Threat description




When an infected file is executed, the virus will install itself in memory and hook INT 21h. If the day is 5th of any month, virus will also hook INT 8h (system timer).


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

The INT 21h handler intercepts calls to DOS function 4Bh (load program). If the filename fits "*.COM" it is considered for infection. Only those files that are smaller than 62.5kB and have no EXE 'MZ' header are infected. Files which have the word 1972h at offset 3 are left alone. Nothing is done about changing file attributes so if the virus tries to infect files with read-only attribute, DOS will produce an error message.

If the day was 5th of any month, virus will trigger some time after the execution of an infected program. Depending on the video mode, the virus may cause a scrolling effect on the screen or emit a beep through the speaker.

Virus code contains a text saying 'Signs Of Life !'

Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info