Under 7 Virus
Virus Name: Under 7
Aliases: Paradise
V Status: New
Discovered: June, 1993
Symptoms: .COM file growth; file date/time changes; system hangs
Origin: Unknown
Eff Length: 320 Bytes
Type Code: PRaCK - Parasitic Resident .COM Infector
Detection Method: ViruScan, F-Prot, AVTK, Sweep, NAV,
IBMAV, NAVDX, VAlert, PCScan, ChAV,
NShld, Sweep/N, AVTK/N, NProt, IBMAV/N, Innoc, NAV/N
Removal Instructions: Delete infected Files
General Comments:
The Under 7 virus was received in June, 1993. Under 7 is a memory
resident infector of .COM programs, including COMMAND.COM.
When the first Under 7 infected program is executed, this virus will
install itself memory resident in low available free memory, hooking
interrupt 21. It will also access the system hard disk at this time,
and a system hang may occur.
Once the Under 7 virus is memory resident, it will infect .COM
programs when they are executed. Infected programs will have a file
length increase of 320 bytes with the virus being located at the end
of the file. The program's date and time in the DOS disk directory
listing will have been updated to the current system date and time
when infection occurred. One text string can be found at the end of
the viral code in all Under 7 infected programs:
"COM"