Welcome to the Virus Encyclopedia of Panda Security.
|Alias:||Viernes 13, Israelí, Russian, 1808, 1813, BlackBox, BlackWindow, Arab Star, PLO |
It carries out damaging actions on the affected computer.
It does not spread automatically using its own means.
|Detection updated on:||Feb. 2, 2007|
| Jerusalem.1808.A is considered to be a very dangerous virus, as it infects executable files with EXE and COM extensions. When these files are run, the virus goes memory resident. It then, proceeds to infect all files that are executed or copied. Jerusalem.1808.A can carry out several infections on files with EXE extension that have been already infected, However, this is not the case in files with COM extensions.|
The most immediate effect of its infection can be observed 30 minutes after the virus goes memory resident. The virus causes a general slowdown of the system. Additionally, one of the most dangerous payloads of this virus is the fact that can delete any programs that are run on the computer. However, this will only occur on Friday the 13th.
One of the first symptoms of infection is the fact that the size of infected files will increase. The size of COM files will increase by 1813 Bytes, whereas the size of EXE files will increase by a value of between 1808 and 1822 Bytes. In any of these cases, the viral code will be stored at the end of the infected file. However, the time and date values of the infected files will not be modified.
Moreover,, half an hour after the virus goes memory resident, a considerable slowdown of the system can be observed.. In addition, (depending on the variants of the virus), a black or white rectangle will be displayed on the screen.
However, the most dangerous /threatening payload of this virus is the fact that it can eliminate programs. This only occurs when the date corresponding to the system clock reads Friday the 13th. Then the virus will delete all programs that are run.