| Description:
|
Details
Uranus.2048
It is a harmless memory resident multipartite virus. It infects COM, EXE, NewEXE (NE) files and disk boot sectors. When an infected file is executed, the virus writes its code to the first hard drive track (unused sectors) and writes its loader to the boot sector of C: drive. The virus then returns to the host program.
When the system is loaded from infected disk, the virus hooks INT 13h, waits for DOS loading process, hooks INT 21h and writes itself to the end of COM, EXE and NewEXE (NE) files that are executed or accessed by FindFirst/Next ASCII DOS calls. When 1.4Mb floppy disks are accessed, the virus infects their boot sectors.
The virus checks the file names - it compares two last letters of file name with pairs of letters of the string:
ANOT86AVVPUSILEDOPNDLPGRPLRKYRRE
and does not infect these files (anti-viruses and utilities SCAN, F-PROT, KRNL386, NAV, AVP, FINDVIRUS, MSMAIL and so on).
The virus also contains the string:
Sailor_Uranus |