Quox is a very simple stealth boot virus, effective only with processors 80286 and higher. When an attempt is made to load the system from an infected diskette the virus installs itself into memory and redirects the interrupt INT 13h to itself. When reading or writing into diskettes boot sector and hard disk’s MBR respectively, it infects them. The virus saves the original diskette boot sector into its last sector; MBR is located to the end of the side one. The virus contains neither activating routine nor text but sometimes it may cause data loss. If the virus is active in memory no alterations in infected sectors are seen.

