Fandom

Malware Wiki

Ah

1,319pages on
this wiki
Add New Page
Comments0 Share
Smallwikipedialogo
Most of this page uses content from Wikipedia. The original article was at Ah. The page may have contained some inaccurate or outdated information, so please edit it so it contains better information.
The list of authors can be seen in the page history. As with Malware Wiki, the text of Wikipedia is available under the Creative Common Attribution-ShareAlike 3.0 License.
Remove this template when most of the Wikipedia content has been removed or the Wikipedia information is outnumbered by non-Wikipedia information.
 


Ah (also known as Tuesday and Jerusalem.Ah) is a very buggy computer virus which infects COM files . Ah is based on the V1024 virus, and originated in Italy in May 1991. When the first program infected with Ah is executed, Ah will install itself memory resident at the top of system memory, but below the 640K DOS boundary. After it is memory resident, Ah will infect .COM programs over 1K in length when they are executed. Infected programs will increase in size by 1,173 bytes, though the file length increase will be hidden if Ah is resident. Their date and time in the DOS directory will appear to be unaltered, though if the program's original time was 12:00a, it will now be blank. The virus will be located at the beginning of infected programs. Total system and available free memory, as indicated by the DOS CHKDSK program, will decrease by 1,216 bytes. Interrupts 08 and 21 will be hooked by the virus. Systems infected with Ah will experience frequent system hangs. These hangs occur when the user attempts to execute a .COM program which is infected with Ah. They may also occur when the virus attempts to infect an uninfected program. System hangs occur so frequently with Ah that the virus is very noticeable. The Ah virus activates on Tuesdays, at which time it will attempt to format the first few tracks of the system hard disk.

Ah
Common name Ah
Technical name Jerusalem.Ah
Aliases David-1173, Tuesday,Jerusalem.David
Family N/A
Classification Virus
Type DOS
Subtype COM infector. Buggy, causes system hangs.
Isolation 1991
Point of isolation Unknown
Point of Origin Italy
Author(s) Unknown, not David Grant[disambiguation needed] and the PCVRF

The following text string is found in infected files:

  • "(C) David Grant Virus Research 1991 PCVRF Disribuite this virus freely!!! ...ah...John...F**k You!"

Ah is believed[by whom?] to have been created by the same person as several other viruses from Italy, including Smack and Enigma. David Grant and the PCVRF had nothing to do with its creation

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.