| Description:
|
Details
Majkl Family
These are harmless memory resident encrypted multipartite viruses. While executing of the infected file the virus writes itself to MBR of the hard drive, hooks INT 13h, 21h and then writes itself to the end of COM- and EXE-files that are executed or opened. While booting from infected MBR the virus hooks INT 8, 13h, waits for DOS loading procedure, then hooks INT 21h and hits the files.
The viruses use anti-debugger tricks bases on the features of i386+ processors. The "Majkl.1438" virus contains the text string:
Majkl |