patoruzu famil
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Patoruzu Family
These are relatively harmless memory resident parasitic viruses. They hook INT 21h, and write themselves to the end (931 bytes version) or beginning (1024 bytes version) of COM files (except COMMAND.COM) that are executed.
"Patoruzu.931" is encrypted, and On the 17th of any month, it disables CreateDir DOS function.
While infecting, "Patoruzu.1024" renames a file "TOMY", then infects it, and renames it back to original name. This virus hooks INT 13h also, and sometimes tries to change the contents of the sector that are read, but it fails.
On the 17th of any month, "Patoruzu.1024"--and on November 17th, "Patoruzu.931"--display the following messages:
"Patoruzu.931":
Huijaaa !! La proxima vez sera tardeall
Si sos MENEMISTA reza por tus discos.
>> Virus PatoruzU 2.0 - Argentina <<
"Patoruzu.1024":
Viva Sumo! y Muera MENEM - Virus PatoruzU 1.0 - Argentina.
Copyright @2006 patoruzu famil