Fandom

Malware Wiki

Rotor

1,321pages on
this wiki
Add New Page
Comments0 Share

Virus.DOS.Rotor.1068 is a memory resident parasitic encrypted virus on DOS.

BehaviorEdit

When the virus is loaded into memory, it first infects C:\COMMAND.COM, followed by hooking INT 8 and 21h to infect any executable that is accessed by writing itself to the end of the file.

Memory usageEdit

The exact memory usage is 4,096 bytes.

PayloadEdit

When the value of month is equal to that of the day on the system date, on running any infected file the virus activates by rotating the following characters on screen:

l - / \ |

The user cannot stop the rotation of these characters unless resetting the system.

After activation, the system might hang when the user issues a command containing these characters, while the system would return "Bad command or file name" or "Syntax error" in normal cases.

Other detailsEdit

The virus contains the encrypted internal text string:

c:\command.com

VideosEdit

Virus.DOS03:34

Virus.DOS.Rotor

Rotor virus review by Alles Sandro

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.