rikki famil
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Rikki family
These are not dangerous nonmemory resident parasitic viruses. They search for .COM files, then writes itself to the end of the file. While infecting a file they temporary rename it with COx (x=FFh) extension. To rename file the viruses do not call any DOS function, but make it by absolute disk read/write calls (INT 25h/26h) - the viruses read directory entry, search for file name, patch it and then write directory sector back to disk.
The viruses display the messages:
"Rikki.839":
Demo virus #1 by Rikki Cate 21/9/90
File infected:
Press key to continue
"Rikki.1787":
Demo virus #3 by Rikki Cate 21/9/90
File infected:
Press key to continue
"Rikki.1970"
Demo virus #2 by Rikki Cate 21/9/90
File infected:
Press key to continue
PC-cillin has been replaced by a demonstration virus. To activate the
virus, reboot the computer.
PC-cillin has been replaced by a demonstration virus.
This message could easily duplicate the PC-cillin start-up screen.
The virus is now resident in memory in place of PC-cillin. It
will emulate the PC-cillin display and command keys. It will also
infect any .COM programs which are accessed by interrupt 21 hex.
Press any key to continue.
Copyright @2006 rikki famil