Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Ungame


Aliases:


Ungame

Malware
Virus
W32

Summary

When the infected file is executed for the first time, the virus will install itself in memory. Virus reserves 768 bytes for itself at the top of the free memory. Virus hooks INT 21h and INT 8h (system timer).

Virus will infect all executed files which are between 3 and 61441 bytes long. Virus checks whether the file contains string 'Dr' at the end of the file and determines this way if the file is already infected or not. The string is a part of text the virus contains: 'UnGame(C)Dr'.

Every 4096 timer ticks, virus checks if the video mode is 4, 13, or 19 the timer handler selects 1 of 8 routines to run - depending on timer count. These routines include warm reboot, some video and musical effects and a displayed message 'Come On, no.51, You Time is Up.'.

This virus has nothing to do with the Ungame product from DVD Software.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.









Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.