Virus Protection > computer-virus-t-page1 > - td.153

td.153

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
TD.1536
It is not a dangerous memory resident multipartite virus. It writes itself to the end of COM and EXE files, to the MBR of the hard drive and to the boot sector of floppy disks. The virus does not manifest itself by any sound or video effect. It was named after its ID-text "TD" that presents in infected files, boot and MBR sectors.
When an infected file is executed, the virus infects the MBR of the hard drive, hooks INT 21h and stays memory resident. It then affects files that are executed. The virus pays attention to Windows self-checking signature ENUNS that presents at the end of Windows COM files and patches it. While installing memory resident the virus also infects the C:\WINDOWS\WIN.COM file and deletes the C:\WINDOWS\SYSTEM\IOSUBSYS\HSFLOP.PDR file, if they exist.
On loading from infected disk the virus hooks INT 13h, 1Ch, waits for DOS loading process and then hooks INT 21h. By hooking INT 13h the virus infects floppy disks, INT 13h handler also has stealth routine that is activated on accessing to already infected disks.

Updated: 02/24/2006
Copyright @2006 td.153
Webroot Software Inc.