Ah (also known as Tuesday and Jerusalem.Ah) is a very buggy DOS virus which infects COM files. Ah is based on the V1024 virus, and originated in Italy in May 1991. Ah is believed to have been created by the same person as several other viruses from Italy, including Smack and Enigma.
When the first program infected with Ah is executed, Ah will install itself memory resident at the top of system memory, but below the 640K DOS boundary. After it is memory resident, Ah will infect .COM programs over 1K in length when they are executed. Infected programs will increase in size by 1,173 bytes, though the file length increase will be hidden if Ah is resident. Their date and time in the DOS directory will appear to be unaltered, though if the program's original time was 12:00a, it will now be blank. The virus will be located at the beginning of infected programs. Total system and available free memory, as indicated by the DOS CHKDSK program, will decrease by 1,216 bytes. Interrupts 08 and 21 will be hooked by the virus.
Systems infected with Ah will experience frequent system hangs. These hangs occur when the user attempts to execute a .COM program which is infected with Ah. They may also occur when the virus attempts to infect an uninfected program. System hangs occur so frequently with Ah that the virus is very noticeable.
The Ah virus activates on Tuesdays, at which time it will attempt to format the first few tracks of the system hard disk.
The following text string is found in infected files:
"(C) David Grant Virus Research 1991 PCVRF Disribuite this virus freely!!! ...ah...John...F**k You!"
David Grant and the PCVRF had nothing to do with its creation.