| Description:
|
Details
Jd Family
These are memory resident parasitic viruses. They copy themselves to the system memory at the address 0043:0100, hook INT 21h and write themselves to the end of COM files that are executed or opened.
Some of these viruses detect their already installed TSR copy with "Are you here?" call (INT 21h, AX=3FFFh), the TSR part returns 4A44h ('JD') in AX register.
Sometimes "Jd.448,460" delete the files instead of opening them. |