Class Virus
Platform Boot

Technical Details

It is a dangerous memory resident boot virus. It hooks INT 13h and infects
the MBR of the hard drive and boot sector of floppy disks. The virus
contains the text string:


Depending on its counter the virus also hooks INT 21h. While executing a
file the virus searches a disk boot sector image within this file – the
virus scans the file for the “MSDOS” string and checks boot stamp 55AAh. If
such data are found, the virus replaces them with its copy. As a result,
the virus converts disk formatting utilities to virus droppers – while
formatting a disk they will write to the disk boot sector the virus code
instead of original bootstrap routine.

Text added: 30.12.96/GV

Find out the statistics of the threats spreading in your region