Hadi.615
Details
Hadi.6153
It is not a dangerous memory resident partly encrypted parasitic virus. It hooks INT 8, 9, 20h, 21h and writes itself to the end of COM and EXE files that are executed or closed. The virus is semi-stealth: on opening an infected file the virus disinfects it, on DOS calls FindFirst/Next the virus returns the original length of infected files. When the disk checking utilities are run, the virus disables its stealth routines. The list of these utilities looks as follows: CHKDSK.EXE, SCANDISK.EXE, NDD.EXE, SPEEDISK.EXE, SD.EXE, DEFRAG.EXE. The virus does not infect the files: DEBUG.EXE, TD.EXE, CV.EXE, SI.EXE, NCSI.EXE, SYSINFO.EXE, MSD.EXE, HJ2321.EXE.
Depending on the system date and its internal flags the virus displays the messages:
Hercul Hadi
by Hadi Javan Amirkhizi
03/07/1996
TABRIZ–IRAN
Call me to repair your system (if you find me)
Press CTRL key for 5 seconds to return
Related Posts