391 Virus
Virus Name: 391
Aliases:
V Status: Rare
Discovery: July, 1994
Symptoms: .COM file growth
Origin: Unknown
Eff Length: 391 Bytes
Type Code: PNCK - Parasitic Non-Resident .COM Infector
Detection Method: AVTK, IBMAV, ViruScan, Sweep, F-Prot, NAV,
NAVDX, VAlert, PCScan,
Sweep/N, AVTK/N, IBMAV/N, NShld, NProt, NAV/N, LProt
Removal Instructions: Delete infected files
General Comments:
The 391 virus was received in July, 1994. Its origin or point of
isolation is unknown. This virus is a non-resident, direct action
infector of .COM files, including COMMAND.COM.
When a program infected with the 391 virus is executed, this virus
will infect one .COM file located in the current directory. Infected
programs will have a file length increase of 391 bytes with the virus
being located at the end of the file. The program's date and time in
the DOS disk directory listing will not be altered. The following
text strings are visible within the viral code:
"*.com"
"????????COM"