Dudley

Alias:Dudley
Strain:-
detected when:
where:
Classification:COM and EXE infector
Length:4608

Preconditions

Operating System(s):MS-DOS
Version/Release:None
Computer model(s):PC's
Caroname:Dudley

Attributes

Easy identification:

Type of Infection:

The virus appends itself to the files Selfrec in memory: INT21h;AX=5454h -> AX=0000 Selfrec on disk: EXE_Checksum==5045h; COM_start==7100h

Infection Technique:
Infection Trigger:INT 21h && (AX == 4B00h ||(AH == 3Dh || AH == 56h || AH == 6Ch) &&(ext == COM || ext == EXE))
Storage Media affected:
Interrupts hooked:21h/4B00h 21h/3Dh 21h/56h 21h/6Ch 21h/5454h
Stealth:
Tunneling/Selfprot:
Oligo/Polymorphism:
Encoding Method:
Damage:Transient: None Permanent: None
Damage Trigger:Transient: None Permanent: None
Particularities:None Displayed text: None Not displayed text: "<[Oi Dudley!][PuKE]>" Polymorphic COM and EXE infector. Contains code thatattempts to avoid infecting a file with name ????SC??.???,but it has a bug.
Similarities:None

Agents

Countermeasures:
Standard means:

Acknowledgements

Location:Virus Test Center, University Hamburg, FRG
Classification by:David M. Chess
Documentation by:David M. CHess
Date:1993-03-10
Information Source:Caroentry (autom.converter by S.Freitag)

(c) 1996 Virus-Test-Center, University of Hamburg