Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically


This is a resident, stealth boot virus. When an attempt is made to load the system from an infected diskette the virus attacks the hard disk’s MBR. It locates the original MBR and the rest of its body into the last two sectors of active partition. The virus differentiates what operating system the active partition belongs to. If it is not DOS, the hard disk will not be infected. After infecting the MBR the system is loaded. Upon booting from hard disk the virus installs itself into memory and redirects the interrupt INT 13h service to itself. Then it tries to attack diskettes which are not write-protected. If the system date is March 25th, a routine with destructive code is activated; it will overwrite a part of the active partition and displays the following text:

FINNISH_SPRAYER.1. Send your painting +358-0-43220119 (FAX) [Aija]

© 1992-2004 Eset s.r.o. All rights reserved. No part of this Encyclopedia may be reproduced, transmitted or used in any other way in any form or by any means without the prior permission.