======== Computer Virus Catalog 1.2: Amilia Virus (25-Jan-1992) ======
Entry...............: Amilia Virus
Alias(es)...........: ---
Virus Strain........: Murphy Virus Strain
Virus detected when.: January 1992
              where.:
Classification......: Program (appending) virus, resident
Length of Virus.....: 1,164 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM - PC, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: Infected files will contain the string
                         "AmiLia I Virii  -  [NukE] i99i
                          By Rock Steady/NukE"
Type of infection...: All *.COM and *.EXE files that are executed or
                         opened will be infected if the files are
                         bigger than 1,614 bytes. COM files must also
                         be smaller than 64,000 bytes.
Infection Trigger...: Any of the following operations on any *.COM or
                         *.EXE file:Load/Execute, Open, Extended Open.
Infection targets:..: All *.COM files with 1614<=length<=64000 bytes;
                      All *.EXE files with 1614<=length and old header.
Interrupts hooked...: INT 1C, INT 24
Interrupts used.....: INT 13, INT 21, INT 40, INT 41
Damage..............: 1) On sundays, when executing or opening an *.EXE
                         file, the following message is displayed:
                             "AmiLiA I Virii - [NukE]
                              Released Dec91 Montreal
                              (C) NukE Development Software Inc"
                         Thereafter, the program terminates.
                      2) Upon each INT 21 call, the virus also checks
                         system tick count for being above equivalent
                         of about 16 hours; if this amount of on-time
                         is reached, a green smiley face on black back-
                         ground moves diagonally around the screen
                         bouncing at edges and characters.
Damage Trigger......: 1) For the message: day of the week = Sunday;
                      2) For the smiley:  16 hours of power on time.
Similarities........: ---
Particularities.....: This virus carefully looks for the correct INT 13
                         entry to avoid being trapped by a guardian.
--------------------- Agents -----------------------------------------
Countermeasures.....:
- ditto - successful:
             Removal: Not always possible: a 'NE' type EXE will not
                         work anymore.
Standard means......:
--------------------- Acknowledgement --------------------------------
Location............: Micro-BIT Virus Center, Univ Karlsruhe, Germany
Classification by...: Christoph Fischer
Documentation by....: Christoph Fischer
Date................: January 25, 1992
===================== End of Amilia Virus ============================
===== Computer Virus Catalog 1.2: AntiCAD Virus (31-January-1992) ====
Entry...............: AntiCAD Virus
Alias(es)...........: AntiCAD-4096 = Invader Virus
Virus Strain........: Jerusalem Virus Strain, ANTICAD Substrain
Variants............: AntiCAD-A; -B; -C; Chinese; Danube (Donau);
                         Mozart Viruses
Virus detected when.: August 1990
              where.: Australia
Classification......: Program (COM, EXE) & System (Boot, Master Boot)
                         infector; memory resident
Length of Virus.....: 1) Length on media: 4,096 bytes on COM & BOOT;
                                          4,096-4,111 bytes on EXE
                      2) Length in memory: 5,120 bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS and compatible OS
Version/Release.....: MS-DOS 3.0 and upwards
Computer model(s)...: IBM and compatible PCs
--------------------- Attributes -------------------------------------
Easy Identification.: Virus contains text:
                        "NO SYSTEMDISK...PLEASE INSERT..."
Type of infection...: Depending on type of victim:
                         COM: Prepending but COMMAND.COM not infected;
                         EXE: Appending  but ACAD.EXE not infected;
                         BOOT: any diskette without write protection;
                         Master-BOOT: all HD-Drives.
Infection Trigger...: Any Load/Execute operation
Media affected......: All kinds (disks, any diskette)
Interrupts hooked...: 08h (Timer), 09h (Keybord), 13h (Disk),
                         21h (DOS-Calls), 24h (error handler).
Damage..............: Transient: the virus plays some music (variants
                         may play noise), and system is slowed down.
                         This routine activates
                      Permanent: If CTRL-ALT-DEL is pressed while
                         music is playing or ACAD is loaded, *all in-
                         formation on all disks will be overwritten*.
                         CMOS-entries will be deleted.
Damage Trigger......: Transient damage: in original ANTICAD virus,
                         transient damage (playing music, system slow-
                         down) is activated 30 minutes after virus'
                         activation. In ANTICAD variants, activation
                         of transient damage (music/noise) may be de-
                         layed between 7 and 30 days.
                      Permanent damage: one of the following activi-
                         ties will activate permanent damage (over-
                         writing disk media, deleting CMOS entries):
                            P1) pressing CTRL-ALT-DEL when
                                music/noise is played;
                            P2) execution of ACAD;
                            P3) after about 4000 keystrokes.
                         These effects may not be activated every
                         time as activation also depends on several
                         internal triggers.
Particularities.....: ---
Similarities........: Viruses in same (Jerusalem) strain, and esp.
                         those in same (AntiCAD) substrain.
--------------------- Agents -----------------------------------------
Countermeasures.....: According to their documentation, many antivirus
                         products claim recognise and eradicate virus.
-ditto- successful..: Tested: Dr.Solomon's Toolkit, Fridrik Skulason's
                         F-PROT.
Standard means......: 1) Reboot from clean bootdisk.
                      2) Delete all infected files.
                      3) Use SYS-Command to reinstall BOOT sector.
                      4) Use FDISK /MBR to reinstall Master-BOOT
                         sector (MS-DOS 5.0 only).
--------------------- Acknowledgement --------------------------------
Location............: Virus-Test-Center, University Hamburg, Germany
Classification by...: Matthias Jaenichen
Documentation by....: Matthias Jaenichen
Date................: 31-January-1992
Information Source..: Disassembly, "PC Viruses" by A.Solomon,
                      "VSUM" (P.Hofmann)
===================== End of ANTICAD Virus ============================
==== Computer Virus Catalog 1.2: Dedicated Virus (31-January 1992) ===
Entry...............: Dedicated Virus
Alias(es)...........: ---
Virus Strain........: ---
Polymorphism engine.: Mutating Engine (ME) 0.9
Virus detected when.: UK
              where.: January 1992
Classification......: Polymorphic encrypted program (COM) infector,
                         non-resident
Length of Virus.....: 3,5 kByte (including Mutating Engine)
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM - PCs, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: COM file growth (no other direct detection means
                         are known as virus encrypts itself, and due
                         to the installed mutation engine, all occu-
                         rences of this virus differ widely)
Type of infection...: COM file infector: all COM files in current
                         directory on current drive (disk,diskette)
                         are infected upon executing an infected file.
Infection Trigger...: Execution of an infected COM file.
Media affected......: Hard disk, any floppy disk
Interrupts hooked...: ---
Crypto method.....: The virus encrypts itself upon infecting a COM
                         file using its own encryption routine; upon
                         execution, the virus decrypts itself using
                         its own small algorithm.
Polymorphic method..: After decryption, the virus' envelope consisting
                         of Mutating Engine 0.9 will widely vary the
                         virus' coding before newly infecting another
                         COM file. Due to this method, common pieces
                         of code of more than three bytes (=signatures)
                         of any two instances of this virus are highly
                         improbable.
                      Remark: Mutating Engine 0.9 very probably was
                         developped by the Bulgarian virus writer
                         "Dark Avenger"; such a program was announced
                         early 1991 as permutating more than 4 billion
                         times, and it appeared in October 1991 or
                         before.
                         The class of permutating viruses is named
                         "polymorphic" to indicate the changing
                         structure which may not be identified with
                         contemporary means. To indicate the relation
                         to such common engine, the term "Polymorhic
                         engine (method)" has been introduced.
                         ME 0.9 was distributed via several Virus
                         Exchange Bulletin Boards, so it is possible
                         that other ME 0.9 related viruses appear.
                         According to (non-validated) information, an-
                         other ME 0.9 based virus (Pogue?) has been
                         detected in North America: COM file infector,
                         memory resident, length about 3,7 kBytes.
Damage..............: Virus overwrites at random times random sectors
                         (one at a time) with garbage (INT 26 used).
Damage Trigger......: Random time
Similarities........: ---
Particularities.....: The virus contains a text greeting a US based
                         female hacker; this text is visible after
                         decryption.
--------------------- Agents -----------------------------------------
Countermeasures.....: Contemporarily, no automatic method for reliable
                         identification of polymorphic viruses known.
- ditto - successful: ---
Standard means......: ---
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Vesselin Bontchev, Klaus Brunnstein
Documentation by....: Dr. Alan Solomon
Date................: 31-January-1992
===================== End of Dedicated Virus =========================
====== Computer Virus Catalog 1.2: FEXE Virus (31-January-1992) ======
Entry...............: FEXE = FEXE 1.0 Virus
Alias(es)...........: ---
Virus Strain........: FICHV Virus Strain
Virus detected when.:
              where.:
Classification......: Program (EXE) infector, memory resident
Length of Virus.....: 1. Length on media:    897 ($381) bytes;
                      2. Length in memory: 2,288 bytes.
--------------------- Preconditions -----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: DOS 2 and upwards
Computer model(s)...: IBM PC/AT & compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: Infected files are 897 bytes longer than clean
                         EXE files. Free memory space was decreased
                         by 2288 bytes. File time is set to 62 seconds.
                         In memory, the text "** FEXE 1.0 vous a eu **"
                         can be found (28 bytes below Int_21 entrypoint)
Signature...........: AC 32 07 AA 43 3B DA 72 03 BB
                      Remark: this string is a pert of the virus'
                         decryption routine, but is rather unique due
                         to its programming error.
Type of infection...: The virus appends itself to the end of an EXE
                         file and changes the EXE-header.
Infection Trigger...: Whenever an infected file is executed, the virus
                         will go resident and thereby infect the first
                         uninfected EXE-file (found via "Search First",
                         "Search Next"). Upon any "Execute" or "Open
                         file" operation (INT 21, ah=$4B/$3D), virus
                         will infect the first uninfected EXE-file in
                         the same manner.
Storage media affected: EXE files on any disk/diskette
Interrupts hooked...: INT 21 (functions ah=$4B, ah=$3D)
Damage..............: Virus will overwrite the first 6 sectors on both
                         sides of each track, starting from track 0,
                         with the text "** FEXE 1.0 vous a eu **".
Damage Trigger......: Activating an infected file during April (any
                         year).
Particularities.....: Virus uses a simple self-encryption, which was
                         possibly planned as a complex decryption,
                         but due to a programming error operates only
                         in a simple manner (XOR). It always uses
                         standard INT 21 functions (including
                         "Terminate/stay resident": ah=$31).
Similarities........: FICHV viruses (which infect COM files only).
--------------------- Agents -----------------------------------------
Countermeasures.....: No countermeasures known.
Countermeasures successful: Dito. (Tested antivirus do not detect it)
Standard means......: Delete infected EXE files & install clean ones.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Toralv Dirro
Documentation by....: Toralv Dirro
Date................: 31-January-1992
Information Source..: In-depth analysis of virus code
===================== End of FEXE Virus ==============================
==== Computer Virus Catalog 1.2: FICHV 2.0 Virus (31-January-1992) ===
Entry...............: FICHV 2.0 Virus
Alias(es)...........: ---
Virus Strain........: FICHV Virus Strain
Virus detected when.:
              where.:
Classification......: Program (COM) infector, memopry resident
Length of Virus.....: 1. Length on media:    896 ($380) bytes;
                      2. Length in memory: 1,248 bytes.
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: DOS 2 and upwards
Computer model(s)...: IBM PC/AT & compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: Infected files are 896 bytes longer than clean
                         COM files. The amount of free RAM is decreased
                         by 1248 bytes. File time is set to 62 seconds.
                         In memory,the text "****FICHV 2.0 vous a eu**"
                         can be found (690 Bytes below Int 21 entry
                         point).
Signature...........: AC 32 07 AA 43 3B DA 72 03 BB
                      Remark: this string is a pert of the virus'
                         decryption routine, but is rather unique due
                         to its programming error.
Type of infection...: The virus appends the first 896 bytes of an in-
                         fected program to the end of the COM file,
                         then overwriting the first 896 bytes.
Infection Trigger...: Whenever an infected file is executed, the virus
                         will go resident and thereby infect the first
                         uninfected EXE-file (found via "Search First",
                         "Search Next"), if the free disk space is
                         >3,000 bytes and the file is longer than
                         1,500 bytes.
                      When the virus is resident, whenever INT 21
                         "Execute" ($4B) is called, the virus will
                         infect the first uninfected COM-file.
Storage media affected: COM files on any disk/diskette
Interrupts hooked...: INT 21 (function ah=$4B).
Damage..............: Virus will overwrite the first 6 sectors on both
                         sides of each track, starting from track 0,
                         with the text "****FICHV 2.0 vous a eu**".
Damage Trigger......: Execution of an infected program during March
                         (any year).
Particularities.....: Virus uses a simple self-encryption, which was
                         possibly planned as a complex decryption,
                         but due to a programming error operates only
                         in a simple manner (XOR). It always uses
                         standard INT 21 functions (including
                         "Terminate/stay resident": ah=$31).
                      Side effect #1: The virus does not check if the
                         file to be infected is smaller than 64,640
                         bytes; therefore, an infected COM file may
                         grow larger than 65,535 bytes and then cannot
                         be executed any longer.
                      Side effect #2: Virus overrides memory at
                         location 6000:0; therefore, conflicts (crash)
                         with other TSR's are possible.
Similarities........: FICHV 2.1, FEXE virus
--------------------- Agents -----------------------------------------
Countermeasures.....: F-Prot 2.02 suspects that virus be a new variant
                         of the FICHV-Virus.
Countermeasures successful: None at classification time.
Standard means......: Delete infected files.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Toralv Dirro
Documentation by....: Toralv Dirro
Date................: 31-January-1992
Information Source..: In-depth analysis of virus code
===================== End of FICHV 2.0 Virus =========================
==== Computer Virus Catalog 1.2: FICHV 2.1 Virus (31-January-1992) ===
Entry...............: FICHV 2.1 Virus
Alias(es)...........: 903 Virus
Virus Strain........: FICHV Virus Strain
Virus detected when.:
              where.:
Classification......: Program (COM) infector, memopry resident
Length of Virus.....: 1. Length on media:    903 ($387) bytes;
                      2. Length in memory: 1,264 bytes.
Length of Virus.....:
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: DOS 2 and upwards
Computer model(s)...: IBM PC/AT & compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: Infected files are 903 bytes longer than clean
                         COM files. The amount of free RAM is decreased
                         by 1264 bytes. File time is set to 62 secons.
                         In memory,the text "****FICHV 2.1 vous a eu**"
                         can be found (693 Bytes below the Int 21
                         entry point).
Signature...........: AC 32 07 AA 43 3B DA 72 03 BB
                      Remark: this string is a pert of the virus'
                         decryption routine, but is rather unique due
                         to its programming error.
Type of infection...: The virus appends the first 903 Bytes of an in-
                         fected program to the end of the file, then
                         overwriting the first 903 bytes.
Infection Trigger...: Whenever an infected file is executed, the virus
                         will go resident and thereby infect the first
                         uninfected EXE-file (found via "Search First",
                         "Search Next"), if the free disk space is
                         >3,000 bytes and the file is longer than
                         1,500 bytes.
                      When the virus is resident, whenever INT 21
                         "Execute" ($4B) or "Open a File" ($3D) is
                         called, the virus will infect the first
                         uninfected COM-file.
Storage media affected: COM files on any disk/diskette.
Interrupts hooked...: INT 21 (functions ah=$4B and ah=$3D).
Damage..............: Virus will overwrite the first 6 sectors on both
                         sides of each track, starting from track 0,
                         with the text "****FICHV 2.1 vous a eu**".
Damage Trigger......: Execution of an infected program during March
                         (nay year).
Particularities.....: Virus uses a simple self-encryption, which was
                         possibly planned as a complex decryption,
                         but due to a programming error operates only
                         in a simple manner (XOR). It always uses
                         standard INT 21 functions (including
                         "Terminate/stay resident": ah=$31).
                      Side effect #1: The virus does not check for a
                         maximum length of the file to be infected, so
                         the infected files might grow bigger than
                         65,535 bytes and then cannot be executed
                         any longer.
                      Side effect #2: Virus overrides memory at
                         location 6000:0; therefore, conflicts (crash)
                         with other TSR's are possible.
Similarities........: FICHV 2.0, FEXE virus
--------------------- Agents -----------------------------------------
Countermeasures.....: F-Prot v 2.02 recognizes the virus as "FICHV
                         virus"; Scan v85 recognizes it as
                         "903 virus".
Countermeasures successful: Dito.
Standard means......: Delete infected files.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Toralv Dirro
Documentation by....: Toralv Dirro
Date................: 31-January-1992
Information Source..: In-depth analysis of virus code
===================== End of FICHV 2.1 Virus =========================
==== Computer Virus Catalog 1.2: Hafenstrasse Virus (20-Nov-1991) ====
Entry...............: Hafenstrasse Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: 22-October-1991
              where.: Hamburg, Germany
Classification......: Program virus, non-resident, EXE-infector
Length of Virus.....: 809 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM - PC, XT, AT and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: ---
Type of infection...: The virus infects only EXE files. The virus
                         is not memory-resident.
Infection Trigger...: The virus infects in direct action; when an in-
                         fected program is run, virus tries 5 times
                         to find a file to infect, but will only in-
                         fect one file at a time.
Interrupts hooked...: ---
Damage..............: The message "Hafenstrasse bleibt !" is written
                         to a hidden file. The name of the file is
                         composed of 4 randomly-chosen letters. Even
                         though this seems to be fairly harmless,
                         this will eventually fill the disk, or the
                         capacity of the directory may be exceeded.
                      Remark: the text "Hafenstrasse bleibt!" (=har-
                         bour street remains) is a slogan which some
                         inhabitants (belonging to an "alternative
                         scene") of Hamburg's "harbour street" use
                         to publicly withstand local government plans
                         to replace their old houses by new ones.
Damage Trigger......: A new file is created every time an infected
                         file is run.
Particularities.....: The text is encrypted (only the text).
--------------------- Agents -----------------------------------------
Countermeasures.....: ---
- ditto - successful: ---
Standard means......: ---
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Morton Swimmer
Documentation by....: Morton Swimmer
Date................: 20-November-1991
===================== End of Hafenstrasse Virus ======================
== Computer Virus Catalog 1.2: Michelangelo Virus (31-January-1992) ==
Entry...............: Michelangelo Virus
Alias(es)...........: Nina Turtle Virus (in Taiwan)
Virus Strain........: Stoned Virus Strain
Virus detected when.: Summer 1991
              where.:
Classification......: System virus (boot, partition table), resident
Length of Virus.....: Fits well into code space of partition table
                      Memory: 2,048 bytes just below end of DOS
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM - PC, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: ---
Direct Detection....: Original partition table or original boot sector
                         can be found in sector 7 of a hard disk
                         and specific sectors of 5.25"/3.5" diskette.
                      CHKDSK "total memory bytes" shows that available
                         memory is reduced by 2,048 bytes.
Type of infection...: Upon booting from an infected floppy, virus will
                         make itself memory resident and infect par-
                         tition table. Any INT13 is intercepted there-
                         after. Any floppy A: operation will infect
                         disk in drive A: provided the motor was off;
                         this reduces excessive infection testing.
Infection Trigger...: Booting from an infected disk will infect a com-
                         puter. Usage of the floppy A: drive (read,
                         write, or format) can cause an infection of
                         that medium.
Infection targets:..: Partition table of harddisks and bootsectors
                         of floppy disks.
Interrupts hooked...: INT 13
Damage..............: Data destruction by overwriting the medium, from
                         which system was booted from: on harddisks,
                         virus will overwrite sector 1-17 on head 0-3
                         of all tracks; on floppies, virus will over-
                         write sector 1-9 or 1-14 (depending on FAT
                         type) on both heads and all tracks.
Damage Trigger......: Data destruction occurs when system's date
                         equals March 6 of any year. This is birthdate
                         of Michelangelo Buonarotti, Italian artist,
                         architect and engineer (born March 6, 1475
                         in Caprese, died February 18, 1564 in Rome)
                      Remark: there is *no evidence* in the virus
                         that it's programmer related March 6 to
                         Michelangelo B.; the name probably is the
                         interpretation of the first person to
                         (possibly partially) analyse this virus.
Similarities........: Virus seems to be an enhanced Stoned virus
Particularities.....: 1) Virus uses BIOS directly.
                      2) As virus overwrites hard disk sector 7, it
                         may also affect other operating systems which
                         use an infected disk.
--------------------- Agents -----------------------------------------
Countermeasures.....:
- ditto - successful: Fridrik Skulason's F-PROT and Dr. Solomon's
                         FINDVIRU detect and eradicate this virus.
Standard means......: Boot from a clean disk and move original sector
                         to its proper location (sector 1, head 0,
                         track 0). On systems where an early FDISK (no
                         hidden sectors) was used to low-level format
                         hard disk, FAT copy 1 might be damaged; an
                         additional copying of FAT 2 onto FAT 1 might
                         then be necessary.
--------------------- Acknowledgement --------------------------------
Location............: Micro-BIT Virus Center, Univ.Karlsruhe, Germany
Classification by...: Christoph Fischer
Documentation by....: Christoph Fischer
Date................: 17-September-1991
Update..............: Padgett Patterson, Orlando/Florida (31-Jan-1992)
===================== End of Michelangelo Virus ======================
===== Computer Virus Catalog 1.2: Plovdiv 1.3 Virus (31-Jan-1992) ====
Entry...............: Plovdiv 1.3 Virus
Alias(es)...........: Damage 1.3 Virus
Virus Strain........: Damage Virus Strain
Virus detected when.: September 1991
              where.: Plovdiv, Bulgaria
Classification......: Program virus, Extending, Resident
Length of Virus.....: 1,000 in files, 1,328 bytes in memory
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx and upward, special support for 3.30
Computer model(s)...: IBM-PC, XT, AT and compatibles
--------------------- Attributes -------------------------------------
Easy identification.: The virus contains the string
                         "(c)Damage inc. Ver 1.3 1991 Plovdiv S.A.".
Type of infection...: Self-Identification: The virus identifies
                         infection by seconds field in file time.
                      Executable Files: Size increased by 1,000 bytes.
                      System infection: RAM-resident. Allocates a
                         memory block at high end of memory by
                         1,344 bytes. If MS-DOS version is 3.30, virus
                         finds original address of INT 21h and INT 13h
                         handlers, thus bypassing active monitors.
Infection Trigger...: Programs are infected at load time (using the
                         function Load/Execute of MS-DOS), and when-
                         ever a *.COM or *.EXE file is Opened.
Media affected......: Any logical drive that is the "current" drive.
Interrupts hooked...: INT 21h functions 4Bh, 3Dh are used to infect
                         files. Functions 11h and 12h are used to hide
                         virus infection in files.
                      INT 24h and INT 13h are temporary captured to
                         mask out errors.
                      INT 32h contains original INT 21h handler.
Damage..............: The virus formats all available tracks on the
                         current drive.
Damage trigger......: The virus carries an evolution counter that
                         is decreased every time the virus is executed.
                         Upon counter = 0, the virus reads the system
                         timer. If the value of hundreds is greater
                         than 50, the virus will format all available
                         tracks on the current drive (effectively a
                         50% chance of destruction). "Current" drive
                         is any logical drive on which file is opened,
                         executed or searched thru FindFirst/FindNext.
Particularities.....: The virus knocks out the transient part of
                         COMMAND.COM forcing it to be reloaded and
                         thereby infected.
Similarities........: Damage 1.1 Virus
--------------------- Agents -----------------------------------------
Countermeasures.....: VirusClinic 2.00.007+ (Ivan Trifonoff)
Countermeasures successful: VirusClinic 2.00.007+ (Ivan Trifonoff)
Standard means......: text search of string "Damage"
--------------------- Acknowledgement --------------------------------
Location............: Laboratory of Computer Virology,
                      Bulgarian Academy of Sciences, Sofia
Classification by...: Ivan Trifonoff
Documentation by....: Ivan Trifonoff
Date................: 2-October-1991
Information Source..: ---
===================== End of Plovdiv 1.3 - Virus =====================
======= Computer Virus Catalog 1.2: Semtex Virus (31-Jan-1992) =======
Entry...............: Semtex Virus
Alias(es)...........: Screen Trasher Virus
Virus Strain........:
Virus detected when.: September 1991
              where.: Germany
Classification......: Program (appending) virus, resident
Length of Virus.....: 1,000 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 1.xx upward
Computer model(s)...: IBM - PC, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Direct Detection....: Every hour, the screen is overwritten by trash.
Easy Identification.: Infected files will contain the string:
                       "  S E M T E X  by Dusan Toman, CZECHOSLOVAKIA"
                       " (7)213-040 or (804)212-23  "
Type of infection...: All *.COM that are executed or opened will be
                         infected if their length <= 61,000 Bytes.
                         COMMAND.COM will also be infected; there is
                         explicit code in the virus that exploits
                         the comspec.
Infection Trigger...: Any Load/Execute or Open of a *.COM file.
Infection targets:..: All *.COM files with length <= 61,000 Bytes.
Interrupts hooked...: INT 08 (hooked); INT 10, INT 21 (used);
                      INT 61 (occupied)
Damage..............: At an hourly intervall, virus will trash screen
                         contents by overwriting with garbage.
Damage Trigger......: A Counter that counts the timer tics.
Similarities........: ---
Particularities.....: 1) This virus does not intercept INT 24, so a
                         write error will occur upon each infection
                         attempt.
                      2) Windows 3.0 will not like what virus does
                         to the memory allocation.
                      3) INT 61 usage will render the following pro-
                         ducts inoperative:
                            Atari Portfolio (system management)
                            HP 95LX System (system management)
                            JPI topspeed modula (procedure exit trap)
                            FTP PC/TCP (function calls)
                            Adaptec and Omti controller
                            Banyan Vines (network)
                            Sangoma CCIP (CCPOP3270)
--------------------- Agents -----------------------------------------
Countermeasures.....:
- ditto - successful:
Standard means......:
--------------------- Acknowledgement --------------------------------
Location............: Micro-BIT Virus Center, Univ Karlsruhe, Germany
Classification by...: Christoph Fischer
Documentation by....: Christoph Fischer
Date................: 31-January-1992
===================== End of Semtex Virus ============================
==== Computer Virus Catalog 1.2: Sverdlov Virus (31-January-1992) ====
Entry................: Sverdlov Virus
Alias(es)............: Hymn = Hymn of USSR Virus
Virus Strain.........: 1990
Virus detected when..: USSR
              where..: September 1991
Classification.......: Program virus, postfix, memory resident
Length of Virus......: On media: 1,974 bytes
---------------------- Preconditions ---------------------------------
Operating System(s)..: MS-DOS and compatible
Version/Release......: 3.0 and upwards
Computer model(s)....: IBM and compatible PC/XT/AT upwards
---------------------- Attributes ------------------------------------
Easy Identification..: Infected files grows by 1,971 bytes.
Type of infection....: Program infector: The virus will make itself
                          memory-resident and infect infect every
                          program which uses INT21 (functions 3c,
                          3d, 3e, 43, 4b)
Infection Trigger....: At any time but not if system date's Day=Month
Media affected.......: Any (hard disk, floppy disk)
Interrupts hooked....: INT 21h, INT 1Ch, INT 24h
Damage...............: Permanent: ---
                       Transient: The virus shows a nice spectacle
                          on the screen, in displaying a V-shaped
                          window in different colors; inside the
                          window you, the text is displayed:
                          " USSR (c) 1991 ". Moreover, the national
                          anthem of USSR is played.
Damage Trigger.......: When becoming memory resident, virus sets a
                          random number. When random number=1,
                          damage is triggered.
Particularities......: ---
Similarities.........: ---
--------------------- Agents ------------------------------------------
Countermeasures......: ---
  - dito - successful: Tested: Fridrik Skulason's F-PROT
Standard means.......: ---
--------------------- Acknowledgement ---------------------------------
Location............: Virus Test Center, University Hamburg, Germany
                           and Technical University Dresden, Germany
Classification by...: Frank Schwarz
Documentation by....: Frank Schwarz
Date................: 31-January-1992
Information Source..: ---
===================== End of Sverdlov Virus ==========================
===== Computer Virus Catalog 1.2: VDV-853 Virus (31-January-1992) ====
Entry................. VDV-853 Virus
                       (VDV = "Verband Deutscher Virenliebhaber";
                            = "community of German virus lovers")
Alias(es)............. ---
Strain................ VCS Virus Strain
Detected: when........ December 1991
          where....... Hamburg, Germany
Classification........ Program (COM) infector, encrypted, appending,
                         direct action; not memory resident
Length of Virus....... on media: 853 bytes
---------------------- Preconditions ---------------------------------
Operating System(s)... MS/PC-DOS 2.x upwards
Computer models....... All IBM PC/AT compatibles with CPU > 8088.
---------------------- Attributes ------------------------------------
Easy identification... ---
Signature............. Search string at offset 00h:
                       E8 14 00 8A A4 4F 04 8D BC 20 01 B9 2F 03 89 FE
Type of infection..... Self-identification: files containing C350h at
                          offset 03h regarded as infected.
                       EXE files: no infection.
                       COM files: are infected only once. Files are
                          randomly infected in the current directory
                          or in root directory and below if word at
                          offset 03h of file doesnot contain C350h.
                          File size is increased by 853 bytes. Virus
                          is not RAM resident; files can only be in-
                          fected when an infected host is started.
Infection trigger..... Any time an infected file is run, the virus
                          infects up to 10 files, but only if the
                          INT 26h (=absolute-disk-write-vector) is
                          not hooked.
Affected media........ Files on hard disk or any diskette.
Interrupts hooked..... ---
Damage................ Permanent damage: when triggered, all files in
                          the root directory will be overwritten with
                          273 bytes of text including a Christmas tree
                          and message (see Particularities).
                       Transient Damage: when the file has been over-
                          written, message (see: Particularities) will
                          be displayed until a key is pressed.
Damage trigger........ Permanent or transient damage is activated when
                          month of system date = December and day of
                          system date = 24, 25 or 26 (Christmas).
Particularities....... 1) Virus is encrypted; upon each infection, en-
                          cryption key is changed.
                       2) Virus uses opcode 68h (push constant on
                          stack) which isnot defined on 8088 processors;
                          so, virus will not work on such machines.
                       3) Files with ReadOnly attribute will not be
                          infected.
                       4) VDV-853 virus was written by some "Verband
                          Deutscher Virenliebhaber" (=community of
                          German virus lovers). This virus is realated
                          to VCS virus (see Catalog edition July 91)
                          but may have been created before the release
                          of the VCS 1.0.
                          The following message can be found in over-
                          written (damaged) files and will be display-
                          ed under damage trigger conditions:
                          "Froehliche Weihnachten wuenscht
                                 der Verband Deutscher Virenliebhaber
                           Ach ja, und dann wuenschen wir auch noch
                           viel Spasz beim Suchen nach den Daten von
                           der Festplatte!
                           gez. VDV, Dezember 1990."
                           Translation:
                          "Happy Christmas wishes the community of
                           German virus lovers
                           Oh yes, and then we wish you a lot of fun,
                           by searching for your data on your
                           harddisk!"
                           Yours  VDV, December 1990.";
                           On the left side of the message, a stylized
                           Christmas tree is displayed in textgraphic.
Similarities........... 1) Virus is similar to VCS 1.0 virus and uses
                           the same code, except that damage routine
                           and some address functions are changed.
                        2) In distinction to VCS 1.0 virus, VDV-853
                           has no generation counter and a different
                           damage routine. Probably, is was not
                           created with Virus Construction Set 1.0
---------------------- Agents ----------------------------------------
Countermeasures.......
 - ditto -   successful. Solomon's Findviru V4.01 detects as VDV-853.
                         Skulason's F-PROT V2.02  detects as VDV-853.
                         Tode's NTI-VDV.EXE is an antivirus that only
                            looks for VDV-853 virus, and if requested
                            will restore the original file.
 - ditto - unsuccessful. McAfee's Scan version 86b and below
Standard Means........ Notice file length. Use ReadOnly attribute.
                       Or use FLU-Shot or another program, which
                       monitors INT 26h.
---------------------- Acknowledgements ------------------------------
Location.............. Virus Test Center, University Hamburg, Germany
Classification by..... Stefan Tode
Documentation by...... Stefan Tode
Date.................. 31-January-1992
Information source.... ---
====================== End of VDV-853 Virus ==========================
======= Computer Virus Catalog 1.2: Violetta Virus (25-Jan-1992) =====
Entry...............: Violetta Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: January 1992
              where.:
Classification......: Program virus, resident
Length of Virus.....: 3,840 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM - PC, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: Infected files will contain the string
                         "VIOLETTA" twice (offset 2H and 202H in file)
Type of infection...: All *.COM files except COMMAND.COM when executed
                         will be infected. The virus saves the first
                         3,840 bytes of the host to the end of the file
                         and overwrites the first 3,840 bytes with the
                         virus code. Files smaller than 3,840 bytes
                         are first enlarged to 3,840 bytes.
Infection Trigger...: Load and Execute of a *.COM file.
Infection targets:..: All *.COM files except COMMAND.COM
Interrupts hooked...: INT 21
Interrupts used.....: INT F1, INT FF both used, but not chained; this
                         might cause trouble with Zenith Z100 warm
                         boot procedure.
Damage..............: No active payload
Damage Trigger......: ---
Similarities........: ---
Particularities.....: Unusual coding, much dead code, several code
                         sections overwritten with NOPs.
--------------------- Agents -----------------------------------------
Countermeasures.....:
- ditto - successful:
             Removal: Not always possible: correct size of files
                         smaller than 3,840 cannot be restored.
Standard means......:
--------------------- Acknowledgement --------------------------------
Location............: Micro-BIT Virus Center, Univ Karlsruhe, Germany
Classification by...: Christoph Fischer
Documentation by....: Christoph Fischer
Date................: January 25, 1992
===================== End of Violetta Virus ==========================
==== Computer Virus Catalog 1.2: ZeroHunt Virus (31-January-1992) ====
Entry................. ZeroHunt Virus
Clones................ ZeroHunt-415, ZeroHunt-411 (minor variations)
Alias(es)............. Minnow, Minnow-1 Virus
Strain................ Zero-Hunt Virus Strain
Detected: when........
          where.......
Classification........ Program (COM) infector, but not increasing;
                          stealth, indirect action, memory resident
Length of Virus....... 1) Length on media:  no increase in file length
                       2) Virus code in memory/inside file:
                              Length (ZeroHunt-411) = 411 bytes;
                              Length (ZeroHunt-415) = 415 bytes;
---------------------- Preconditions ---------------------------------
Operating System(s)... MS/PC-DOS 2.x and upwards
Computer models....... All IBM PC compatibles.
---------------------- Attributes ------------------------------------
Easy identification... ---
Type of infection..... EXE files: not infected;
                       COM files: are infected only once.
                       Self-identification: files containing F5E9h
                          at begin of file, and containing E8h at
                          memory address 0:021Ch are regarded as
                          infected.
                        Virus searches for 411/415 bytes, depending
                           on the clone, for 00h's; if found (typic-
                           ally a buffer), virus copies itself into
                           this part of file: therefore, size of in-
                           fected files do not increase!
                        Virus makes itself RAM resident and copies
                           itself into the interrupt table (in low
                           memory at location 0:021Ch, INT 87h).
                        Files are infected when executed.
Infection trigger.....  Any file, which is executed via function 4B00h
                           of INT 21h, will be infected, only if 1st
                           byte of file is E9h and if 411/415 bytes
                           containing 00h's are found.
Interrupts hooked..... INT 21h (always pointing to 0:02D5h);
                       INT 24h (during infection);
                       INT 8Bh (points to EE83:019Bh for ZH-411 virus,
                                and to    EE83:019Fh for ZH-415 virus).
Damage................ No intentional damage.
                       Side effect: system or programs may hang, if
                          they are using the interrupt table as a
                          buffer or if they are using Interrupts
                          > INT 87h (possibly BASIC or LAN Adapters).
                       Moreover, files may get corrupted if one variant
                          tries to infect a file while the other vari-
                          ant is yet active in memory. If ZeroHunt-415
                          is active in memory, 4 bytes of a file in-
                          fected with ZeroHunt-411 will be corrupted
                          (4 bytes overwritten with 00h).
Damage trigger........ ---
Particularities....... Stealth method: Virus cannot be found in an
                          infected file, because it monitors all DOS
                          read access functions and may temper them
                          (detail: INT 21h fct. 14h not monitored),
                          thus removing itself from an infected file.
                       Virus may also hook Interrupts > 87h (due to
                          the location of virus).
Similarities.......... ZeroHunt-411 is an optimized version of
                          ZeroHunt-415; due to this optimization,
                          some code/data differs.
---------------------- Agents ----------------------------------------
Countermeasures.......
- ditto - successful.. McAfee's Scan version 85+ (both variants)
                       Solomon's FindViru V4.01+ ( "      "    )
                       Skulasons F-PROT V.2.02 recognizes:
                          ZeroHunt.415 correctly, disinfects wrongly;
                          ZeroHunt.411 as new variant.
Standard Means........ Easy disinfection (only if virus is active in
                          memory): copy all *.COM files to different
                          extension (maybe *.MOC), then reboot system
                          from an clean disk and then rename all *.MOC
                          files back to *.COM.
---------------------- Acknowledgements ------------------------------
Location.............. Virus Test Center, University Hamburg, Germany
Classification by..... Stefan Tode
Documentation by...... Stefan Tode
Date.................. 31-January-1992
Information source.... Full reverse engineering of both viruses
====================== End of Zerohunt Virus =========================
======== Computer Virus Catalog 1.2: Akuku Virus (25-July-1992) ======
Entry...............: Akuku virus
Standard CARO name..: Akuku.completely
Alias(es)...........: Russian-A
Virus Strain........: Akuku virus strain
Virus detected when.: ---
              where.: ---
Classification......: Program (COM,EXE) virus, non memory resident
Length of Virus.....: 1. Length in RAM:     1108 bytes
                      2. Length in program: 1111-1114 bytes
--------------------- Preconditions -----------------------------------
Operating System(s).: MS-DOS, PC-DOS
Version/Release.....: version 2.xx and higher
Computer model(s)...: IBM-PC, XT, AT and compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: Virus contains string "Sorry, I'm completely dead."
                      Seconds field in file's time set to 62.
Type of infection...: Installs itself memory-resident when infected
                         program is run. Infects both .EXE and .COM
                         files, including COMMAND.COM, by appending
                         itself to end of file. EXE files are increased
                         by 1114 (45Ah) bytes, COM files by 1111 (457h)
                         bytes, but this amount may increase by up to
                         15 (0Fh) bytes as padding for paragraph align-
                         ment.
Infection Trigger...: Upon running infected file, disk must have 3000
                         (BB8h) bytes of free space. EXE files must be
                         larger than 1000 (3E8h) bytes; COM files must
                         be larger than 1000 (3E8h), but smaller than
                         64000 (FA00h) bytes.
Self Identification.: On disk, virus checks if seconds field of file
                         is set to 62.
Damage..............: Transient damage: virus will display message
                         "Sorry, I'm completely dead.". Virus installs
                         payload in memory, which plays a song.
                      Permanent damage: ---
Damage Trigger......: Trigger for damage is the current time at in-
                         fection time. If the minutes field is one of:
                         32, 33, 34 or 35, the virus displays "Sorry,
                         I'm completely dead, installs the song and
                         plays it every 14 seconds.
Particularities.....: 1. The file date and time will not be altered
                         in the disk directory, except for the seconds,
                         which will be set to 62.
                      2. The drive to be infected is selected according
                         to this rule: if the current time's seconds
                         is =0, select drive A:; if it is >0, but <=22
                         the current drive is selected, and if it is
                         >22, C: is selected.
                      3. Virus will search the whole current directory
                         for files to infect, as well as the first
                         level of all of it's subdirectories. It will
                         infect the first 3 files found. Default
                         drive is reset to the correct drive.
                      4. Virus installs the whole virus body in memory,
                         although only the song is active.
Similarities........: Very similar to Akuku.3 and Cop-Mpl viruses.
                         All Akuku viruses try to infect three files
                         in directory of current disk, but differ on
                         what happens if they cannot be found.
                      The identification by 62 seconds field is similar
                         to Vienna viruses.
--------------------- Agents ------------------------------------------
Countermeasures.....: F-Prot, Anti-Virus Toolkit, ViruScan
Countermeasures successful: F-Prot, Anti-Virus Toolkit
Standard means......: ---
--------------------- Acknowledgement ---------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Christopher G. Street (guest from Brown Univ)
Documentation by....: Christopher G. Street (guest from Brown univ)
Date................: June 14, 1992
Information Source..: Original virus code
===================== End of Akuku Virus ==============================
======= Computer Virus Catalog 1.2: Amoeba Virus (25-July-1992) ======
Entry...............: (Maltese) Amoeba Virus
Standard CARO name..: Amoeba
Alias(es)...........: Family-N, Irish, Grain of Sand Virus
Virus Strain........: ---
Virus detected when.: UK
              where.: November 1st, 1991 (upon first triggered damage)
Classification......: Program (COM,EXE) infector, variable encryption,
                         memory resident
Length of Virus.....: 1) Length on media:  2 kByte
                      2) Length in memory: 2 kByte
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM - PCs, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: 1) Enlarged file size: using DIR, compare actual
                         file size with original file size.
                      2) Reduction of available memory by 2k Bytes,
                         using CHKDSK.
                      3) Unencrypted text (AMOEBA) in partition sector.
Type of infection...: Upon executing an infected file, the virus makes
                         itself memory resident in highest available
                         2 kByte. Thereafter, upon reading or executing
                         a non-infected file this will be infected.
                      Self-identification: Virus inspects memory (using
                         a Set Date call with invalid date) whether
                         it is in memory; moreover, it checks whether
                         some antivirus programs (Ross Greenberg's
                         FluShot+ or Virex-PC) or PSQR virus are in
                         memory. If any of these are found, virus does
                         not infect any program. There are unconfirmed
                         reports that this virus checks and deactivates
                         Murphy virus.
Infection Trigger...: Any DOS read or load/execute operation.
Media affected......: Any hard disk and floppy disk.
Interrupts hooked...: INT 24
Crypto method.......: Decryption uses variations of several patterns
                         of instructions, differing for COM and EXE
                         files.
Polymorphic method..: ---
Damage..............: Permanent damage: upon trigger condition, it will
                         overwrite low tracks of a hard disk and any
                         diskette, accompanied by a flashing display,
                         and subsequently hang-up the system. In the
                         overwritten partition sector, the following
                         encrypted text (from Pickering Manuscripts:
                         Blake's Auguries of Innocence, first 4 lines)
                         can be found:
                            "To see a world in grain of sand
                             And a heaven in wild flower,
                             Hold infinity in the palm of your hand
                             And eternity in a hour."
                             The Virus 16/3/91
                         When an infected system is booted, this text
                            is displayed and the system hangs.
                         Moreover, partition sector contains also un-
                            encrypted texts: "AMOEBA", and the message
                            that University of Malta "destroyed 5X2
                            years of human life".
                      Transient damage: ---
Damage Trigger......: November 1st and March 15th, any year.
Similarities........: En/Decryption method similar to V2PX.
Particularities.....: 1) Virus replaces critical error handler INT 24;
                         if virus tries to infect a write-protected
                         diskette, the prompt "Abort, Retry, Fail" is
                         suppressed.
                      2) There is speculation that the uncrypted text
                         may be related to an unhappy fate of 2
                         students of University of Malta, having left
                         after 5 years.
--------------------- Agents -----------------------------------------
Countermeasures.....: McAfee Scan, Skulason F-PROT, Solomon FINDVIRU
                         and some others
Standard means......: Boot from clean system and delete infected files.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Klaus Brunnstein
Documentation by....: Virus Bulletin (Dec.91), Stiller's Virus Report
                         (see: Virus-L Vol.5 Issue 30: Feb.14, 1992)
Date................: 15-February-1992
===================== End of (Maltese) Amoeba Virus ==================
====== Computer Virus Catalog 1.2: Anthrax Virus (25-July-1992) ======
Entry...............: ANTHRAX Virus
Standard CARO Name..: Anthrax Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: July 1990
              where.: Netherlands
Classification......: Program virus: COM, EXE and partition record
                         (MBR) infector, memory-resident
Length of Virus.....: 1040-1096 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....:
Computer model(s)...: IBM-PC, XT, AT and upwards, and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: The following strings can be found in virus body:
                         "(c) Damage Inc", "1990", "ANTHRAX"
Type of infection...: Virus infects COM, EXE and partition record
                         (MBR). After execution of virus' code, it
                         immediately infects MBR but does NOT stay
                         resident. A second copy of the virus is
                         stored in the last 3 sectors of the hard disk,
                         thus overwriting any data stored there.
                      After having been started from the MBR, virus
                         becomes memory-resident until it has infected
                         one file. It infects a file in the lowest
                         branch of the current directory.
                      Anthrax does NOT infect the Bootrecord of a
                         floppy or hard disk.
Infection Trigger...: Execution of infected program.
Storage media affected: Floppies and hard disks.
Interrupts hooked...: INT13h, INT 1Ah, INT 20h, INT 21h, INT 24h
Damage..............: Transient damage: ---
                      Permanent damage: virus overwrites last 3 sec-
                         tors of hard disk (with it's 2nd copy).
Damage Trigger......: ---
Particularities.....: Virus V2100 installs ANTHRAX in the MBR, if
                         it finds the second copy of ANTHRAX in
                         last 3 sectors of the hard disk.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: F-PROT, SCAN, FindViru
Standard means......: It is very important to clean the last 3 sectors
                       of the harddsik.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Matthias Jaenichen
Documentation by....: Andrzej Kadlof, Virus Information Bank (Poland)
Date................: 14-July-1992
Information Source..: Reverse engineering of virus code
====================== End of ANTHRAX Virus ==========================
===== Computer Virus Catalog 1.2: Armagedon Virus (26-July-1992) =====
Entry...............: Armagedon Virus
Standard CARO Name..: Armagedon Virus
Alias(es)...........: Greek Virus
Virus Strain........: ---
Virus detected when.: Mai 1990
              where.: Greece
Classification......: Programm/Link (COM) virus
Length of Virus.....: 1079 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MSDOS
Version/Release.....:
Computer model(s)...: IBM-PC, XT, AT and upwards, and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: Text in virus body: "Armagedon the GREEK"
Type of infection...: Infects COM files only (Int 21h function 4Bh)
                         by prepending the virus before COM file.
Infection Trigger...: Load and execute File by Subfuction 4Bh of Int21h
Storage media affected: diskettes, hard disk
Interrupts hooked...: Int 21h DOS-Services:
                         - function 4Bh changed for infection;
                         - function E0h, returns DADAh;
                         - function E1h, returns the Int21h-Segment;
                      Int08h Timer-Interrupt: Damage-routine added.
Damage..............: Virus sends a string to all 4 COM-ports. This
                         string advises any connected hayes-modem to
                         drop the line and to dial "081<pause>141".
                         In Greece, this would be the time-annouce-
                         ment in Iraklion. Any other device connected
                         to a COM-port would output the String
                         "+++aTh0m0s7=35dp081,,,,141"
Damage Trigger......: If time is between 05:00 and 06:00 hours (am)
Similarities........: ---
--------------------- Agents -----------------------------------------
Counterm. successful: McAfee Scan, Skulason F-PROT, Solomon FindViru
Standard means......: Deleting the first 1079 Bytes will disinfect the
                        Programm.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, germany
Classification by...: Matthias Jaenichen, VTC Hamburg
Documentation by....: Yuval Tal, Weizmann-Institute, Rehovot, Israel
Date................: June 26, 1990
Information Source..: Yuval Tal
===================== End of Armagedon Virus =========================
========= Computer Virus Catalog 1.2: BFD Virus (25-July-1992) =======
Entry...............: BFD Virus
Standard CARO Name..: BootEXE.452 Virus
Alias(es)...........: BootEXE-452 = Sector Eleven Virus
Virus Strain........: BootEXE Virus Strain
Virus detected when.: July 7, 1992
              where.: U.S.
Classification......: Multipartite (=Program & System) Virus: Resident
                         EXE file (converts EXE format to COM format),
                         diskette boot and system boot infector
Length of Virus.....: System infection: 1 sector on infected disks
                      File infection:   0x01C3h bytes (but files do
                                        NOT grow in length)
--------------------- Preconditions -----------------------------------
Operating System(s).: PC-DOS
Version/Release.....: Any?
Computer model(s)...: Any?
--------------------- Attributes --------------------------------------
Easy Identification.: Infected EXE files begin with EB 39 rather than
                         with "MZ".
Self Identification.: 1) If virus is active in memory, INT13 with F0
                         in AH returns 19 in AH.
                      2) Infected files do not begin with "MZ".
                      3) Infected disks/diskettes contain virus in
                         boot records (compares).
Type of infection...: Any file that begins with "MZ", contains fewer
                         than 0x80 512-bytes pages, has not too many
                         relocation items in the table, has FFFF in
                         the Max Req Para field, and a header size
                         of 0x20 paragraphs.  Any diskette read from,
                         and the first partition on the first hard
                         disk, if it starts on a head other than zero.
Infection Trigger...: Any INT13 that reads the first sector of the file.
Storage media affected: Any diskette can be infected, but only 360K 5.25"
                          diskettes will boot properly. Any hard disk.
Interrupts hooked...: INT13 only.
Damage..............: No apparent intentional damage
Damage Trigger......: ---
Particularities.....: An unusual infection method; the virus installs
                         itself in unused EXE header space when the
                         start of the EXE file is read via INT13.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Not stealthed, so scanners with a signature, and
                         modification detectors, should have no trouble.
                         INT21-based monitors won't notice it.
Countermeasures successful: ?
Standard means......: Infected files can be made to work again by
                         changing the first two bytes back to "MZ"
                         (zeroing out the virus code in the unused
                         header space is also a good idea).
--------------------- Acknowledgement --------------------------------
Location............: IBM High Integrity Computing Laboratory, USA
Classification by...: David Chess
Documentation by....: David Chess
Date................: 9-July-1992
Information Source..: Analysis of original virus
===================== End of BFD Virus ===============================
======== Computer Virus Catalog 1.2: Groove Virus (25-July-1992) ======
Entry...............: Groove Virus
Standard CARO Name..: MtE_0_90.Groove Virus
Alias(es)...........: ---
Virus Strain........: MtE-based
Virus detected when.: USA
              where.: June 1992
Classification......: Polymorphic, memory-resident program (COM and
                         EXE, appending) virus
Length of Virus.....: 1. In RAM: 140 paragraphs;
                      2. on file: variable on disk due to MtE.
--------------------- Preconditions -----------------------------------
Operating System(s).: MS/PC DOS
Version/Release.....: 3.0+ ???
Computer model(s)...: All 80x86-based PCs
--------------------- Attributes --------------------------------------
Easy Identification.: Programs stop running as expected if at all.
Self Identification.: In memory: AX=0FBA0h, INT 21h -> AX = 0ABFh
                         if resident.
                      On files: EXE header checksum = 0FBAh
                                COM 5th byte = 0BAh, 6th byte = 0Fh
Type of infection...: COM & EXE programs (not based on extension)
Infection Trigger...: Execution using INT 21h function 4B.
Storage media affected: All (diskettes,,hard disk)
Interrupts hooked...: INT 21h, INT 24h
Damage..............: Transient damage: the following message will
                         either be displayed after 12:30 midnight
                         based on the tick count returned by INT 1Ah
                         on systems with a RTC, or it is displayed
                         every time when a file is infected:
                         "Dont wory, you are not alone at this hour...
                          This Virus is NOT dedicated to Sara
                          its dedicated to her Groove
                                                 (...Thats my name)
                          This virus is only a test virus therefore
                          be ready for my  Next  Test .."
                         This message is not readable in most mutations
                         due to encryption.
                      Permanent damage:
                      Virus will delete the following files upon
                         activation:   C:\NAV_._NO
                                       C:\NOVIRCVR.CTS
                                       C:\NOVIPERF.DAT
                                       C:\CPAV\CHKLIST.CPS
                                       C:\TOOLKIT\FILES.LST
                                       C:\UNTOUCH\UT.UT1
                                       C:\UNTOUCH\UT.UT2
Damage Trigger......: Execution of an infected file
Particularities.....: Virus does not check file extension to determine
                         its type, but rather checks for "MZ" or "ZM"
                         at the start of a file and assumes EXE-type
                         if a match is found; otherwise, it infects
                         as a COM-type file.
                      Infected files will not run properly.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: CatchMtE 1.0, VDSFSCAN 2.10, VDS 2.10, Gobbler-II
Countermeasures successful: Same as above, but all antivirals that can
                            detect MtE-based viruses 100% of the time
                            should be effective.
Standard means......: Delete infected files and restore clean copies.
--------------------- Acknowledgement --------------------------------
Location............: Baltimore, MD, U.S.A.
Classification by...: Tarkan Yetiser, VDS Advanced Research Group
Documentation by....: Tarkan Yetiser
Date................: 29-June-1992
Information Source..: ---
===================== End of Groove Virus ============================
== Computer Virus Catalog 1.2: Hafenstrasse-2 Virus. (25-July-1992) ==
Entry...............: Hafenstrasse-2 Virus
Standard CARO name..: Hafenstrasse.1641
Alias(es)...........: Hafenstrasse.e, Red-X-Exe
Virus Strain........: Both Hafenstrasse & Ambulance (Red-X) strains
Virus detected when.: June 92
              where.: Hamburg
Classification......: Direct action EXE- and COM-infector
Length of Virus.....: 1637-1652 Bytes appended to files
--------------------- Preconditions ----------------------------------
Operating System(s).: IBM & Compatibles
Version/Release.....: DOS 2.x and above
Computer model(s)...: IBM PC, XT, AT and higher, and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: Heavily increased time to access disk, when
                         starting an infected program.
Search string.......: String 3D 00 10 73 1B FE 84 D9 04 06 E8 can be
                         found at about 600 bytes offset from the end.
Type of infection...: EXE-files: standard ways of infecting EXE-files.
                      COM-files: virus behaves as trojan dropper in
                                 releasing Ambulance=Red X virus.
Infection Trigger...: Starting an infected file: virus will search
                         for 1 EXE- and 1 COM-file in path to infect.
Storage media affected: Only files in subdirectories included in the
                         path are infected.
Interrupts hooked...: ---
Damage..............: Permanent damage: system may hang when nearly
                         all files are infected (see Particularities)
                      Transient damage: on COM-files, virus will cause
                         an ambulance car to cross the screen.
Damage Trigger......: On COM files: first time on 6th, then every 8th
                         execution of virus (infection counter).
Particularities.....: 1) First virus to drop a virus from another
                         virus strain (Ambulance car=Red X).
                      2) Virus will check, if the INT-26-vector points
                         to an adress with a segment above $1000; in
                         this case, it will not activate (trying to
                         undergo some online detectors, e.g. Flushot).
                      3) If the files in the PATH are (almost) all
                         infected, the system may hang, because it
                         continues to search for infected files and
                         uses a random function to determine, whether
                         to infect a yet uninfected file.
                      4) No exact match is done do recognize COM- and
                         EXE-files.
                      5) File date and time is not altered.
Similarities........: Hafenstrasse variants, Ambulance car variants
                         (both virus strains use very similar ways to
                         search for a file, to infect; they may come
                         from related authors).
--------------------- Agents -----------------------------------------
Countermeasures successful: F-PROT 2.04a, Antivir from H&B-EDV
Standard means......: Delete and replace infected files.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Toralv Dirro
Documentation by....: Toralv Dirro
Date................: 07-July-1992
Information Source..: Original virus analysis
===================== End of Hafenstrasse-2 Virus ====================
=== Computer Virus Catalog 1.2: Hafenstrasse-3 Virus (25-July-1992) ==
Entry...............: Hafenstrasse-3 Virus
Standard CARO name..: Hafenstrasse.1191
Alias(es)...........: ---
Virus Strain........: Hafenstrasse virus strain
Virus detected when.: July 1992
              where.: Hamburg
Classification......: Direct action EXE-infector
Length of Virus.....: 1187-1202 Bytes appended to files
--------------------- Preconditions -----------------------------------
Operating System(s).: IBM PC & Compatibles
Version/Release.....: DOS 2.x and above
Computer model(s)...: IBM PC, XT, AT and hiogher, and compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: ---
Scan signature......: String: 3d 00 10 73 14 fe 84 03 01 e8 28 02 e8
                         1f 00 may be found at an offset of about
                         1150 bytes from the end of the file.
Type of infection...: Virus uses standard methods of infecting EXE
                         files searched for in the current path.
Infection Trigger...: Upon starting an infected program, virus
                         searches for an EXE file.
Storage media affected: Only files in subdirectories included in
                         path are affected.
Interrupts hooked...: ---
Damage..............: Permanent damage: ---
                      Transient damage: the first time an infected
                         program is started, virus will display an
                         ambulance car crossing the screen until it
                         reaches the right border, where it will
                         crash against a wall displaying texts
                         "BOOM" and "no more RedX !!!"
Damage Trigger......: The first time an infected program is started.
Particularities.....: 1) This virus does not infect COM files with an
                         Ambulance car dropper, as does the previous-
                         ly found Hafenstrasse-2. Instead, this
                          variant contains a modied ambulance car
                         routine.
                      2) The vector of INT 26 is tested, whether it
                         points to a segment above $1000 or not.
                         As in all (known) Hafentrasse viruses, file
                         and date will not be changed on infection.
Similarities........: Hafenstrasse variants, Ambulance (RedX) variants.
--------------------- Agents -----------------------------------------
Countermeasures.....: ---
Countermeasures successful: F-PROT 2.04a
Standard means......: Delete and replace infected files.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Toralv Dirro
Documentation by....: Toralv Dirro
Date................: 21-July-92
Information Source..: Original virus analysis.
===================== End of Hafenstrasse-3 Virus ====================
===== Computer Virus Catalog 1.2: Halloween Virus (25-July-1992) =====
Entry...............: Halloween Virus
Standard CARO Name..: Halloween Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: December 1991
              where.: British Columbia, Canada
Classification......: Program virus (COM&EXE infector, including
                         COMMAND.COM), non-resident
Length of Virus.....: Infected file length: 10,000 bytes (exactly)
--------------------- Preconditions ----------------------------------
Operating System(s).: PC/MS-DOS
Version/Release.....: Any?
Computer model(s)...: Any IBM PC and compatibles?
--------------------- Attributes -------------------------------------
Easy Identification.: 1) Significant file growth: 10 kByte (exactly).
                      2) Text "Happy HalloweenU" appears near start
                         of infected programs.
Type of infection...: Virus infects COM & EXE programs in the current
                         directory only, but only files with length
                         >= 10,000 (2710h) bytes will be infected.
                      Infection is done through prepending virus to
                         EXE and COM files to be infected file. Date
                         and time of infected file will match the
                         original one's, however the file's position
                         in the directory may change.
Infection Trigger...: Execution of infected program.
Storage media affected: All
Interrupts hooked...: ---
Damage..............: Permanent/transient damage: On October 31
                         (Halloween),  infected files will be
                         truncated to 666 bytes and the message
                              "All Gone Happy Halloween"
                         will appear.
Damage Trigger......: October 31 (Halloween), any year since 1992.
Particularities.....: 1) Search for uninfected files is proceeding
                         from top directory, and each executable file
                         is inspected for previous infection/length.
                      2) During infection, virus holds original code
                         in a temporary file. Moreover, it traps the
                         original file's return code for use when the
                         virus terminates (possibly for tunneling).
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: McAfee Scan, Skulason F-PROT, Solomon FindViru
Countermeasures successful:
Standard means......: On identification, virus may be removed from most
                         programs  (both COM & EXE) by simply stripping
                         off the first 10k bytes.
--------------------- Acknowledgement --------------------------------
Location............: Orlando/Florida, USA
                      Virus Test Center, University Hamburg, Germany
Classification by...: Padgett Patterson (USA), Klaus Brunnstein (VTC)
Documentation by....: Klaus Brunnstein (VTC)
Date................: 15-July-1992
Information Source..: Padgett Patterson's report on Halloween virus
===================== End of Halloween Virus =========================
======= Computer Virus Catalog 1.2: Joshi Virus (25-July-1992) =======
Entry...............: Joshi Virus
Alias(es)...........: Joshua Virus
Virus Strain........: ----
Virus detected when.: ?
              where.: India, Germany
Classification......: Master Bootsector and Bootsector Virus,
                         memory resident, stealth
Length of Virus.....: 4 KByte
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: any
Computer model(s)...: IBM - PC, XT, AT, upward and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: CHKDSK will report 6KB memory less than
                         installed.
                      On hard disks, the Master Bootsector contains
                         EB 1F 90 as first Bytes; at end of sector 3
                         and beginning of sector 4 on track 0, string
                         "Type Happy Birthday Joshi" can be found.
Type of infection...: Hard disk: Master Bootsector will be infected;
                         the original Master-Bootsector will be saved
                         in sector 9. The virus resides on track 0,
                         sectors 1-8.
                      Floppy-Disk: Bootsector will be infected; the
                         original Bootsector will be saved on additio-
                         nal track 40/80 in sector 9. Virus resides
                         on track 40/80 in sectors 2 to 6. On 720 kB
                         diskettes, virus will overwrite original
                         data on track 40.
Infection Trigger...: Actions: Read, write, verify track 0/sector 1
Storage Media affected: Any hard disk, any floppy
Infection targets:..: Hard disk Master Bootrecord; Floppy Bootrecord
Interrupts hooked...: INT 8, INT 9, INT 13h, INT 21h
Interrupts used.....: INT 8, INT 9, INT 10H, INT 13h, INT 19h
Damage..............: Permanent damage: on 720 kByte floppies,
                         original data on track 40 will be overwrit-
                         ten during infection.
                      Transient damage: virus displays message
                         "Type Happy Birthday Joshi".
Damage Trigger......: On January 5th, a DOS call (INT 21h) of any
                        of the following functions
                        - 48h (memory allocation)
                        - 49h (free allocated memory block)
                        - 4Ah (resize allocated memory block)
                        - 2Ah (get date)
                        - 2Bh (set date)
                        - 2Ch (get time)
                        - 2Dh (set time)
Particularities.....: 1) Joshi prevents being overwritten by the
                         STONED-virus
                      2) With Hercules graphic cards, problems may
                         occur as JOSHI does not save Hercules screen
                         memory.
--------------------- Agents -----------------------------------------
Countermeasures.....: According to their documentation, many antivirus
                         products claim to recognise/eradicate virus.
-ditto- successful..: Tested: Dr.Solomon's Toolkit 4.15,
                         Fridrik Skulason's F-PROT 2.04a,
                         H&B-EDV Antivir-IV 4.03 and McAfee Scan93.
Standard means......: 1) Reboot from clean bootdisk.
                      2) Use SYS-Command to reinstall BOOT sector on
                         floppies.
                      3) Use FDISK /MBR to reinstall Master-BOOT
                         sector on Harddisk (MS-DOS 5.0 only).
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center Hamburg, Univ Hamburg, Germany
Classification by...: Torsten Dargers, Ulf Heinemann
Documentation by....: Torsten Dargers, Ulf Heinemann
Date................: 26-June-1992
===================== End of JOSHI Virus =============================
==== Computer Virus Catalog 1.2: Leningrad.543 Virus (25-07-1992) ====
Entry...............: Leningrad.543 Virus
Standard CARO name..: Leningrad.543
Alias(es)...........: Sov1, Sov-543, USSR-543, C-543, PANIKER
Virus Strain........: Leningrad virus strain
Virus detected when.: Mid 1990
              where.: Leningrad (St.Petersburg), Russia (ex USSR)
Classification......: Non-resindent program (COM) infector
Length of Virus.....: COM files increased by 543 bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.xx upward
Computer model(s)...: IBM-PC, XT, AT and compatibles
--------------------- Attributes -------------------------------------
Wasy Identification.: Infected files contain strings "*.COM", "PATH="
                         and "That could be a crash, crash, crash !".
Type of infection...: Virus searches path and current directory. It
                         infects using standard DOS INT 21h calls.
Infection Trigger...: Any start of an infected file.
Storage media affected: Hard disk, any floppy disk
Interrupts hooked...: ---
Damage..............: Transient damage: Upon starting an infected pro-
                         gram on a Friday 13th, the virus will display
                         "That could be a crash, crash, crash !"
                      Permanent damage: an infected files may grow
                         > 64KB, so it cannot be started afterwards.
Damage Trigger......: Any Friday 13th.
Particularities.....: ---
Similarities........: Leningrad.600 = Sov2 virus
--------------------- Agents ------------------------------------------
Countermeasures successful:McAfee Scan,Skulason F-PROT,Solomon FINDVIRU
Standard means......: Delete infected COM files, copy uninfected
                         versions from original write protected disk.
--------------------- Acknowledgement ---------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Torsten Dargers
Documentation by....: Dr. Eldar Musaev, Leningrad, Russia
Date................: 07-July-1992
Information Source..: ----
===================== End of Leningrad-543 Virus =====================
===== Computer Virus Catalog 1.2: Mummy 1.2 Virus (25-July-1992) =====
Entry...............: Mummy 1.2 Virus
Standard CARO Name..: Jerusalem.Mummy.1_2 Virus
Alias(es)...........: ---
Virus Strain........: Jerusalem Virus strain, Mummy substrain
Virus detected when.: Spring 1992
              where.: Germany
Classification......: Program (EXE) virus (appending), memory resident
Length of Virus.....: Appends 1399-1414 bytes
--------------------- Preconditions -----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: All versions above 2
Computer model(s)...: PC and all compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: File growth; no plain text in files visible.
                      Virus self-identification: EXE header checksum
                         (file offset 12h) contains 0C0Bh.
Type of infection...: All files starting with "MZ" (normal EXE header)
                         that are executed or opened will be infected
                         provided there is enough space left on volume.
Infection Trigger...: Load & Execute or Open of a file containing "MZ"
                         as first two bytes.
Storage media affected: All (diskettes, hard disks)
Interrupts hooked...: INT 24 (hooked); INT 21 and 26 (used)
Damage..............: Transient damaga: there is an encrypted text in
                         the virus, that is decrypted when the virus
                         goes memory resident. This text is never
                         displayed!
                      Memory dump (typical text!):
                         0D 0A 20 04 20 4D 75 6D .. . Mum
                         6D 79 20 56 65 72 73 69 my Versi
                         6F 6E 20 31 3E 32 20 04 on 1.2 .
                         20 0D 0A 0A 4B 61 6F 68  ...Kaoh
                         73 69 75 6E 67 20 53 65 siung Se
                         6E 69 6F 72 20 53 63 68 nior Sch
                         6F 6F 6C 0D 0A 0A 54 7A ool...Tz
                         65 6E 67 20 4A 61 75 20 eng Jau
                         4D 69 6E 67 20 70 72 65 Ming pre
                         73 65 6E 74 73 0D 0A 0A sents...
                         53 65 72 69 65 73 20 4E Series N
                         75 6D 62 65 72 20 3D 20 umber =
                         5B 78 78 78 78 78 5D 0D [xxxxx].
                         0A 24                   .$
                      Permanent damage: virus contains a counter
                         (16bit) being decremented upon every loading
                         or opening of an infected file; this counter
                         is reset to zero every time an OEM call to
                         DOS is made (INT 21 AH=FFh and AL<>FFh) (this
                         function is used by several programs).
                         Upon each attemted infection, this counter is
                         checked whether having reached zero; if so,
                         the current logical drive is overwritten with
                         the virus code and memory garbage. 99 sectors
                         are being overwritten starting with the
                         bootsector (logical sector 0). This acitivity
                         destroys the bootsector, FAT 1 and FAT 2, and
                         the root directory as well as some data.
Damage Trigger......: If trigger counter becomes zero.
Particularities.....: Trigger counter is forced to zero if DOS INT 21h
                         is invoked, e.g. by specific programs or an-
                         other virus. New infection sinherit trigger
                         counter in infecting file.
Similarities........: Jerusalem/Mummy virus strain
--------------------- Agents ------------------------------------------
Countermeasures.....: McAfee Scan, Skulason F-PROT, Solomon FindViru
                      Removal not recommended, might not work on special
                         EXE files!
Standard means......: Replace infected file with uninfected original.
--------------------- Acknowledgement --------------------------------
Location............: Micro-BIT Virus Center, Univ Karlsruhe, Germany
Classification by...: Christoph Fischer (Klaus Brunnstein, VTC)
Documentation by....: Christoph Fischer
Date................: April-1992
Information Source..: ---
===================== End of Mummy 1.2 Virus =========================
====== Computer Virus Catalog 1.2: P-Check Virus (25-July-1992) ======
Entry...............: P-Check Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: April 1992
              where.:
Classification......: System (bootsector/partition table (MBR)) virus,
                         stealth
Length of Virus.....: Length on medium: 512 Bytes (=1 sector)
--------------------- Preconditions -----------------------------------
Operating System(s).: MS-DOS
Version/Release.....:
Computer model(s)...: IBM PC and compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: Memory decreased by 1 kBytes after infection;
                         no plain text in bootsector or MBR, like
                         "Non system disk..." or "Bad partition....".
Type of infection...: Boot sectors and partition table of media.
Infection Trigger...: Booting from an infected disk will infect the
                         hard disk; from this time, all read accesses
                         to the boot sector of any physical drive will
                         infect the medium in this drive.
Storage media affected: All media: Floppy disk, hard disk.
Interrupts hooked...: INT 09, INT 13.
Damage..............: Transient/Permanent damage:
                      Some built-in mechanism simulates a parity error
                         message on the screen after 1 hour of opera-
                         tion plus an additional hour for each infec-
                         tion: the more infections, the longer till
                         the parity check display.
                      The parity error simulation switches to 40 x 25
                         mode, displays 'PARITY CHECK' and then halts
                         the processor.
                      Virus constantly garbles the INT01&INT03 entries,
                         so that debug will not work; this is not tied
                         to a trigger.
Damage Trigger......: The internal timer tick (not the CMOS clock) is
                         used for timing. Trigger= 1+n hours after
                         boot up (n=number of infections since booting)
Particularities.....: ---
Similarities........: ---
--------------------- Agents ------------------------------------------
Countermeasures.....: Up-to-date antiviral products.
                      Removal: SYS on floppies; FDISK /MBR (DOS 5.0)
Standard means......:
--------------------- Acknowledgement --------------------------------
Location............: Micro-BIT Virus Center, Univ Karlsruhe, Germany
Classification by...: Christoph Fischer (Klaus Brunnstein, VTC)
Documentation by....: Christoph Fischer
Date................: April-1992
Information Source..: ---
===================== End of P-Check Virus ===========================
======== Computer Virus Catalog 1.2: Peach Virus (25-July-1992) ======
Entry...............: Peach Virus
Standard CARO Name..: Peach Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.:
              where.:
Classification......: Program (COM&EXE) Virus (appending), resident
Length of Virus.....: On media: 887 Bytes.
--------------------- Preconditions ----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: 2.00 and above
Computer model(s)...:
--------------------- Attributes -------------------------------------
Easy Identification.: The following text can be found in infected files:
                      "Roy XuatroNo 2 Peach GardenMeyer Rd. Spore 1543"
Self Identification.: In memory: at position 0040:00fc, the string
                         "Roy" can be found.
                      In file: in the EXE header, the IP field will con-
                         tain 01fch at position 14h; in COM file, virus
                         compares the COM startup code it inserts.
Type of infection...: Virus infects COM and EXE files. It identifies
                         EXE files by looking for "Z" at position 1.
                      Virus goes memory-resident.
Infection Trigger...:Load and Execute (Int 21h function 4B00)
Storage media affected:Anything that can be addressed using DOS calls
                         (floppy diskettes, hard disks)
Interrupts hooked...: Int 21h, Int 23h and Int 24h (Control-C and
                         Critical Error Handler) during infection.
Damage..............: Transient Damage: ---
                      Permanent Damage: if file "chklist.cps" (crea-
                         ted by Central Point AntiVirus) is found,
                         this file is deleted.
Damage Trigger......: If file "chklist.cps" is found.
Particularities.....: ---
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Skulason F-PROT 2.02, Solomon FindViru 3.5
Standard means......: ---
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
                      S&S International (Deutschland)
Classification by...: Morton Swimmer
Documentation by....: Morton Swimmer
Date................: 7-July-1992
Information Source..: Original virus
===================== End of Peach Virus =============================
===== Computer Virus Catalog 1.2: Seventh Son Virus (25-07-1992) =====
Entry...............: Seventh Son Virus
Standard CARO name..: Seventh_Son.284 Virus
Alias(es)...........: Seventh Son-284 Virus
Virus Strain........: Seventh Son virus strain
Virus detected when.: October 1991
              where.: Eastern Europe
Classification......: File (COM) virus
Length of Virus.....: 284 Bytes
--------------------- Preconditions -----------------------------------
Operating System(s).: DOS
Version/Release.....:
Computer model(s)...: IBM compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: The displayed text "Seventh son of a seventh son"
                         can be found in infected programs.
Type of infection...: Infects only COM files
Infection Trigger...: Execution of an infected program.
Storage media affected: Infects any diskette and hard disks
Interrupts hooked...: ---
Damage..............: Permanent damage: ---
                      Transient damage: displays the text
                                        "Seventh son of a seventh son"
Damage Trigger......: Permanent damage: ---
                      Transient damage: executing an infected program
Particularities.....: ---
Similarities........: Seventh Son variants (.332, .350)
--------------------- Agents -----------------------------------------
Countermeasures.....: McAfee Scan,Skulason F-PROT,Solomon FINDVIRU
Standard means......: Delete infected files and replace with un-
                         infected originals or backups.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Michaela Schroeder, Peter Liem, Doerte Hachfeld,
                      Holger Prescher
Documentation by....: Holger Prescher, Doerte Hachfeld, Peter Liem,
                      Michaela Schroeder
Date................: 20-July-1992
Information Source..: Reverse-Engineering of virus code
===================== End of Seventh Son Virus =======================
===== Computer Virus Catalog 1.2: Silly Willy Trojan (25-07-1992) ====
Entry...............: Silly Willy Trojan
Standard CARO Name..: Silly_Willy Trojan
Alias(es)...........: ---
Virus Strain........: Silly Willy (Trojan/Virus) Strain
Virus detected when.: March 92
              where.: Munich, Germany
Classification......: Trojan
Length of Virus.....: 803 Bytes
--------------------- Preconditions ----------------------------------
Operating System(s).: IBM PC & Compatibles
Version/Release.....: DOS 2.x and above
Computer model(s)...: IBM PC, XT, AT and upwards, and compatibles
--------------------- Attributes -------------------------------------
Easy Identification.: ---
Scan signature......: The string: 0e 1f b0 49 be 11 00 b9 24 03 2b ce
                      28 04 can be found at begin of an trojanized
                      file.
Type of infection...: ---
Infection Trigger...: ---
Storage media affected: Any floppy diskette, hard disk
Interrupts hooked...: ---
Damage..............: Transient/Permanent damage: The trojan displays
                         a face, telling that he is Silly Willy and
                         right now formatting the hard disk. But
                         instead, it writes a hidden file, so the
                         user observes some hard disk activities. The
                         hidden file has a length between 154,622 and
                         459,952 bytes and contains the text
                            "The User of This Computer Is Stupid!".
                         After some time, another message will appear:
                            "ERROR: o SYSTEM found!
                             No Files on drive C:
                             Insert SYSTEM diskette in drive A:
                                and push a key!"
                         After pushing a key, the first 9 sectors on
                         the first five tracks will be overwritten
                         with the text
                            "The User of This Computer Is Stupid!"
                         Then, the system hangs.
Damage Trigger......: Starting a trojanized EXE-file
Particularities.....: Silly Willy Trojan is dropped by Silly Willy
                         Virus which overwrites EXE files with trojan.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Solomon FindViru 4.23, Antivir from H&B-EDV
Standard means......: Delete/replace trojanized files with clean ones.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
                      Siemens Nixdorf AG (SNI), Munich
Classification by...: Toralv Dirro (VTC), Ralph Dombach (SNI)
Documentation by....: Toralv Dirro
Date................: 16-July-92
Information Source..: Original virus analysis
===================== End of Silly Willy Trojan ======================
===== Computer Virus Catalog 1.2: Silly Willy Virus (25-07-1992) =====
Entry...............: Silly Willy Virus
Standard CARO Name..: Silly_Willy Virus
Alias(es)...........: ---
Virus Strain........: Silly Willy (Trojan/Virus) Strain
Virus detected when.: March 91
              where.: Munich, Germany
Classification......: Direct action COM-infector, Trojan dropper (EXE)
Length of Virus.....: Length in COM-files: 2261-2314 bytes
--------------------- Preconditions -----------------------------------
Operating System(s).: IBM PC & Compatibles
Version/Release.....: DOS 2.x and above
Computer model(s)...: IBM PC, XT, AT and upward, and compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: Increased file size; unusual long loading time.
Scan signature......: The string : BE 15 00 8B 1A B9 D0 08 81 E9 can be
                         found at about 2300 bytes offset from the end
                         of an infected file.
Type of infection...: COM-files will be searched via FindFirst,FindNext,
                         starting with root directory, and in sub-
                         directories, if no uninfected files are found
                         in the root.
                      EXE-files will be overwritten with Silly Willy
                         Trojan (see separate Virus Catalog entry).
Infection Trigger...: Starting an infected file; virus will search
                         for one COM-file to infect and for one EXE-
                         file to trojanize.
Storage media affected: Only files on drive C: will be affected.
Interrupts hooked...: ---
Damage..............: Transient damage: ---
                      Permanent damage: EXE-files are overwritten
                        with Silly Willy Trojan (see separate Virus
                        Catalog entry).
Damage Trigger......: Start of an infected program
Particularities.....: 1) The virus uses polymorphic methods to hide
                         from detection in COM-files. At offset 0,
                         16 Bytes are inserted in COM-files; these
                         can hold 16 different values of code. The
                         virus merges two 8 byte strings, and each
                         string has four different values; moreover,
                         a random number of bytes is inserted, too.
                         Due to a very simple decryption algorithm
                         (XOR) and some unincrypted code, the poly-
                         morphic routine is rather ineffective.
                      2) Date and time of infected programs will not
                         be changed.
                      3) Only COM-files with a length between 1087
                         and 58,932 bytes will be infected.
                      4) No exact match to recognize EXE and COM
                         files is performed.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Checksums, etc.
Countermeasures successful: Solomon FindViru 4.23, H&B-EDV AntiVir
Standard means......: Delete and replace infected files.
--------------------- Acknowledgement --------------------------------
Location............: Siemens Nixdorf AG (SNI), Munich, Germany
                      Virus Test Center, University Hamburg, Germany
Classification by...: Ralph Dombach (SNI), Toralv Dirro (VTC)
Documentation by....: Toralv Dirro
Date................: 16--July-1992
Information Source..: Orignal virus analysis
===================== End of SILLY WILLY Virus =======================
=== Computer Virus Catalog 1.2: VCS V1.0 Manta Virus (25-July-1991) ==
Entry................. VCS V1.0 Manta Virus
Standard CARO Name.... VCS.Manta Virus
Alias(es)............. ---
Strain................ VCS Virus Strain
Detected: when........ Summer 1992
          where....... Bulletin Board, Hamburg, Germany
Classification........ Clone of VCS V1.0 Virus
                       Program Virus, direct action; overwriting
                          AUTOEXEC and CONFIG.SYS; encrypted.
Length of Virus....... Increase of file length: 1077 bytes
---------------------- Preconditions ---------------------------------
Operating System(s)... MS/PC-DOS
Computer models....... All IBM PC compatibles with CPU > 8088
---------------------- Attributes ------------------------------------
Easy identification... Same as VCS V1.0 virus:
                       Files containing C350h at offset 03h regarded
                          as infected (self identification)
                       Search string at offset 00h:
                       E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE
Type of infection..... Same as VCS V1.0 virus
Infection trigger..... Same as VCS V1.0 virus
Interrupts hooked..... ---
Damage................ Same as VCS V1.0 virus:
                       Permanent damage: when triggered, the files
                          'C:\AUTOEXEC.BAT' and 'C:\CONFIG.SYS' will
                          be overwritten with 512 bytes of text.
                       Transient Damage: when AUTOEXEC and CONFIG.SYS
                          have been overwritten, a text which was
                          deliberately choosen by the installator
                          (see: Particularities:Generating the virus)
                          may be displayed.
Damage trigger........ Same as VCS V1.0 virus
Particularities....... Same as VCS V1.0 virus
Particularities/Generating this virus: VCS V1.0 Manta was generated
                       with the VCS V1.0 (see catalog entry VCS V1.0).
                       In addition to the characteristics of VCS V1.0,
                       the following text will be displayed until
                       a key is pressed:
                          "RAM Parity Error at 0F67:1B2C"
                          "(C)ontinue  (S)hut off NMI  (R)eboot ".
                       The files C:\AUTOEXEC.BAT and C:\CONFIG.SYS will
                       be overwritten with this text, as well as with
                       the following text referring to popular jokes
                       about some people which drive a special Opel
                       car type called "Manta". The text is:
                       "Ein Mantafahrer haelt an einer Ampel. Neben ihm
                        haelt ein Porsche. Beide kurbeln die Scheiben
                        runter, und der Porschefahrer fragt: 'Was hat
                        vier Beine und ist unheimlich bloed?'
                        Mantafahrer: 'Keine Ahnung'
                        Porschefahrer: 'Du und deine Freundin'
                        An der naechsten Ampel haelt ein Golf neben dem
                        Manta. Mantafahrer: 'Was hat vier Beine und ist
                        unheimlich doof ?' Golffahrer: 'Keine Ahnung'
                        Mantafahrer: 'Meine Freundin und ich'."
                       Translation:
                       "A Manta driver stops at a traffic lights.
                        A Porsche stops beside him. Both of them open
                        the window and the Porsche driver asks:
                        'What has four legs and is very very mad?'
                        Says Manta driver: 'I do not know'
                        Says Porsche driver: 'You and your girlfriend'
                        At next traffic lights, a Golf stops beside the
                        Manta. Says Manta driver: 'What has four legs
                          and is very very mad ?'
                        Says Golf driver: 'I do not know'
                        Says Manta driver:'My girlfriend and me.' "
                       Moreover, VCS V1.0 Manta uses opcode 68h (push
                          constant on stack) which is not defined on
                          8088 processors; so, virus will not work on
                          such systems.
Similarities........... ---
---------------------- Agents ----------------------------------------
Countermeasures....... Searchstring at offset 00h of virus:
                       E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE
 - ditto -   successful. Actual versions of McAfee Scan, Skulason
                            F-PROT, Solomon FindViru.
                       Tode's NTI-VCS.EXE is an antivirus that
                            only looks for VCS virus, and if requested
                            will restore the file.
Standard Means........ Notice file length. Use ReadOnly attribute.
---------------------- Acknowledgements ------------------------------
Location.............. Virus Test Center, University Hamburg, Germany
Classification by..... Stefan Tode
Documentation by...... Stefan Tode and Matthias Jaenichen
Date.................. 15-July-1991
Information source.... ---
====================== End of VCS V1.0 Manta Virus ===================
===== Computer Virus Catalog 1.2: VCS V1.1a Virus (21-July-1992) ======
Entry................. VCS V1.1a Virus
Alias(es)............. Virus-Construction-Set V1.1a
Strain................ VCS Virus Strain
Detected: when........ JAN 1992
          where....... Bulletin Board, Hamburg, Germany
Classification........ Clone of VCS V1.0 Virus
                       Program Virus, direct action; overwriting,
                          AUTOEXEC.BAT and CONFIG.SYS; encrypted.
Length of Virus....... Increased File Length: 1077 bytes
---------------------- Preconditions ---------------------------------
Operating System(s)... MS/PC-DOS
Computer models....... All IBM PC compatibles with CPU > 8088.
---------------------- Attributes ------------------------------------
Easy identification... Files containing C390h at offset 03h regarded
                       as infected (self identification).
Scan signature........ Searchstring at offset 00h (same as VCS V1.0):
                       E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE
                       same as VCS V1.0
Type of infection..... same as VCS V1.0
Infection trigger..... same as VCS V1.0
Interrupts hooked..... ---
Damage................ same as VCS V1.0
Particularities....... same as VCS V1.0
Particularities/Generating as VCS 1.0, generated by Virus Construction
                          Set Version 1.0
DisSimilarities....... Virus is similar to VCS V1.0 virus and uses the
                       same code, except the self identification
                       routine. Only the version number is changed, so
                       the following string can be found in VCS V1.1a:
                          "Virus Construction Set V1.1a"
---------------------- Agents ----------------------------------------
Countermeasures....... Searchstring at offset 00h of virus:
                       E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE
 - ditto - successful. Skulason's F-PROT V2.04  detects as VCS variant.
                       McAfee's Scan version 93 as Manta
                       Tode's NTI-VCS.EXE is an antivirus that
                          only looks for VCS viruses, and if requested
                          will restore the file.
Standard Means........ Notice file length. Use ReadOnly attribute.
---------------------- Acknowledgements ------------------------------
Location.............. Virus Test Center, University Hamburg, Germany
Classification by..... Stefan Tode
Documentation by...... Stefan Tode
Date.................. 21-July-1992
Information source.... ---
====================== End of VCS V1.1a Virus ========================
===== Computer Virus Catalog 1.2: VCS V1.3 Virus (25-July-1992) ======
Entry................. VCS V1.3 Virus
Standard CARO Name.... VCS.RUF
Alias(es)............. Virus-Construction-Set V1.3 Virus=VCS1.3.RUF
Strain................ VCS Virus Strain
Detected: when........ March 1992
          where....... Bulletin Board, Hamburg, Germany
Classification........ Clone of VCS V1.0 Virus;
                       Program Virus, direct action; overwriting
                          AUTOEXEC and CONFIG.SYS; encrypted.
Length of Virus....... Increase of file length: 1077 bytes
---------------------- Preconditions ---------------------------------
Operating System(s)... MS/PC-DOS
Computer models....... on IBM PC compatibles with CPU > 8086.
---------------------- Attributes ------------------------------------
Easy identification... Files containing C350h at offset 03h regarded
                          as infected (self identification)
                       Search string at offset 00h:
                       E8 14 00 8A 9C 2F 05 8D BC 20 01 B9 0F 04 89 FE
Type of infection..... same as VCS V1.0
Infection trigger..... same as VCS V1.0
Interrupts hooked..... ---
Damage................ same as VCS V1.0
Particularities....... same as VCS V1.0
Particularities/Generating
                       VCS1.3 = VCS.RUF is a virus which was generated
                          by the Virus Construction Set V1.3.
                       The textbuffer in the damage routine contains
                          the strings "Deutsche Bundespost" (=German
                          Post Office) and "Telekom". A blockgraphics
                          displaed consists of a telephone icon and
                          the German Telecom's slogan:
                          "RUF DOCH MAL AN" (=You should call").
Similarities........... 1) Virus is similar to VCS 1.0 virus and uses
                              the same code, except for the encrypt-
                              ion routine.
                        2) VCS 1.3 is a patched version of VCS 1.0.
                              It was created by someone who calls
                              himself "Hanswurst".
                        3) The textstrings of VCS.EXE are also
                              patched. The following strings can be
                              found in the VCS.EXE:
                           "(C) 1991 by VDV, 1992 by Hanswurst"
                           "Virus Construction Set V1.3, gepatcht"
                           " von Hanswurst 1992"
---------------------- Agents ----------------------------------------
Countermeasures....... Searchstring at offset 00h of virus:
                       E8 14 00 8A 9C 2F 05 8D BC 20 01 B9 0F 04 89 FE
 - ditto - successful. Tode's NTI-VCS.EXE is an antivirus that only
                          looks for VCS viruses, and if requested will
                          restore the file.
 - ditto - unsuccessful. Presently, no AV product identifies VCS V1.3.
Standard Means........ Notice file length. Use ReadOnly attribute.
---------------------- Acknowledgements ------------------------------
Location.............. Virus Test Center, University Hamburg, Germany
Classification by..... Stefan Tode
Documentation by...... Stefan Tode
Date.................. 21-July-1992
Information source.... ---
====================== End of VCS V1.3 Virus =========================
======== Computer Virus Catalog 1.2: XREH Virus (25-July-1992) =======
Entry...............: XPEH-4016 Virus in (kyrillic letters)
                      CHREN-4016 Virus (in Latin letters)
Alias(es)...........: ---
Virus Strain........: XREH Virus Strain
Virus detected when.: ?
              where.: Russia
Classification......: Program (COM & EXE) Virus, memory-resident
Length of Virus.....: 1. Length on media:  4016 bytes (appended)
                      2. Length in memory: 3872 bytes.
--------------------- Preconditions -----------------------------------
Operating System(s).: MS-DOS
Version/Release.....: DOS 2.x and above
Computer model(s)...: IBM & Compatibles
--------------------- Attributes --------------------------------------
Easy Identification.: Total memory size decreased by 4032 bytes, disk
                         access slows down, when virus is active.
Scan signature......: The following bytes can be found at the INT-21-
                      entrypoint: 80 FC 4E 74 12 80 FC 4F 74 0D 2E 3A
Type of infection...: a) COM-files : The virus appends itself to the
                            end of the file, changing the first
                            32 Bytes of the victim (restored later).
                      b) EXE-Files : Virus uses standard ways of
                            infecting EXE-files.
Infection Trigger...: Execution of COM & EXE files, when month>March
                         and year>1991.
                      Usage of INT 21, AH=4E/4F (FindFirst/FindNext),
                         when the date is above March and 1991. (For
                         details ).
Storage media affected: Files on all accessible media are affected.
Interrupts hooked...: INT 21, functions: AH=4E (FindFirst),
                              AH=4F (FindNext), AH=4B (Load&Execute)
                      INT 1C (Timer),
                      INT 01 (Trace) and INT 03 are hooked temporarily
                      (For details see Particularities)
Damage..............: Files with the Extension ".   ", ".LEX", ".TXT",
                      ".BAK" can be garbled, during September-December
                      of any year above 1991.
Damage Trigger......: System-date (see Damage).
Particularities.....: The virus hooks INT 21, AH=4E/4F for infecting
                         files and encrypting files (damage!), as well
                         as subtracting his length from COM/EXE with
                         filetime 30 seconds. Filetime will be set
                         to 30 sec, when it has been infected or garb-
                         led.
                      This routine will garble files, in months
                         >=September of any year above 1991 and in-
                         fecting COM and EXE files in months >=March
                         of any year above 1991, using a 1:4 random-
                         routine to determine whether to be active.
                      The virus uses the EXE-signature (MZ/ZM) to
                         recognize EXE-files.
                      COM files will only be infected, when their size
                         is >=288 and <=61,815 bytes. As the maximum
                         size of COM-files seems to have been forgotten
                         to be changed, while writing a new version of
                         the virus (there are shorter versions!), COM-
                         files can get bigger than 65k and won't run.
                      If the date is >=September and >1991, ".   ",
                         ".LEX", ".TXT", ".BAK" files can be garbled,
                         decrypting up to 64k of them with the kyrillic
                         letters XPEH (hex: 95 80 85 8D) (xor).
                      The INT 1C (Timer) is used to check, wether the
                         entrance of INT 1 and INT 3 (Trace/Breakpoint)
                         is an IRET-instruction; if not, the entrypoint
                         is overwritten with a CALL FAR into the virus.
                         Here the virus determines, from where the INT
                         has been called, and if it was a INT 1 or INT 3.
                         After that, it is decided whether only the
                         Trace-flag is disabled, or if it should hang
                         the system.
                      The virus copies itself to the top of RAM, de-
                         creasing the total amount of memory by 4032
                         bytes.
                      When the virus installs itself into memory, it
                         uses a kind of TRACER, to find the original
                         INT 21 entry (decission is made via the seg-
                         ment: if it is below 200, virus assumes that
                         original INT 21 entry has been reached).
                      While running, the virus constantly de/encrypts
                         parts of it to disable reassembling of itself,
                         making analysis very difficult.
Similarities........: XREH variants
--------------------- Agents -----------------------------------------
Countermeasures.....: F-PROT 2.02D in Quick-scan recognises the virus as
                      a new variant of Cascade.
Countermeasures successful: The Antiviral Package v. 4.6 from Kaspersky
                            (Moscow) recognizes and removes the virus.
Standard means......: Delete and replace infected files.
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Toralv Dirro
Documentation by....: Toralv Dirro
Date................: 05-May-1992
Information Source..: Original virus analysis
===================== End of XREH Virus ==============================
