Classification

Category :

Malware

Type :

Virus

Aliases :

Freew

Summary

This virus activates in January 1993. During this month, it overwrites programs with a trojan.

When the virus infects a file, it stores the current system timer value to low system memory. On the next execution of the virus, it checks that at least 64k timer counts have passed before it infects again.

The virus checks the current drive, and if it is operating on a floppy, it tries to change the drive to C:. On all drives from C: to the current drive, all directories from the root are recursively scanned for files matching "*.COM". These files are then either infected or damaged, depending on the date. Files named "MKS_VIR.COM" or "COMMAND.COM" are ignored.

The virus infects files by storing the beginning of host files to the end of file and replacing the beginning with it's own code. When the virus exits the copy routine restores the original program and jumps to it. The file attribute has read-only and hidden bits cleared during infection and restored afterwards. File date/time are (partly) preserved, except the low byte is set to 0FFh (seconds=62, minutes can become 63 if the previous minutes value was 56). Files with the low byte of the filetime as 0FFh are considered already infected and skipped.

The damage routine only destroys files if the file's creation time's hour field is even. When files are damaged, the beginning of the file is overwritten by a little program that writes "Program terminated normally" to the screen. Also, the hour filed is changed to odd.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

N/A

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award-winning antivirus and malware protection
  • Online browsing, banking, and shopping protection
  • 24/7 online identity and data breach monitoring
  • Unlimited VPN service to safe­guard your privacy
  • Password manager with private data protection
More Support

Community

Ask questions in our Community .

User Guides

Check the user guide for instructions.

Contact Support

Chat with or call an expert.

Submit a Sample

Submit a file or URL for analysis.