Kaczor.4444

   
     _________________________________________________________________
   
   It is a non dangerous memory resident polymorphic stealth multipartite
   virus. It traces and hooks INT 13h, 21h and writes itself into the MBR
   (=Master Boot Record) of the hard drive and EXE-files on floppy disks
   that are accessed. On accessing of infected files on the hard drive
   the virus disinfects them.
   
   On installation from an infected hard drive the virus temporary hooks
   INT 12h, 1Ch also. On DOS loading it cuts the block of system memory,
   hooks INT 13h, 21h and resets INT 12h, 1Ch.
   
   This virus is encrypted in memory too. The INT 13h, 21h handlers
   decrypt the code of subroutines before processing.
   
   On loading, if the keyboard buffer contains the word "kaczor", the
   virus disinfects the MBR and displays:
   
   Zrobione.
   
   If the keyboard buffer contains the word "test", the virus displays
   the message:

 Wersja..........
 Kodowanie.......
 Licznik HD......

   and adds corresponding numbers at the ends of these strings.
   
   On March 3rd the virus hooks INT 08h (timer) and "shakes" the
   screen.
   
   
     _________________________________________________________________
   
   &copy; Copyright 1995 Eugene V. Kaspersky
