Fandom

Malware Wiki

Marine

1,335pages on
this wiki
Add New Page
Comments2 Share

Virus.DOS.Marine.5000 is a very dangerous memory resident parasitic encrypted stealth virus on DOS.

Behavior

When the virus is loaded into memory, it hooks INT 21h and 25h, and writes itself to the beginning of executables that are accessed. While infecting, the virus encrypts the original beginning of the file.

Payload

On June 5 and 21, the virus disables the FindFirst DOS call while searching for files on floppy disks. As a result, DOS shows nothing on them.

On Saturdays in June, the virus overwrites .PAS and .CPP files with the text:

There is nothing in the world that I ever wanted more than to never feel

breaking apart all my programs again.

In July the virus displays a video effect displaying the sun, sea, beach and a moving yacht, with the text:

BСЕ НА МОРЕ !!!

Translation (from Russian):

LET'S GO TO SEA !!!

When this effect is run, the virus encrypts the disk sectors.

Other details

The virus contains the encrypted internal text strings:

COMMAND.COM

.COM.EXE.PAS.CPP

I`m the Ghost V1.2.      Check. Your move, Mr.AntiVirus ! My author`s

coordinates are:Sun system, Earth, Europe, Russi... 2B continued... The

more we know,the less we show.

References

Securelist (Kaspersky Labs), Virus.DOS.Marine.5000

Videos

Virus.DOS08:05

Virus.DOS.Marine (Mild Flashing Lights Warning)

Marine virus review by danooct1

Virus.DOS.Marine02:26

Virus.DOS.Marine.5000

Marine virus review by Alles Sandro

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.