ile in the current
directory of "C:\".
Detecting Method: None.
Note:
1) Doesn't stay resident in memory.
2) Killcom doesn't hook INT 24h when infecting files. An error
message occurs if there is an I/O error (such as write protect).
Virus Name: Killboot
Virus Type: Trojan
Virus Length: 32000 Bytes
PC Vectors Hooked: None
Damage: Destroys all data in the BOOT SECTOR of
"C:\" and "B:\", then shows a line of codes
and the system halts.
Detecting Method: None.
Note:
1) Doesn't stay resident in memory.
2) Doesn't infect any files or partition.
Virus Name: Kennedy
Other names: None
Virus Type: File Infector Virus
Virus Length: 333 bytes
Executing Procedure:
1) The virus checks if it is memory resident. If it isn't, it
loads itself into memory by hooking INT 21h.
2) It then executes the original file.
3) Once in resident memory it will infect any uninfected file
that is executed.
Damage: Destroys the FAT.
Detecting Method:
1) On June 6th, November 8th, and November 22th, the virus will
display the following message: "Kennedy is dead - long live
the Dead Kennedys."
2) It then proceeds to destroy the FAT.
Note: Loads itself resident in memory. An error message occurs if
there is an I/O error (such as write protect).
Virus Name: Klf-356
Virus Type: COM File infector
Virus Length: 356 bytes
Executing Procedure:
1) Checks whether it has stayed resident in memory. If not, it
will stay resident in high memory.
2) Then it hooks INT 21h and goes back to the original routine.
Vectors hooked:
1) Hooks INT 21H(AH=4Bh) to infect files.
2) First, it will hang INT 24h to prevent divulging its trace
when writing.
3) If the program to be executed is an uninfected COM file, the
virus proceeds to infect it.
Damage: None
Detecting Method: Infected file sizes increase by 356 bytes.
Virus Name: Kiwi-550
Virus Type: EXE File infector
Virus Length: 550-570 bytes
Executing Procedure:
1) Checks whether it has stayed resident in memory. If not, it
will stay resident in high memory.
2) Then it hooks INT 21h and goes back to the original routine.
Vectors hooked:
1) Hooks INT 21H(AH=4Bh) to infect files.
2) First, it will hang INT 24h to prevent divulging its trace
when writing.
3) If the program to be executed is an uninfected |