Fandom

Malware Wiki

ADT

1,335pages on
this wiki
Add New Page
Comments0 Share

Virus.DOS.ADT.1778 is a memory resident parasitic DOS virus, it is named by the ASCII art of its payload on debugging an infected file.

Behavior

When the virus is in memory, it hooks INT 21h to infect any executable file that is run by writing itself to the end of the file.

The virus has two infection behaviors, when it stays in memory, not only the program file that is run would be infected, it also searches for the first uninfected executable file in both COM and EXE formats in current directory and infects them.

Memory usage

The exact memory usage is 2,048 bytes.

Payload

On 19th of any month the virus also hooks INT 9 (keyboard) and displays the text "Andreas" at the cursor position.

When the user tries to debug a file infected by ADT using DEBUG, the virus displays the text:

-------------##########-############----##############---------####-----------
------------###########-##############--##############---------####-----------
-----------#####--#####-#####----######------####--------------####-----------
----------#####---#####-#####----######------####--------------####-----------
---------##############-#####----######------####---------------##------------
--------###############-#####----######------####---------------##------------
-------#####------#####-##############-------####-----------------------------
------#####-------#####-############---------####---------------##------------

And it disables the keyboard input and hangs the system.

Videos

Virus.DOS.ADT00:52

Virus.DOS.ADT.1778

ADT virus review

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.