Prevent Online Threats

Shadow Famil

Details
Shadow Family

These are very dangerous memory resident parasitic encrypted viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed or loaded as overlays. “Shadow.1702″ also intercepts FindFirst/Next DOS call (DIR command), and infects the files that are listed.
The viruses (except “Shadow.1702″) have an error in the infection routine, and as a result the infected COM files are not recoverable. These viruses also overwrite the ‘*BBS*.*’ files, “Shadow.1702″ writes a trojan program to there, that program “clears” the screen by using VGA tricks and halts PC.
The viruses contain the text strings:
“Shadow.1185,1200″: [Shadow] NecroSoft Enterprises-a division of BCA
Greets to SKISM
“Shadow.1702″: [Shadow-B/2] NecroSoft Enterprises - a division of BCA
Greets to SKISM

Related Posts

  • Zombie.VPI.1521
  • Spectral.60
  • BAT.Shadow.123
  • Wrzod.104
  • TPVO.Glacier.118
  • Leave a Reply


    Spyware Removal Spyware Protection Tools