Prevent Online Threats

Gondor.307

Details
Gondor.3072

It is a not dangerous memory resident encrypted parasitic virus. It hooks INT 12h, 21h and on DOS calls FindFirst ASCII it searches for EXE-files and writes itself to their ends. It deletes the CHKLIST files. Depending on the system date and time it disables several DOS functions such as file deleting and creating, changing the directory and so on. On June, 9th it displays:
HAPPY BIRTHDAY ,HONEY.

It contains other internal text strings:
GONDOR=WARRIOR
*.exe .EXE
chklist?.???

Related Posts

  • No related posts
  • Leave a Reply


    Spyware Removal Spyware Protection Tools