Class Virus
Platform DOS

Technical Details

It’s a dangerous memory resident multipartite companion virus. It
hooks INT 21h and on execution of .EXE-files it creates companion
.COM-files. On selection of a new disk it overwrites boot sector of A:
drive with trojan program and saves itself at the last sectors of A: drive.
On loading from that drive the trojan programs scans disk sectors for
EXE-files and overwrites them by this virus (code which is stored at the
last disks sectors). Two months after infection this virus disables calls
to printer (sets INT 17h to IRET instruction). This virus contains the
internal text string:


