Virus.Win32.Rhapsody.2602
| Alert Level : | High |
| Discovered: | Jun 05 2000 |
| Tag: | Executable File and Boot Viruses |
| Discoverer and Source: | http://www.kaspersky.com/ |
Malware Behavior and Technical Description
This is a harmless non-memory resident parasitic Windows virus. It searches for PE EXE files with .EXE and .SCR file name extensions in Windows, Windows system and current directories, then writes itself to the end of the file.
The virus also infects BAT (DOS batch) files. It writes to there a DEBUG script that contains an image of an infected PE EXE file. When an infected BAT file is run, it runs the DEBUG utility to convert the script back to the PE EXE file form, saves it to a disk and spawns.
The virus contains the following "copyright" strings:
[Win32/BAT.Rhapsody]
(c) 1999 Billy Belcebu/iKX
0
Removal Virus.Win32.Rhapsody.2602 instructions:
0
Need help? Live computer support via remote at SupportSpace |

