| Description:
|
Details
Nostardamus.3584
It is a very dangerous virus, in some cases it searches for C:*.* files and deletes them.
It uses INT 22h hook to wait the host program termination, hooks INT 21h and installs itself memory resident. It's a stealth virus, while accessing to an infected file it disinfects it. It checks the file name and do not infect several anti-virus programs.
This virus checks the file name by using the strings:
COMEXEOVLOVR
PROSCAEXTWEB
ARJRARLHAZIP
COMWINCHK
and does not infect these files or disables its stealth routines.
This virus also contains the strings:
-=Unlimited Grief=-
Kiev'96
EMME 3
Killer |