rael.321
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Rael.3211
This is a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h, and writes itself to the end of COM files (except COMMAND.COM) that are executed or opened. It also infects files when searching DOS functions FindFirst/Next ASCII.
The virus contains the text strings:
c:\dos\sys.com
c:\dos\dosshell.com
c:\dos\format.com
c:\dos\keyb.com
and infects these files when an infected file is executed. Depending on the system timer, this virus infects the files with a Trojan program that erases the disk sectors being executed.
On the 14th of every month, it deletes files after infection, and starting from 12:00, it displays the following message:
___ __ ___ _
_ _ _ _ _ _
___ ____ ___ _
_ _ _ _ _ _
_ _ _ _ ___ ____
IMPERIAL AEROSOL KID
V 01/NOV/93 por RAEL
It also contains the text strings:
com
COMMAND
command
RAEL-IMPERIAL AEROSOL KID VIRUS III
-Buenos Aires-Argentina-
allRael, Imperial Aerosol Kid-exits in the daylight, spraygun head...
- SaTaNiC BRaIn B.B.S. 383-7480 Las 24 Horas -
Copyright @2006 rael.321