pest.272
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Pest.2728
This is a very dangerous memory resident parasitic polymorphic virus. It traces INT 13h, hooks INT 21h, and writes itself to the end of COM and EXE files that are executed. The virus checks the file names by using the text string:
ASCECLHVSPF-ACPRVINWI
and does not infect files with names that begin with: SCA, CLE, VSH, F-P, CPA, VIR, and WIN. While infecting a file, the virus also checks it for some specific code and pathes it.
Under a debugger, or on the 13th of any month, and depending on the system timer, the virus corrupts the hard drives sectors and reboots the computer. Starting from the 4096th (1000h) infection, the virus overwrites the data saved on the disk with the following text:
PRIEST V.D.G.I. hopes you can recover your data !!!
The virus also contains the text string:
Pest (c) 12/10/93 by (and best wishes from) PRIEST Int., Gbw/Germany
Copyright @2006 pest.272