK

While installing or terminating any program the virus checks the system memory for anti-virus monitors TBAV and VSAFE and disables them, it uses its string to locate these monitors:
TBMEMXXXTBCHKXXXTBDSKXXXTBFILXXX

Depending on its generation and system date the virus displays the message:
Welcome to the Explosion’s Mutation Machine !
Dis is level 3.

It also contains the text strings:
* EMM 1.0 *
COM EXE

Related Posts

  • No related posts
  • Leave a Reply


    Spyware Removal Spyware Protection Tools