F-Secure Virus Descriptions : RP
This is a stealth boot sector virus. Unlike most other boot sector
viruses, RP does not decrease the total amount of DOS memory;
instead it decreases the amount of free memory.
RP activates on the 17th of December. When the machine is booted on that
date, the virus decrypts a message, switches the display to 40 column
mode and displays the following text:
RP wants to say hello!
After this, the virus overwrites part of the hard drive, making
the machine unbootable.
The virus is buggy and often crashes when infecting a floppy.
RP was reported to be in the wild in Hungary and Denmark in January
1996.
[Analysis: Mikko Hypponen, F-Secure]
|