AtomAnt 3.0 Virus


 Virus Name:  AtomAnt 3.0 
 Aliases:     Filling 
 V Status:    Rare 
 Discovered:  July, 1993 
 Symptoms:    .COM & .EXE growth; 
              decrease in total system & available free memory 
 Origin:      Unknown 
 Eff Length:  2,143 - 2,157 Bytes 
 Type Code:   PRhAK - Parasitic Resident .COM & .EXE Infector 
 Detection Method:  ViruScan, AVTK, Sweep, F-Prot, IBMAV, NAV, 
                    NAVDX, VAlert, PCScan, ChAV, 
                    NShld, Sweep/N, AVTK/N, IBMAV/N, NAV/N, LProt, NProt, 
                    Innoc 
 Removal Instructions:  Delete infected files 
                      
 General Comments: 
       The AtomAnt 3.0 or Filling virus was received in July, 1993.  Its 
       origin or point of isolation is unknown.  AtomAnt 3.0 is a memory 
       resident infector of .COM and .EXE programs, including COMMAND.COM. 
 
       When the first AtomAnt 3.0 infected program is executed, the virus 
       virus will install itself memory resident at the top of system 
       memory but below the 640K DOS boundary, not moving interrupt 12's 
       return.  Total system and available free memory, as indicated by 
       the DOS CHKDSK program, will have decreased by 2,144 bytes. 
       Interrupts 01, 09, 1C, 21 and 80 will be hooked by AtomAnt 3.0 in 
       memory. 
 
       Once the AtomAnt 3.0 virus is memory resident, it will infect .COM 
       and .EXE programs when they are executed.  Infected .COM programs 
       will have a file length increase of 2,143 bytes.  Infected .EXE 
       programs will increase in size by 2,145 to 2,157 bytes.  In both 
       cases, the virus will be located at the end of the file.  The 
       program's date and time in the DOS disk directory listing will not 
       be altered.  The following text is encrypted within the viral code 
       and is not visible within infected programs: 
 
               "A billentyľzet 5000 leütésig garanciális.Ez most lejárt. 
                Kérem cserélje ki !" 
               "Csak aztán idejében hagyja abba!" 
               "Ez nem SKĆLA áru!!!!" 
               "Hát igazán nem kedveltek bennünket ?" 
               "MC Hammer rap-sztár és PEPSI ôrült, de most kicseréltük 
                a PEPSI-ét" 
               "valami másra ... FILLING, NOTHING MORE THEM FILLING ..." 
               "Kérem fogadjon el egy vírust a vallási eszmélés egyházától." 
               "Nem akar adakozni ?" 
               "Túl régi ROM-BIOS verzió ! Cserélje ki újabbra !" 
               "Atomant v3.0 Erôsebb, mint valaha !" 
               "Csôtörés az I-O csatornábkan. 
                Kérem azonnal hívjon szerelôket!!!" 
               "Tömeg van az adatbuszon.Gyorsítsa meg azl" 
 
       It is unknown what AtomAnt 3.0 does besides replicate. 
 
       Known variant(s) of AtomAnt 3.0 are: 
       AtomAnt 1.0: Received in August, 1993, AtomAnt 1.0 is an earlier 
                    version of AtomAnt 3.0.  It's size in memory is 576 
                    bytes, hooking interrupts 21 and 80.  It infects .COM 
                    programs when they are executed.  Infected files 
                    increase in size by 564 bytes with the virus being 
                    located at the end of the file.  The program's date and 
                    time in the DOS disk directory listing will not be 
                    altered.  The following text strings can be found within 
                    the viral code in all AtomAnt 1.0 infected programs: 
                    "Hát igazám nem kedveltek bennünket ?" 
                    "AtomAnt v1.00" 
                    Origin:  Unknown  August, 1993. 

Show viruses from discovered during that infect .

Main Page