Details Artem.2165 It is not a dangerous memory resident encrypted parasitic virus. It hooks INT 1Ch, 21h and writes itself to the end of COM and EXE files that are executed or closed. On opening an infected file the virus disinfects it (stealth routine). When several file compressing and some other utilities are run, the virus disables its stealth routine. The list of these routines looks as follows: ARJ, BSA, CHKDISK, DIET, ICE, LHA, PKLITE, PKZIP, RAR. Depending on its internal counter the virus shakes the screen. The virus contains the text strings, the first one contains parts of names listed above (tree bytes per name): ARJBSACHKDIEICELHAPKLPKZRAR EXECOM Artemiev I.A.

Leave a Reply

Your email address will not be published. Required fields are marked *