Fandom

Malware Wiki

Rotor

1,335pages on
this wiki
Add New Page
Comments0 Share

Virus.DOS.Rotor.1068 is a memory resident parasitic encrypted virus on DOS.

Behavior

When the virus is loaded into memory, it first infects C:\COMMAND.COM, followed by hooking INT 8 and 21h to infect any executable that is accessed by writing itself to the end of the file.

Memory usage

The exact memory usage is 4,096 bytes.

Payload

When the value of month is equal to that of the day on the system date, on running any infected file the virus activates by rotating the following characters on screen:

l - / \ |

The user cannot stop the rotation of these characters unless resetting the system.

After activation, the system might hang when the user issues a command containing these characters, while the system would return "Bad command or file name" or "Syntax error" in normal cases.

Other details

The virus contains the encrypted internal text string:

c:\command.com

Videos

Virus.DOS03:34

Virus.DOS.Rotor

Rotor virus review by Alles Sandro

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.