Taiwan_Over Virus

 Virus Name:  Taiwan_Over 
 Aliases:     Taiwan_Over.2770, SSH.2770 
 V Status:    New 
 Discovered:  January, 1995 
 Symptoms:    .COM file growth; TSR; file date/time changes 
 Origin:      Unknown 
 Eff Length:  2,770 Bytes 
 Type Code:   PRsC - Parasitic Resident .COM Infector 
 Detection Method:  F-Prot, ViruScan, AVTK, Sweep, IBMAV, 
                    NAV, NAVDX, VAlert, PCScan, ChAV, 
                    NShld, NProt, AVTK/N, IBMAV/N, Sweep/N, NAV/N, LProt, 
                    Innoc 4.0+ 
 Removal Instructions:  Delete infected files 
 General Comments: 
       The Taiwan_Over, Taiwan_Over.2770 or SSH.2770, virus was received 
       in January, 1995.  Its origin or point of isolation is unknown. 
       Taiwan_Over is a memory resident infector of .COM files, but not 
       COMMAND.COM.  It is a fast infector, quickly spreading on infected 
       When the first Taiwan_Over infected program is executed, this virus 
       will install itself memory resident as a low system memory TSR of 
       3,072 bytes.  Interrupts 05, 08, 16, 17, and 21 will be hooked by the 
       virus in memory. 
       Once the Taiwan_Over virus is memory resident, it will infect .COM 
       files when they are executed, opened, or copied.  Infected files 
       will have a file length increase of 2,770 bytes with the virus being 
       located at beginning of the file, though some of the original host 
       program may be imbedded within the code.  The file's date and time in 
       the DOS disk directory listing will have been updated to the current 
       system date and time when infection occurred.  The following text 
       strings are visible within the viral code in all Taiwan_Over infected 
               "RRG????????.COM COMMAND.BAT" 
       It is unknown what the Taiwan_Over virus does besides replicate. 
       Known variant(s) of Taiwan_Over are: 
       Taiwan_Over.2944: Received in January, 1995, Taiwan_Over.2944 
               is a 2,944 byte variant of the Taiwan_Over virus described 
               above.  Its low system memory TSR is 3,248 bytes, hooking 
               interrupt 05, 08, 16, 17, and 21.  It adds 2,944 bytes to 
               the .COM files it infects.  Infected files contain the 
               following text string within the viral code: 
               "RRG????????.COM COMMAND.COM" 
               Origin:  Unknown  January, 1995. 

Show viruses from discovered during that infect .

Main Page