==== Computer Virus Catalog 1.2: "AIDS" Trojan (10-February-1991) ===== Entry...............: "AIDS" Trojan Alias(es)...........: PC Cyborg Trojan Trojan Strain.......: --- Trojan detected when: December 1989 where.: USA, Europe Classification......: Trojan Horse Carrier of Trojan...: A hidden file named REM<255> of 146188 bytes; (<255> represents the character ASCII(255)); distributed with AIDS.EXE as INSTALL.EXE file on AIDS Information Disk of PC Cyborg, Panama --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS, PC-Dos Version/Release.....: --- Computer model(s)...: IBM PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: The string "rem<255> PLEASE USE THE auto.bat FILE INSTEAD OF autoexec.bat FOR CONVENIENCE <255>" can be found in AUTOEXEC.BAT Installation Trigger: Installing the "AIDS Information Diskette" on hard disk drive C. Storage media affected:Free space on Partition C:, all directories Interrupts Hooked...: --- Damage..............: Permanent damage: All directory entry names are encryped by a simple encryption algorithm: A -> } , B -> U , C -> _ , D -> @ , E -> 8 , F -> ! , G -> ' , H -> Q , I -> # , J -> D , K -> A , L -> P , M -> C , N -> 1 , O -> R , P -> X , Q -> Z , R -> H , S -> & , T -> 6 , U -> G , V -> 0 , W -> K , X -> V , Y -> N , Z -> I , # -> C , ! -> S , ' -> $ , ^ -> ~ , _ -> 0 , $ -> 3 , 0 -> R , 1 -> F , 2 -> Y , 3 -> { , 4 -> J , 5 -> E , 6 -> T , 7 -> ) , 8 -> M , 9 -> - , @ -> L , ~ -> ^ , & -> 7 , } -> 5 , { -> 4 , ) -> % , ( -> B , - -> 2 , % -> W Moreover, 90 extensions known to the program are changed to the following extensions each consisting of one blank plus 2 letters: COM -> AK , BAK -> AD , EXE -> AU , PRG -> BR , BAT -> AG , DBF -> AN DOC -> AR , WK1 -> CC , DRW -> DI , NDX -> BK , DRV -> CI , BAS -> AF OVR -> BN , FNT -> AW , ZBA -> CH , SYS -> BZ , FLB -> DJ , FRM -> AX DAT -> AL , LRL -> CJ , OVL -> BM , HLP -> BA , PIC -> DK , XLT -> CF MNU -> BI , TXT -> CB , CAL -> CK , FON -> CL , SPL -> CM , PAT -> DL MAC -> CN , STY -> BY , VFN -> DM , TST -> CO , GEM -> DN , FIL -> AV DEM -> AP , REN -> DO , IMG -> DP , RSC -> DQ , MSG -> BJ , MEM -> DR REC -> BX , GLY -> AZ , CMP -> BI , LGO -> CP , DCT -> AO , GRB -> CQ CNF -> AJ , INI -> BB , GRA -> CR , DB -> AM , DTA -> CS , APP -> AC CAT -> AH , DIR -> AQ , DVC -> AS , DYN -> AT , INP -> BC , LBR -> BD LOC -> BF , MMF -> BH , OUT -> BL , PGG -> BO , PIF -> BP , PRD -> BQ PRN -> BS , SCR -> BU , SET -> BV , SK -> BW , ST -> BX , TAL -> CA WK2 -> CD , WKS -> CE , XQT -> CG , $$$ -> CT , VC -> CU , TMP -> CV PAS -> CW , QBJ -> CX , MAP -> CY , LST -> CZ , LIB -> DA , ASM -> DB BLD -> DC , COB -> DD , DIF -> DH , FMT -> DG , MDF -> BG , FOR -> DF The free space on partition C is filled with a file containing a number of strings con- sisting of blanks followed by CR/LF. Every time the computer boots, a COMMAND.COM is simulated. Almost all commands are requested by an error message. DIR shows the directory before encryption. Damage..............: Transient damages: from time to time, the fol- lowing message is displayed: "It is time to pay for your software lease from PC Cyborg Corporation. Complete the INVOICE and attach payment for the lease option of your choice.If you don't use the printed INVOICE, then be sure to refer to the important reference numbers below in all correspondence. In return you will recieve: - a renewal software package with easy to follow, complete instructions; - an automatic, self installing diskette that anyone can apply in minutes." Damage Trigger......: Booting the system 90 times (9 in some cases) Particularities.....: AIDS.EXE will only run after installation on drive C. Some hidden directories are created containing hidden subdirectories and some files which are used by the trojan; filenames contain blanks and can't be accessed via COMMAND.COM. AIDS.EXE and INSTALL.EXE have been written in Microsoft Quick Basic 3.0; according to VTCs retroanalysis, the program quality and the encryption method show moderate quality; more- over, the dialog as well as the function to evaluate the personal risk of an AIDS infect- ion, are rather primitive. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke, Uwe Ellermann Documentation by....: Ronald Greinke Date................: 10-February-1991 ===================== End of AIDS Trojan ============================= === Computer Virus Catalog 1.2: Anti-Pascal 605 Virus (12-Feb-1991) == Entry................ Anti-Pascal 605 Virus Alias(es)............ AP-605, V605, C-605 Virus Virus Strain......... Anti-Pascal strain Virus detected when.. June 1990 where.. Sofia Classification....... Program Virus extending .COM, direct action Length of Virus...... 605 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).. MS-DOS, PC-DOS Version/Release...... 2.1x upward Computer models...... IBM PC/XT/AT and compatibles --------------------- Attributes ------------------------------------- Easy identification.. Infected files begin with "PQVWS". They also contain the string "combakpas???exe" at offset 0x17.0 Self identification.. Files are considered infected if the word at offset 7 contains 0x10C. VIRSCAN string....... BF00018B360C0103F7B95D021E07EA00, scan COM files only. Type of infection.... Extends .COM files. The virus overwrites the first 605 bytes of the file. The original 605 bytes are moved after the end of the file. Infection Trigger.... Execution of an infected file. Storage Media affected Infects .COM files on the current drive and on disk D:. Interrupts hooked.... INT 24h during infection. Damage............... transient: --- permanent: may overwrite .BAK and .PAS files. Damage trigger....... If less than two files in the current directory can be infected, a .BAK or .PAS file is selected and overwritten with the virus body. The virus tries then to rename the file with a .COM or (if rename is unsuccess- ful) .EXE extension, but due to a bug this never succeeds. Infective range...... Only files with length 605 to 64930 bytes are infected. Particularities...... 1. Files larger than 64674 bytes are no longer loadable after infection. 2. If the Archive attribute of the file is reset, the virus sets it after infection. 3. If the ReadOnly attribute of the file is set, the virus is not able to infect it. 4. File date is modified. Similarities......... --- --------------------- Agents ----------------------------------------- Countermeasures...... Category 1: Monitoring files Category 2: Alteration detection Category 3: Eradication -ditto- successful... Category 1: FluShot+, Anti4us Category 2: Sentry Category 3: V605Clr.Com Standard means....... Setting the attributes of the .COM files to ReadOnly effectivly prevents this virus from infecting/spreading. --------------------- Acknowledgement -------------------------------- Location............. Bulgarian Academy of Sciences, Sofia Classification by.... Vesselin Bontchev Documentation by .... Vesselin Bontchev Date................. June 7, 1990 Information Source... --- ===================== End of Anti-Pascal 605 Virus =================== === Computer Virus Catalog 1.2: Dark Avenger 3 Virus (14-Feb-1991) === Entry...............: Dark Avenger 3 Virus Alias(es)...........: V2000 = Eddie 3 Virus Virus Strain........: Dark Avenger Strain Classification......: Program Virus, RAM-resident Length of Virus.....: 2000 Bytes (2076 Bytes in RAM resident mode) --------------------- Preconditions ---------------------------------- Operating System(s).: MSDOS, PCDOS Version/Release.....: 3.3 Computer model(s)...: IBM compatibles PCs --------------------- Attributes ------------------------------------- Easy Identification.: Two Strings : 1) "Copy me - I want to travel" (at beginning of virus-code) 2) "(c) 1989 by Vesselin Bontchev" (near end of virus code; but V.Bontchev is not the author!) Type of infection...: Link-Virus (postfix infection); virus infects every "COM" and "EXE" file with minimum file-length of 1959 bytes. Infection Trigger...: Programs are infected at load time (using MsDos function Load/Execute) as well as on every read attempt (viewing, copy etc.) Storage media affected: Any Drive Interrupts hooked...: INT 21h [Dos-Functions] ) hooked by resident INT 27h [TSR] ) part of virus INT 24h [Critical Error] > during infection INT 13h [BIOS-Disk Access] > during infection and damage Damage..............: On every 16's execution of an infected file, virus will overwrite a new random data sector on disk; the last overwritten sector will be stored in boot sector. System hang-up, if a program is to be executed, which contains the string "(c) 1989 by Vesselin Bontchev"; V.Bonchev is a Bulgarian author of anti-virus programs. Damage Trigger......: The virus uses the last byte of "MSDOS-Version"- field in the bootblock as counter; if an infected file is executed, this counter will be invremented. Particularities.....: On some 386 PCs with different BIOS version, infected programs hang-up the system during virus installation. The virus overwrites the transient part of DOS in RAM to provoke the reload of "command.com", to get a chance for an early infection of this file. The virus intercepts the "Find first" and "Find next" functions, and on "DIR" command execution, virus decreases the file length of marked files by 2000 (virus length). Similarities........: As in Eddie 2 virus, infected files are marked with "62" in the "seconds"-field of time stamp. --------------------- Agents ----------------------------------------- Countermeasures.....: The virus will be (for example) detected by : F-FCHK 1.13 (F. Skulason) Findviru 1.8 (Solomon: Virus Tools 4.25) --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: J”rg Steindecker Documentation by....: J”rg Steindecker Date................: 14-February-1991 ===================== End of Dark Avenger 3 Virus ==================== ===== Computer Virus Catalog 1.2: FISH #6 Virus (12-February-1991) === Entry...............: FISH #6 Virus Alias(es)...........: FISH-6 = European Fish Virus Virus Strain........: 4096 = 4K = FroDo = Stealth strain Virus detected when.: October 1990 where.: Bonn/Germany ??? Classification......: Program (extending), RAM-resident, stealth virus Length of Virus.....: .COM & .EXE files: length increased by 3584 bytes in RAM: 4096 bytes. --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: --- Type of infection...: System: Allocates a memory block at the high end of memory. Finds original address of Int 21h handler and original address of Int 13h hand- ler, therefore bypasses all active monitors. Inserts a JMP FAR to virus code inside origi- nal DOS handler. .COM & .EXE files: program length increased by 3584. A file will only be infected once. Files with READ-ONLY attribute set can be in- fected; files with SYSTEM attribut set will not be infected (e.g.IBMBIO.COM, IBMDOS.COM). COMMAND.COM is the first file, which will be in- fected in an non infected system. Infection Trigger...: Files are infected if function 4B00H (Load/Exe- cute) or function 3EH (Close File) of MS-DOS is called and if last three bytes of file- name sum-up to either 223 (COM) or 226 (EXE), and if free diskspace is >16384 bytes. Interrupts hooked...: INT21h, through a JMP FAR to virus code inside DOS handler; INT01h, during virus installation & processing INT13h, INT24h during infection. Damage..............: Permanent Damage: a message will be displayed: "FISH VIRUS #6 - EACH DIFF - BONN 2/90 '~Knzyvo}'" and then the processor stops (HLT instruction). Damage Trigger......: If (system date>1990) and a second infected .COM file is executed. Particularities.....: 1. The virus is encrypted in memory and on disk. 2. Summing-up the last 3 bytes of the filename for determining .COM and .EXE files for in- fection will also include more than 1200 other extensions such as .BMP,.MEM,.OLD,.PIF, .QLB for .COM-files and .LOG,.TBL for .EXE- files and filenames without extension, e.g. READCOM. , TESTFAX. , TEXTOLD. Therefore, virus code will be appended to datafiles (e.g. when using "TYPE TEXTOLD", file TEXTOLD will be infected). 4. Only files with id="MZ" or id="ZM" get infected as .EXE. 5. If virus is not in memory, infected data files are corrupted. 6. Infected files get a new date 100 years ahead: (newyear:=oldyear+100); e.g 1991+100=>2091, but with DIR, the new date is not visible. 7. Do not use "CHKDSK /F" in an infected system, as files get damaged (crosslinked-sectors). 8. If the system is infected, the virus redirects all file accesses so that the virus itself can not be read from the file (stealth technique). 9. Find first/next function returns are tampered so that files with (year>100) are reduced by 3584 bytes in size. 10.Get/set filedate is also tampered. Remark: the reference to "Bonn" built-into the message (see damage) has lead to the assump- tion that FISH#6 was originated in this Ger- man town; a similar assumption has been made for the related WHALE=MOTHER FISH virus due to a string "Hamburg" appearing in its code. There is *no forther evidence* that both variants of 4096 originated in Germany; the mentioned strings more probably are built-in to masquerade the origin (Russian: MASKIROWKA) Similarities........: FISH 6 is an optimized 4096 virus as it inherits most of the technology of the 4096 virus. The string '~Knzyvo}' meaning "TADPOLES" is also found in WHALE=MOTHERFISH virus. --------------------- Agents ----------------------------------------- Countermeasures.....: Cannot be detected on disk while in memory, so no monitor/file change detector can help. Countermeasures successful: 1) A Do-it-yourself way (see 4096 virus): Infect system by running an infected file, ARC/ZIP/LHARC/ZOO all infected .COM and .EXE files, boot from uninfected floppy, and UNARC/UNZIP/LHARC E etc. all files. Pay special attention to disinfection of COMMAND.COM. 2) FINDVIRU 1.6 (Solomon) 3) F-FCHK 1.12+ (F. Skulason) 4) SCAN 6.3V72 (McAfee) 5) My NTIFISH6.EXE is an antivirus that only looks for FISH 6 virus, and if requested will restore the file. Standard means......: Only sucessful if virus is not in memory! Boot from an uninfected write-protected disk and check century of files (with proper tool). --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Stefan Tode Documentation by....: Stefan Tode Date................: 12-February-1991 Information source..: see: "Virus Bulletin" (also: see 4096) ===================== End of FISH-6 Virus ============================ ====== Computer Virus Catalog 1.2: Hello Virus (14-February-1991) ==== Entry...............: Hello Virus Alias(es)...........: Hello_1a=Hall(oe)chen (German, meaning "Hy!") Virus Strain........: --- Virus detected when.: January 1990 where.: South-West-Germany Length of Virus.....: 2011 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 3.00+ Computer model(s)...: IBM compatibles --------------------- Attributes ------------------------------------- Easy Identification.: Textstring: "Hall(oe)chen, here I'm" "Acrivate Level 1" (wrong syntax!) Type of infection...: Link-Virus; Infects COM- and EXE-files Infection Trigger...: Any program file with file-date different from the system-date (only year/month) Storage media affected: Floppy and harddisk Interrupts hooked...: INT 21h, function 4Bh INT 08h and INT 16h for Damage Damage..............: Slows system down, corrupts keyboard-entries (pressing "A" produces "B") Damage Trigger......: Infection-level greater than 50 or 70 Particularities.....: The damage will not be activated. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Scan V57+ (McAfee), Countermeasures successful: CleanV57+ Standard means......: --- --------------------- Acknowledgement -------------------------------- Location............: VTC-Hamburg, BIT-Karlsruhe Classification......: Matthias Jaenichen, Christoph Fischer Documentation by....: Matthias Jaenichen Date................: 31-January-1990 Update..............: 14-February-1991 Information Source..: --- ===================== End of Hello - Virus =========================== ==== Computer Virus Catalog 1.2: Keypress Virus (10-February-1991) === Entry...............: Keypress Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: January 1991 (when VTC received virus copy) where.: Frankfurt (in an international hotel) Classification......: Program virus (extending), RAM-resident Length of Virus.....: .COM-file length increased by 1232-1247 bytes; .EXE-file length increased by 1472-1487 bytes. --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM - PC, XT, AT and compatibles --------------------- Attributes ------------------------------------- Easy Identification.: Typical text in virus body (readable with HexDump-utilities): ".COM",00h,".EXE",00h Type of infection...: System: RAM-resident, infected if the word 0001h is found at position 0000h:0600h. .COM - Files: if DOS version>=3.00 then ex- tended by using EXEC-function else ex- tended by using open file function and no system file infection. Only files with length from 1217 to 64064 bytes can be infected; files may only be infected once. .EXE - Files: if DOS version>=3.00 then extended by using EXEC-function else extended by using open file function and no system file infec- tion; files may only be infected once. Infection Trigger...: When function 4B00h (EXEC), or function 3D0x (open file) of INT 21h is called. Interrupts hooked...: INT 21h and INT 1Ch always; INT 23h and INT 24h during infection. Damage..............: Transient damage: every 10 minutes, the virus will look at INT 09h (keyboard interrupt) for 2 seconds; if a keystroke is recognized during this time, it will be repeated depend- ing on how long the key is pressed; it thus appears as a "bouncing key". Permanent damage: --- Particularities.....: Date and time of last file modification is set to the current date. .COM files longer than 64032 bytes are no longer loadable. --------------------- Agents ----------------------------------------- Countermeasures.....: --- - ditto - successful: --- Standard means......: Notice file length. Notice date and time of last file modification. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Thomas Lippke Documentation by....: Thomas Lippke Date................: 10-February-1991 ===================== End of Keypress-Virus ========================== ===== Computer Virus Catalog 1.2: Mirror Virus (12-February-1991) ==== Entry................. Mirror Virus Alias(es)............. Flip Clone Virus Strain................ --- Detected: when........ 18-December-1990 (when VTC received virus code) where....... Hamburg, Germany Classification........ Program Virus, indirect action, postfix Length of Virus....... File: either 925 or 933 bytes RAM: 928 bytes ---------------------- Preconditions --------------------------------- Operating System(s)... MS/PC-DOS Computer models....... All IBM PC compatibles. ---------------------- Attributes ------------------------------------ Easy identification... --- Type of infection..... Program virus that only infects files with the extension EXE. The virus loads itself into RAM and hooks various INT 21h functions. When one of these are called, the virus will search the current directory for EXE files to infect. The virus will be located behind the host program. A generation counter is incremented whenever an infected file is run again. Infection trigger..... Any time an infected file is run. Media affected........ Any logical disks. Interrupts hooked..... INT 21h Functions 0fh,16h,3ch,3dh,4b00h,4b03h Damage................ Permanent damage: --- Transient Damage: when triggered, the screen will flip horizontally character for character, but not as sophisticatedly as Flip virus. Damage trigger........ If a program is run with a generation counter of 10, a routine will be installed with INT 1ch pointing to it. After approximately 10 minutes, the damage will trigger. Particularities....... There are a number of possible design bugs in the virus, that may cause unpredictable behaviour. Similarities.......... Although having a similar damage to Flip, this is a completely different virus. ---------------------- Agents ---------------------------------------- Countermeasures....... --- - ditto - successful. McAfee's Scan version 72 Standard Means........ --- ---------------------- Acknowledgements ------------------------------ Location.............. Virus Test Center, University Hamburg, Germany Classification by..... Morton Swimmer Documentation by...... Morton Swimmer Date.................. 12-February-1991 Information source.... --- ====================== End of Mirror Virus =========================== ====== Computer Virus Catalog 1.2: RPVS Virus (10-February-1991) ===== Entry..............: RPVS Virus Alias(es)..........: TUQ = 453 Virus Strain.............: --- Detected: when.....: 1-August-1990 where....: Suedwestdeutscher Bibliotheksverbund (located at University of Konstanz, Germany) Classification.....: Link virus, direct action COM infector Length of virus....: 453 bytes added to COM files -------------------- Preconditions ----------------------------------- Operating System(s): MS-DOS Version/Release....: 2.0+ Computer models....: All MS-DOS-Machines -------------------- Attributes -------------------------------------- Easy identification: File size increased by 453 bytes. The following offsets are taken relative to the address the JMP instruction (cf. infra) points to: offset | string / bytes found -------+---------------------------------- 007 | "VIRUS" 00D | "*.COM" 013 | "????????COM" 030 | file-id of the infected program 043 | original contents of 1st 3 bytes 052 | "TUQ(?)RPVS" Self-identification: Last two bytes = 9090(hex). When an infected file is executed, one uninfected .COM-file in cur- rent directory is infected by appending the viral code. Type of infection..: Direct action. Begin of program is overwritten with JMP instruction pointing to appended viral code. Infection trigger..: Executing an infected file will trigger the infection attempt in the local directory. Virus has been tested with one bait (at most) available, so it is not clear whether multiple programs will be infected. No files outside the local directory have been infected during tests. Storage media affected: Current media (current directory). Interrupts hooked..: --- Damage.............: --- Particularities....: --- -------------------- Agents ------------------------------------------ Countermeasures....: Category 3: ANTI!453.EXE (d:) (/f) Countermeasures successful: ANTI!453.EXE (Daniel Loeffler,VTC-Hamburg) looks for infected files on a given drive (d:) and optionally removes the virus (if /f given). Standard means.....: --- -------------------- Acknowledgement --------------------------------- Location...........: Rechenzentrum der University Konstanz Classification by..: Otto Stolz Daniel Loeffler (VTC-Hamburg) Documentation by ..: Otto Stolz Daniel Loeffler (VTC-Hamburg) Date...............: 10-February-1991 ==================== End of RPVS-Virus =============================== ===== Computer Virus Catalog 1.2: Sadam Virus (14-February-1991) ===== Entry...............: Sadam Virus Alias(es)...........: =Saddam Virus Virus strain........: Stupid Virus Strain (?) Virus detected when.: 1-October-1989 where.: BBS in Israel Classifications.....: COM file infecting virus/extending, resident. Length of virus.....: 917-924 bytes, depending on size of name of infected file. Length of Virus.....: 919 bytes appendend (CBh+2CCh) --------------------- Preconditions ---------------------------------- Operating system(s).: MS-DOS Version/release.....: 2.0 or higher Computer model(s)...: IBM PC,XT,AT and compatibles --------------------- Attributes ------------------------------------- Identification......: Memory: INT 6Bh points to original INT 21h. (see Particularities [4]) .COM files: The encryped message; to decrypt the string, add 6 to each char, the terminat- ing char is 24h before adding 6. The name of the infected file is stored with the virus. (name is stored at infection time; later renaming will not be recognized!) Type of infection...: System: The virus copies itself to high memory at the adress [0:413]*40h-867h. The virus does not diminish the memory size by what is written in [0:413], nor will DOS regard that area as used; therefore, big programs may hang-up the system. .COM files: Extends .COM files; appends 919 bytes to the end of the file. .EXE files: Not infected. Infection trigger...: Several file services of INT 21h Interrupts hooked...: INT 21h, INT 6Bh. Damage..............: Displays the message: "HEY SADAM"{LF}{CR} "LEAVE QUEIT BEFORE I COME" (wrong syntax) Damage trigger......: Counts the number of infections; on every 8th infection, the string will be displayed. Particularities.....: 1. Many programs load themself to this area and therefore erase the virus from memory. 2. The virus uses INT 6BH replacement for the original INT 21H. 3. The virus infects just files in the current directory. 4. If the disk is write-protected, the message from DOS about write protection will be dis- played when the virus tries to spread. 5. The virus will not be able to change files that have the Read-Only attribute set. --------------------- Agents ----------------------------------------- Countermeasures.....: F-Prot 1.13 RESIDENT PART ONLY: identifies the virus as The Stupid Virus and does not let the program get into memory. --------------------- Acknowledgement -------------------------------- Classification by...: Baruch Even (NYEVENBA@WEIZMANN.BITNET) Matthias Jaenichen, VTC-Hamburg Documentation by....: Matthias Jaenichen, VTC-Hamburg Date................: 5-October-1990 Update..............: 14-February-1991 Information Source..: --- ===================== End of Sadam - Virus =========================== ====== Computer Virus Catalog 1.2: 1260 Virus (11-February-1991) ===== Entry................. 1260 Virus Alias(e).............. Variable, Chameleon, Camouflage, Stealth, V2P1 Strain................ distantly related to Vienna strain Detected: when........ where....... Classification........ Program Virus with direct action, COM infector Length of virus....... 1260 Bytes ----------------------- Preconditions -------------------------------- Operating System(s)... MS-DOS Version/Release....... 2.xx and upwards Computer models....... IBM PC's and compatibles ------------------------Attributes ----------------------------------- Easy identification... The seconds field of the timestamp of any infected program will be 62 seconds. Type of infection..... Program virus with direct action. It only in- fects files with COM extension. It replaces first 3 bytes with a jump to the virus. Infection trigger..... Execution of an infected file Media affected........ The virus will infect any COM file in the current directory. Interrupts hooked..... INT 1 and INT 3 while virus is executing Damage................ transient: --- permanent: --- Particularities....... The actual virus code is encrypted once over the whole code, and various single bytes are also encrypted throughout the virus. These bytes are decrypted prior to exec- ution, using its INT 3 (break point) routine to decrypt, and its INT 1 (trace) routine to encrypt. The encryption routine used to decrypt the entire virus is obscur- red by the addition of irrelevant instruc- tions and by scrambling the order of the instructions from infection to infection. As a consequence of this stealth technique, it is not possible to extract any scan string from this virus at all. Similarities.......... The virus is similar to Vienna virus, but highly modified, to contain the encryption methods described above. ----------------------- Acknowledgement ------------------------------ Location.............. Virus Test Center, University Hamburg, Germany Classification by..... Morton Swimmer Dokumentation by ..... Morton Swimmer Date.................. 12-February-1991 ====================== End of 1260 Virus ============================= ======= Computer Virus Catalog 1.2: AZUSA Virus (15-July-1991) ====== Entry...............: AZUSA Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: January 1991 (?) where.: Ohio, USA Classification......: Resident Boot sector and Partition Table Infector Length of Virus.....: 1024 Bytes in memory, 1 sector (400 h) on media --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: 1) Reduction of available memory by 1,024 bytes: CHKDSK returns 654,336 bytes total memory in- stead of 655,360 bytes on 640k machines. 2) "E9 8B 00" are first three bytes of infected boot record or partition table. Scanner Signature...: "E9 8B 00" at 00h on boot sector/partition table Type of infection...: Virus is extremely virulent and will infect hard disk even if partition table cannot be found (cannot boot thereafter). Hard disk: virus replaces absolute sector 1 (partition code & table) with itself, main- taining table data in internal location. Floppy: Virus attempts to infect all floppies previously uninfected; original boot record is stored at track 28h head 1 sector 8 regardless of floppy size. Infection Trigger...: Booting an infected system Interrupts hooked...: --- Damage..............: Permanent Damage: Data lost; COM1&LPT1 "hidden" 1)Data lost: as virus overwrites 1 sector on floppies, previously stored data are lost; on disk, partition table is overwritten but old table data are stored inside virus. 2)COM1 & LPT1 "hidden": after approx.20h re- boots, virus zeroes pointers to COM1 & LPT1 thus making those devices unaccessible. 3)Virus may cause boot failure on machines with security programs in place. Transient Damage: Reduction of available memory by 1,024 Bytes. Damage Trigger......: After approx. 20h reboots, COM1 & LPT1 become in- accessible as pointers are zeroed. Particularities.....: 1) Virus does not use stealth techniques (neither evasive measures nor encryption). 2) Odd coding techniques and lack of understand- ing of floppy disk characteristics indicate self-taught writer/experimenter. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Reload floppy boot sector; use partition table data maintained inside virus to reconstruct original partition table. Countermeasures successful: Detection: SCAN v75, DISKSECURE Standard means......: --- --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Klaus Brunnstein Documentation by....: A.Padgett Peterson, Computer Network Security, Orlando/Florida Date................: 18-April-1991 Information source..: A.Padgett Peterson ===================== End of AZUSA Virus ============================= ==== Computer Virus Catalog 1.2: Empire A/B Virus (15-July-1991) ===== Entry...............: Empire-A Virus Alias(es)...........: --- Virus Strain........: Major variant of: Stoned = Marijuana Virus Known Variant.......: Empire-B Virus Virus detected when.: April 1991 where.: Alberta Canada (?) Classification......: Memory resident Boot + Partition table infector, Stealth virus,undergoing detection mechanisms Length of Virus.....: Empire-A: 2,048 Bytes in Memory, 2 sector(floppy) Empire-B: 1,024 Bytes in Memory, 1 sector(floppy) --------------------- Preconditions ----------------------------------- Operating System(s).: MSDOS Version/Release.....: 2.xx upward (not tested) Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes ------------------------------------- Easy Identification.: Memory size reduced: CHKDSK will return 653,312 "total bytes memory" on a 640k machine. Check first four bytes of MBR or Boot sector for "EA 9F 01 C0",common to Empire-A/B variants. Scan signature......: When booted from a clean floppy disk, virus can be detected using the string "A3 08 7C A1 13 04 48" (Empire-A) Type of infection...: Boot sector virus, related to Stoned; virus consists of 2 sectors, the first of which contains its executable code and replaces MBR on a harddisk or BR on floppy. On floppy, the original boot record is stored on track 0 head 1 sector 2, and the message is stored on the next sector, in simply encrypted form. On harddisk, the original MBR is stored on cyl 0 head 0 sector 6, with the message on the next sector. Stealth mechanism: when virus is active in memory, any request for the MBR will be intercepted by the virus and the real MBR will be returned. Similarly, any attempt to write to the MBR will be changed to a reset by the virus. Infection Trigger...: --- Interrupts hooked...: --- Damage..............: Permanent Damage: Problems on Harddisk/Floppy: High density floppies may experience failures resulting from storage of two original sectors on track 0 head 1 sectors 2-3. Low density floppies with over 80 directory entries may also have problems; these can occur even long after the floppy is dis- infected if the directory is not restored. Harddisk: a disk without "hidden sectors" will probably experience FAT failures, as the sectors to which the original boot sectors have been stored are assumed to be in the "hidden sector" area. Transient Damage = Memory reduction, Message: 1)Active Empire-A virus reduces total memory by 2,048 bytes (CHKDSK will return 653,312 "total bytes memory" on a 640k machine) 2)The following message ( where each sentence is a single line and relies on text- wrapping by terminal for legibility) is displayed: "I'm becoming a little confused as to where the "evil empire" is these days. If we paid attention, if we cared, we would realize just how unethical this impending war with Iraq is, and how impure the American motives are for wanting to force it. It is ironic that when Iran held American hostages, for a few lives the Americans were willing to drag negotiation on for months; yet when oil is held hostage, they are willing to sacrifice hundreds of thousands of lives, and refuse to negotiate ......." Damage Trigger......: Message display is triggered by function of realtime clock (details to be analysed) Particularities.....: Virus tries to avoid reverse analysis: a "cute" at the start will throw a researcher off if a standard STONED opening is expected. Similarities........: Basically Stoned (I), with major deviations Known Variant.......: Empire-B, with following major differences: 1) Virus occupies 1,024 Bytes in Memory 2) Text sector is not used, no message 3) Virus uses encryption with different algorithm on each infection, based on time hack 4) When resident on fixed disk, the original partition table is stored at sector 3 head 0 cyl 0. On floppy, sector 3, head 1, track 0 is used. EMPIRE and EMPIRE-B avoid cross infection by signature checking the first four bytes of MBR or Boot sector for "EA 9F 01 C0". Remark..............: Other common characteristics indicate that both Empire-A and -B were written by the same person or by two people sharing notes. --------------------- Agents ----------------------------------------- Countermeasures.....: Detection: CHKDSK, F-DISKINF, DISKSECURE (SCAN v76C does not pick this up) Countermeasures successful: Detection: CHKDSK, F-DISKINF, DISKSECURE Standard means......: --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Klaus Brunnstein Documentation by....: A.Padgett Peterson, Computer Network Security, Orlando, Florida Date................: April 18, 1991 Information source..: A.Padgett Peterson ===================== End of Empire A/B Virus ======================== ====== Computer Virus Catalog 1.2: Fingers Virus (15-July-1991) ====== Entry...............: Fingers Virus Alias(es)...........: "08/15" Virus Virus Strain........: --- Virus detected when.: --- where.: --- Classification......: Resident Program (COM & EXE) Infector, indirect action. Length of Virus.....: COM & EXE: 1322 Bytes Memory: Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 3.00 upward Computer model(s)...: IBM-PC and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: Virus contains strings (in memory and on file): db "CRITICAL ERROR 08/15: TOO MANY Fi" db 0Fh,"GERS ON KEYBOARD ERROR." Self-identification.: Infected EXE- and COM-files are recognized by signature "TM" in file's CRC field (offset 12h); self-recognition via hooked INT 21h, AX=0FFFEh (returns AX=0815h when virus is resident) Scanner Signature...: --- Type of infection...: Infects COM- and EXE-files by appending at end of file. Infection Trigger...: Upon execution (INT 21h, function AH=4Bh) Storage media affected: all drives Interrupts hooked...: INT 21h,INT 24h,INT 09h(from date of activation) Damage..............: Transient damage: After 1500 keystrokes, the following message is displayed: "CRITICAL ERROR 08/15: TOO MANY FINGERS ON KEYBOARD ERROR." After the message has been displayed, system is halted by virus. Damage Trigger......: Activation date = 11-NOVEMBER-1991 Particularities.....: --- Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: McAfee's Scan V80+ Countermeasures successful: McAfee's Scan V80+ Standard means......: --- --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: M.Mandelbaum Documentation by....: H.Hoppenrath (H+B EDV), M.Mandelbaum VTC Date................: 15-July-1991 Information Source..: --- ===================== End of Fingers Virus =========================== = Computer Virus Catalog 1.2: Green Caterpillar Virus (15-July-1991) = Entry...............: Green Caterpillar (A/B/C) Virus Alias(es)...........: "1575/1591" (15xx) Virus Virus Strain........: Caterpillar Virus detected when.: January 1991 where.: Ontario, Canada Classification......: Resident Program (COM & EXE) Infector Length of Virus.....: Program: 1575 Bytes (modulo 16:1575-1591) Memory: 1760-1840 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MSDOS Version/Release.....: Version 3.00 and upwards Computer model(s)...: IBM-Compatibles (only in Real-Mode) --------------------- Attributes ------------------------------------- Easy Identification.: Text-String found "C:\COMMAND.COM $$$$$" Type of infection...: Memory: virus installs itself in high memory, but will not protect itself against being overwritten in RAM (A-Variant). COM & EXE files: one COM AND one EXE file are infected upon infection triggered; file-date will be changed to system-Date. COMMAND.COM will be infected immediatly after execution. Infection Trigger...: Any time a COPY or DIR-Command is executed Storage media affected: Any media, infection of current path. Interrupts hooked...: INT 21h; INT 24h; corrupts COPY and DIR commands Damage..............: Transient damage: a green caterpillar creeps over the screen, starting at the upper left corner. Damage Trigger......: Two month after 1st infection. Particularities.....: There are three variants reported: B-Variant installs itself in memory, includ- ing self-protection against overwrite. C-Variant is able to infect a program during its execution. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Scan (>V73); VirScan; F-Prot Countermeasures successful: Scan (>V73); VirScan; F-Prot Standard means......: Boot from clean system-disk, restore COMMAND.COM, delete all infected files; hide COMMAND.COM in a separate directory, and use the COMSPEC- entry in the CONFIG.SYS file to avoid re- infection of COMMAND.COM. --------------------- Acknowledgement -------------------------------- Location............: Virus-Test-Center; University Hamburg, Germany Classification by...: Matthias Jaenichen, VTC Documentation by....: Matthias Jaenichen, VTC Date................: 15-July-1991 Information Source..: Disassembly, Vsum9103 (Patricia Hoffman) ================= End of Green Caterpillar Virus ===================== ========= Computer Virus Catalog 1.2: G&H Virus (15-July-1991) ======= Entry ................. G&H Virus Alias(es) ............. Demovirus G&H (see: Particularities) Strain ................ --- Detected: when ........ February 1991 where ....... Germany Classification ........ Program virus: Non-resident COM infector Length of Virus ....... 1247 bytes ----------------------- Preconditions -------------------------------- Operating System(s) ... MS-DOS Version/Release ....... 2.11 and upwards Computer models ....... IBM PC and compatibles ----------------------- Attributes ----------------------------------- Easy identification ... The virus displays a message (in German) every time it infects a file. The message en- compasses a whole screen and includes in- formation on the virus (its length wrongly stated as 1.000 bytes, and virus' behaviour, the author's address as well as advertise- ment for a brochure on PC security. You must press a key before the message goes away. Type of infection ..... The virus infects COM files on diskette drive A in direct action and does not go resident. Six bytes are changed in the beginning of the file (the jump to the virus) and the rest is appended to the file. Infection trigger ..... Execution of an infected program Media affected ........ Only the physical drive A: (in most cases: first floppy drive). Interrupts hooked ..... INT 13 for a short time; it is not used for infection or damage. Damage ................ Transient Damage: message is displayed. Permanent Damage: --- Side Effects: not observed, but possible. Damage trigger ........ Every time an infected program is run. Particularities ....... 1) Checks if the drive is a logical drive by seeing whether DOS uses BIOS to access the disk. Virus checks to see if the text has been changed, by building a checksum over the text; if text was changed, the virus terminates. 2) This virus was produced by a computer security firm in Germany (near Cologne) and sold for a nominal fee (50 DM) by mail-order; the virus was advertised in a German Data Protection monthly as educa- tional. Only after German Information Security Agency (GISA)'s intervention, the distribution was stopped after apparently a few copies were sent out (with major de- mand unsaturated); in another advertisement the virus was officially withdrawn. 3) Even though the names of firm and authors are known and even displayed on screen, VTC anonymizes it by given only the initials as long as virus is not further distributed. Similarities .......... --- ----------------------- Agents --------------------------------------- Countermeasures ....... (no contemporary scanner finds this virus) - ditto - successful . --- Standard Means ........ When seeing message, replace infected program with original (non-infected) version. ----------------------- Acknowledgements ----------------------------- Location .............. Virus Test Center, University of Hamburg, FRG Classification by ..... Morton Swimmer Documentation by ...... Morton Swimmer Date .................. 15-July-1991 Information source .... (original virus reverse-analysed) ======================= End of G&H Virus ============================= ===== Computer Virus Catalog 1.2: Headcrash Virus (15-July-1991) ===== Entry...............: Headcrash Virus Alias(es)...........: "1067" Virus Virus Strain........: --- Virus detected when.: University Giessen (Germany) where.: March 1991 Classification......: .COM - file: RAM-resident program virus Length of Virus.....: .COM - Files: 1067 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM - PC, XT, AT and compatibles --------------------- Attributes ------------------------------------- Easy Identification.: .COM files: first three bytes (E9h WXh YZh) and last three bytes are identical. The seconds field of the timestamp is changed to 62 sec, similar to Vienna strain. Type of infection...: RAM-resident: infected if function AX=58CCH of INT 21H is available in system (carry flag not set). .COM file: infected by hooking EXEC-function. If a program is executed, the virus infects the first not-infected .COM file found in the directory of the executed file; it apends 1067 bytes at the end of the file. Only files with extension .COM and with 1791 < filesize < 61696 bytes are infected. Files are infected not more than once. .EXE file: no infection. Infection Trigger...: System will be infected if day is odd and DOS version > 1.00 . .COM file will be infected, when function 4B00H (LOAD/EXEC) of INT 21H is called. Interrupts hooked...: INT 09H,21H,24H; INT 21H (functions 4B00H, 2521H, 3521H, 58CCH and 58DDH); INT 09H only during execution of infected files; INT 24H only during infection of files. Damage..............: Permanent Damage: Every time a file is executed in an infected system, a .COM file will be infected. Transient Damage: Only once per installation of virus before execution of a file, the fol- lowing message is displayed: "Headcrash Industries celebrate 0040hex." (0040H is the infection counter,and may vary) Damage Trigger......: If a file is executed between 20 and 25 minutes after virus installation AND if realtime clock was not read before virus installation AND if infection counter > 31, then this message is displayed. Particularities.....: - The message "Headcrash.....hex." is encrypted. - All files with .COM extension will be infected (i.e also exe-files with .COM extension). - .COM files with exe-header-id "MZ" will not run after infection. - Command.com will be infected. - At infection of COMMAND.COM, the free memory is temporally shrinked to 64k byte; therefore, many programs will no longer execute. - File attributes are restored after infection. - Get/Set interrupt 21H (functions 3521H,2521H) is monitored and modified by virus. - Function AX=58DDH of INT 21H returns: CX = codesegment of virus, ES/BX = segment/offset of old int 21H. --------------------- Agents ----------------------------------------- Countermeasures.....: Category 3: NTI1067.EXE (VTC Hamburg) - ditto - successful: NTI1067.EXE finds and restores infected programs. Standard means......: Notice .COM file length and seconds-timestamp. Search for hex bytes: 01H,B4H,2AH,CDH,21H,F6H, C2H,01H,75H,03H at location 62 of virus. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Stefan Tode Documentation by....: Stefan Tode Date................: 15-July-1991 ===================== End of Headcrash Virus ========================= ===== Computer Virus Catalog 1.2: LoveChild Trojan (15-July-1991) ==== Entry...............: LoveChild Trojan Horse Alias(es)...........: --- Virus Strain........: Lovechild Strain Virus detected when.: where.: Classification......: Trojan Horse Length of Trojan....: 64 Bytes --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: all DOS-versions Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: Text "LoveChild in reward for software sealing." is contained within the file. The trojan has a lenght of 64 bytes. Scanner Signature...: 4C 6F 76 65 43 68 69 6C 64 20 69 6E 20 72 Type of infection...: This trojan is installed by LoveChild virus. Infection Trigger...: --- Storage media affected: The first harddisk. Interrupts hooked...: --- Damage..............: Trojan writes garbage onto the first harddisk, starting with track 0 and using the first 4 heads. This trojan counts through all tracks, overwriting each, until the harddisk is completely thrashed. Damage Trigger......: Execution of the trojan. Particularities.....: See: LoveChild Virus (Computer Virs Catalog) Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Scan v80 by McAfee finds this trojan. Countermeasures successful: Clean v80 by McAfee deletes this trojan. Standard means......: Delete infected files, copy uninfected versions from original write-protected disk. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Toralv Dirro, Gerald Schrod Documentation by....: Toralv Dirro, Gerald Schrod Date................: 15-July-1991 Information Source..: --- ===================== End of LoveChild Trojan ======================== ==== Computer Virus Catalog (1.2): LoveChild Virus (15-July-1991) ==== Entry...............: LoveChild Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: where.: Classification......: Memory-resident Program Infector (COM) Length of Virus.....: COM-files: 488 Bytes --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: Version 3.30 (all other versions crash) Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: The text "(c) Flu Systems (R)" and "LoveChild in reward for software sealing.." can be found at the end of infected COM-files as well as in memory at the adress 0:1e0. Scanner Signature...: 4C 6F 76 65 43 68 69 6C 64 20 69 6E 20 72 Type of infection...: The virus appends itself to the end of COM-files; first 3 bytes are saved und used for it's identification-byte ($fb) and a jump; these will be restored after execution of virus. Infection Trigger...: Execution of an infected program. Storage media affected: Files can be infected on all media. Interrupts hooked...: INT 21, functions 4b (open/execute) 3d (open with handle) 56 (rename) 3c (create file) 40 (write to file) are used to infect com-files and for the effects (see: particularities). Damage..............:Permanent damage: 1) If an EXE-file is write-accessed (INT 21, ah=40), virus reads a random number and some- times rewrites the file with a trojan horse. If the trojan is executed, it will write gar- bage to harddisk on first four heads, star- ting with track 0 and continuing until reset! (for description of the trojan: see Virus Catalog entry of LoveChild Trojan) 2) If a file is created (INT 21,ah=3c), virus sometimes (randomly) decides to call INT 21, ah=39, thus creating a subdirctory instead. 3) If a file which is not a COM-file is opened, renamed or executed (ah=3d/56/4b), virus sometimes (randomly) calls INT 21, ah=41, thus deleting the entire file. Transient damage: --- Damage Trigger......: 1) Any Write-to-a-file operation (e.g. copying) 2) Create-a-file operation 3) Open or execute non-COM-files or rename file. A random number is used to decide wether to per- form the respective damage or not. Particularities.....: Due to an error in the virus, it will crash on all versions other than MS-DOS 3.30; this is probably due to unsufficient testing; change of one byte only allows virus to run on all DOS versions available. On MS-DOS 3.30, the virus rewrites INT 13; there- fore, any protection-software hooking INT 13 is deactivated. Virus doesn't hook INT 21 directly; it tries to hide, by installing a jump to itself within the INT 21-routine. On other DOS-versions, virus hooks INT 21 vec- tor, but the INT 13 vector is not affected. The virus can always be found at adress 0:1e0 in memory, the entry is 0:2cd. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Scan v80 by McAfee finds virus and trojan. Countermeasures successful: Clean v80 by McAfee removes virus, as well as LOVEKILL.EXE by Toralv Dirro. Standard means......: Delete infected files, copy uninfected versions from original write-protected disk. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Toralv Dirro, Gerald Schrod Documentation by....: Toralv Dirro, Gerald Schrod Date................: 15-July-1991 Information Source..: --- ===================== End of LoveChild Virus ========================= === Computer Virus Catalog V 1.2: Nomenklatura Virus (15-July-1991) == Entry...............: Nomenklatura Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: where.: Classification......: RAM-resident Program (COM & EXE) Infector Length of Virus.....: COM & EXE fles: 1024 Bytes Memory: 1072 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM compatibles --------------------- Attributes ------------------------------------- Easy Identification.: Textstring: 'Nomenklatura' at offset 4 followed by string "00 80 FC 4B 74 0A 80 FC 3D 74 14" Self Identification : Checks length of code after execution of initial jump; infects only if this length isnot 1024. Type of infection...: System: Allocates a memory block at high end of memory, finds original adress of INT 13h handle, collects and changes INT 21h vector. COM&EXE files: program length increased by 1024. Required size of files for infection: .EXE: more than 1024 bytes .COM: filesize between 1024 and 64000 bytes. Files will only be infected once. COMMAND.COM is normally first file that will be infected. If ReadOnly attribute of file is set, virus is not able to infect it. File date & time will not be changed. Infection Trigger...: Programs are infected at load time (using MsDos function 4Bh) as well as when MsDos function 3Dh is invoked. Storage media affected: Any drive Interrupts hooked...: INT 13h during virus installation in RAM, INT 21h hooked by resident part of virus. INT 13h, INT 24h during infection. Damage..............: Permanent Damage: by exchanging random words. Any file containing exchanged words will sud- denly contain totally different data. Any type of file and both FATs may be affected. Transient damage: --- Damage Trigger......: random trigger Particularities.....: While virus is in memory, every virus scanning program will infect all files on the system, as virus uses MsDos function 3Dh (open file). Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Detection in RAM: McAfee's Scan 7.2V77 Skulason's f-syschk V 1.16+ Countermeasures successful: Detection in files & succesful desinfect: Skulason's f-fchk V 1.15+ Standard means......: Set ReadOnly attribute --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification......: Soenke Spehr Documentation by....: Soenke Spehr Date................: 15-July-91 Information Source..: --- ===================== End of Nomenklatura Virus ====================== ===== Computer Virus Catalog 1.2: "Tequila" Virus (15-July-1991) ===== Entry.................. "Tequila" Virus Alias(es).............. --- Strain................. --- Detected: when......... April 1991 where........ Steinhausen, Switzerland Classification......... Memory-resident Program AND System Infector, Stealth, complex Self-Encryption Virus Length of Virus........ EXE-Files: 2,468 Bytes System: 6 sectors (including original MBR) Memory: 3 kBytes ----------------------- Preconditions -------------------------------- Operating System(s).... MS/PC-DOS Version/Release........ 2.00 and upwards Computer models........ All IBM PC compatibles. ----------------------- Attributes ----------------------------------- Easy identification.... A text is contained in 2nd sector AFTER last sector of first active partition. This text is also displayed if INT 21h is called with AX = FE03h. The text is: "Welcome to T.TEQUILA's latest production Contact T.TEQUILA/P.o.Box 543/6312 St'hausen/ Switzerland. Loving thoughts to L.I.N.D.A BEER and TEQUILA forever !" There will be a gap of 6 sectors between the active partition and the next one. Type of infection...... The virus infects EXE files as well as the Master Boot Record and becomes resident. Memory: when an infected EXE-file is execute virus makes itself memory resident (at TOM). EXE-FILES:virus appends 2468 bytes when infec- ting a file. The code segment and offsets in EXE header are changed to point to the virus. In some cases, the stack segment is modified so that the virus will not be over- written in memory. The growth of infected files is invisible when virus is resident in memory, due to its stealth technique. The virus modifies the file's time stamp to read 62 seconds and changes the checksum in the EXE header to be one of a finite set of values. No EXE-files are infected with "SC" or "V" in name (thus excluding most antiviruses). EXE-File encryption: virus is encrypted in file; it selects 1 of 3 possible encryption algorithms and 1 of 2 methods to implement it. Moreover, a random number of random junk code is inserted between instructions. Therefore, no scan signature is valid. The encryption routine uses itself as the key (which makes debugging rather tricky.) Master Boot Record: the virus reduces the ac- tive partition's size by 6 sectors and in- serts into this space the original MBR and the entire virus. Original MBR is patched with virus code. The virus is not encrypted in the MBR. Virus stealth method intercepts Read/Write to MBR and makes original MBR available. No Boot Sector Infection. Infection trigger...... The virus will infect the MBR ONLY when started from file. After the next system start, the virus will infect files from memory. Media affected......... Files can be infected on all media. MBR is ONLY infected on hard disk, not on floppies. Interrupts hooked...... Interrupts 21h function 4Bh (LOAD/EXEC) is used to infect files; Interrupt 21 functions 11h, 12h, 4Eh, 4Fh, and Interrupt 13h are used to mask its operation; Interrupt 21h function FE02h is the virus' memory installation check; Interrupt 21h funtion FE03h displays message. Damage................. Transient Damage: at certain time/date,virus will display a fractal at program termina- tion of any file, even if not infected. Permanent Damage: virus searches for files that have been given a validation string by McAfee's Scan and destroy such files. Damage trigger......... The fractal is displayed at program termina- tion after a certain time; but there seems to be bug in the code somewhere so that it is not executed "normally". The strings are patched any time. Particularities........ 1) Like 1260, V2P2 and V2P6 viruses, virus tries to avoid being scanned for.Generally, virus authors seem to know contemporary virus developments; techniques of older viruses (SHOE-B) and recent stealth methods are used, but encryption methods have no ancestors. 2) Virus spread rapidly in Europe when an in- fected game was downloaded to a shareware BBS. Two authors (18 and 21 years) were ex- amined soon after detection by Swiss police. Similarities........... --- ----------------------- Agents --------------------------------------- Countermeasures........ --- - ditto - successful.. Solomon's Toolkit vers. 5 and Morton Swimmer's NTIteq will find and disinfect TEQUILA. Michael Weiner's inoculator ATEQUILA prevents Tequila infection. Standard Means......... --- ----------------------- Acknowledgements ----------------------------- Location............... Virus Test Center, University of Hamburg, FRG Classification by...... Morton Swimmer Documentation by....... Morton Swimmer Date................... 15-July-1991 Information source..... Michael Weiner's trace of the virus Further information: Morton Swimmers evaluation ======================= End of "Tequila" Virus ======================== ====== Computer Virus Catalog 1.2: RPVS/TUQ Virus (15-July-1991) ====== Entry..............: RPVS Virus Alias(es)..........: TUQ = "453" Virus Strain.............: --- Detected: when.....: August 1, 1990 where....: Suedwestdeutscher Bibliotheksverbund (located at University of Konstanz) Classification.....: Program virus: direct action COM-infector Length of virus....: .COM files: 453 bytes appended ------------------------ Preconditions ------------------------------- Operating System(s): MS-DOS Version/Release....: Version 2.0 upwards Computer models....: All MS-DOS-Machines ------------------------Attributes ----------------------------------- Easy identification: File size increases by 453 bytes. Diverse texts are visible (with proper tool) in the virus; the offsets given are relative to the address the JMP instruction (cf. infra) points to: offset | string / bytes found -------+---------------------------------- 007 | "VIRUS" 00D | "*.COM" 013 | "????????COM" 030 | file-id of the infected program 043 | original contents of 1st 3 bytes 052 | "TUQ(?)RPVS" Self-identification: Last two bytes = 9090(hex). When an infected file is executed, one uninfected .COM-file in current directory is infected by appending the viral code. Type of infection..: Direct action; begin of program is overwritten with JMP to appended viral code. Infection trigger..: Executing an infected file will trigger the infection attempt in the local directory. No files outside the local directory have been infected during tests. Storage media affected: Current media (Current directory). Interrupts hooked..: --- Damage.............: Transient damage: --- Permanent damage: --- Damage trigger.....: --- Particularities....: --- --------------------- Agents ----------------------------------------- Countermeasures....: Category 3: ANTI!453.EXE (d:) (/f) Countermeasures successful: ANTI!453.EXE (Daniel Loeffler,VTC-Hamburg) looks for infected files on a given drive (d:) and optionally removes the virus (if /f given). Standard means.....: --- ----------------------- Acknowledgement ------------------------------ Location...........: Rechenzentrum der University Konstanz Classification by..: Otto Stolz Daniel Loeffler (VTC-Hamburg) Dokumentation by ..: Otto Stolz Daniel Loeffler (VTC-Hamburg) Date...............: 15-July 1991 ===================== End of RPVS/TUQ-Virus ========================== === Computer Virus Catalog 1.2: "Thursday 12" Virus (15-July-1991) === Entry...............: Thursday-12 Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: June 27, 1991 where.: Tornado Bulletin Board (TECS), Hamburg Classification......: Memory-resident Program Infector Simple self-encryption Length of Virus.....: EXE-files: 2270 Bytes; COM-Files: 2168 Bytes Memory: 2161 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes ------------------------------------- Easy Identification.: INT 21 Vector is hooked to adress xxxx:026d; EXE-files start at adress xxxx:100 with jump to 106 and call to 10c (at 106); COM-files start with jump, at the target of this jump, identical code will be found. The virus' text (see: transient damage) can be found near the end of memory, 52dh bytes behind the INT 21 target adress. Scanner Signature...: String 83 f9 00 74 09 51 56 30 24 46 is con- tained near end of EXE and COM files. Type of infection...: The virus appends itself at the end of EXE and COM files. It will not infect programs con- taining any of the following strings in their name: SCAN, CLEAN, VIR, ARJ, FLU or COMMAND. Infection Trigger...: Execution of an infected program. Storage media affected: Files can be infected on all medias. Interrupts hooked...: INT 21, functions 0f,3d (both open a file), 4b (load/execute) 6c (extended open and create (dos 4.0)) are used to infect a file. Damage..............: Permanent damage: --- Transient damage: The virus draws a litte box, containing the following text: "VirCheck V1.2 (C) 1991 Be aware of those worms out there, violating your machine on Friday 13th - it's tomorrow! Special thanks to Ross M. Greenberg Patricia M. Hoffmann and John McAfee Press any key to continue..." The box disappears after pressing any key and system continues working, completely unaffacted. No side effects have been observed, although heavy damage was reported, when running this virus with a hard-disk realtime-packer. Damage Trigger......: The text appears only on Thursday 12th, after execution of 4 programs that were already infected, if the virus is in memory. Particularities.....: The virus was found on a public domain PAC-MAN game (CD-MAN), which could be downloaded from the Tornado BBS, Hamburg. The infected program was downloaded 19 times before detection of contamination; at this time (1st generation), it was also reported in Kiel (100 km north of Hamburg). After report, infected program was deleted from BBS. (It is known, who actually put the program onto BBS, and we try to get more information where the virus actualy comes from) Similarities........: --- --------------------- Agents ------------------------------------------ Countermeasures.....: (no contemporary scanner finds the virus) Countermeasures successful: ANTITH12 of Toralv Dirro finds and eradicates this virus. Standard means......: Delete infected EXE&COM files, copy uninfected versions from original write-protected disk. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Toralv Dirro, Stefan Tode Documentation by....: Toralv Dirro Date................: 15-July-1991 Information Source..: (original virus analysis) ===================== End of Thursday-12 Virus ======================= ===== Computer Virus Catalog 1.2: VCS V1.0 Virus (15-July-1991) ====== Entry................. VCS V1.0 Virus Alias(es)............. Virus-Construction-Set V1.0 = VDV Virus (VDV = "Verband Deutscher Virenliebhaber"; = "community of German virus lovers") Strain................ --- Detected: when........ March 1991 where....... Bulletin Board, Hamburg, Germany Classification........ Program Virus, direct action; overwriting AUTOEXEC and CONFIG.SYS; encrypted. Length of Virus....... File: 1077 bytes ---------------------- Preconditions --------------------------------- Operating System(s)... MS/PC-DOS Computer models....... All IBM PC compatibles. ---------------------- Attributes ------------------------------------ Easy identification... Files containing C350h at offset 03h regarded as infected (self identification) Search string at offset 00h: E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE Type of infection..... .COM files: increased by 1077 bytes; virus is not RAM resident, files can only be in- fected when an infected host is started; files are randomly infected in the current directory or in root directory and below. Files are not infected if word at offset 03h of file contains C350H. .COM files are infected only once. .EXE files: no infection. Infection trigger..... Any time an infected file is run, the virus infects up to 10 files, but only if the Int 26h (=absolute-disk-write-vector) is not hooked by a program. Interrupts hooked..... --- Damage................ Permanent damage: when triggered, the files 'C:\AUTOEXEC.BAT' and 'C:\CONFIG.SYS' will be overwritten with 512 bytes of text. Transient Damage: when AUTOEXEC and CONFIG.SYS have been overwritten, a text which was deliberately choosen by the installator (see: Particularities:Generating the virus) may be displayed. Damage trigger........ If generation counter > damage counter, the permanent/transient damage is performed. Particularities....... Virus is encrypted; on each infection, en- cryption key and generation counter are changed; virus therefore mutates. Files with ReadOnly attribute set will not be infected. .COM files longer than 64,190 bytes are no longer loadable. Particularities/Generating this virus: VCS virus was created by program VCS.EXE ('Virus Construction Set V1.0'), which was written by a "Verband Deutscher Virenliebhaber" (=community of German virus lovers) and was available via a BBS in Hamburg. Using VCS.BIN and a textfile, VCS.EXE generates the program VIRUS.COM (1077 bytes). In constructing this virus, the user can adjust the damage counter (1st active generation: 1..199) and specify his own textfile of 512 bytes. In VCS' menu (22 lines), detailed informa- tion is given how to generate 1st virus, ending with: "3) Start VIRUS.COM ... The infected program is now 1077 Bytes longer than before and can be given to known persons, friends and enemies.." The textfile (in German, 29 lines) distri- buted with VCS is essentially: "Virus Construction Set" "All have waited for it, here it is! Who didnot want to shove a little virus under his best enemy, but had none at his hand? ....." "This virus copies itself when invoked on .COM files in actual drive, after speci- fied number of generations a specified text will be displayed, AUTOEXEC.BAT and CONFIG.SYS will be deleted. Virus detects FLUSHOT in memory and keeps quiet." "This program is a community exercise of VDV Hamburg. We can be reached in BBS Hamburg (local tel#) under 'VDV'...." "In case of interest, version 2 of VCS will soon be available, with more possi- bilities to tune the virus." "Now to the legal aspect: herewith, a user is explicitly warned that this program generates viruses which may damage data. By using this program, the user accepts full responsibility for the viruses which he generates. We are not responsible under any circumstances. Nevertheless we renounce, due to evident reasons, to mention our adress here..." "... donate 20 DM to Red Cross. Generally, this program may be copied and used as desired." "We wish much fun with our viruses...." Similarities........... --- ---------------------- Agents ---------------------------------------- Countermeasures....... Searchstring at offset 00h of virus: E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE - ditto - unsuccessful. McAfee's Scan version 75 and below - ditto - successful. Tode's NTI-VCS.EXE is an antivirus that only looks for VCS virus, and if requested will restore the file. Standard Means........ Notice file length. Use ReadOnly attribute. ---------------------- Acknowledgements ------------------------------ Location.............. Virus Test Center, University Hamburg, Germany Classification by..... Stefan Tode Documentation by...... Stefan Tode and Matthias Jaenichen Date.................. 15-July-1991 Information source.... --- ====================== End of VCS V1.0 Virus ========================= ======== Computer Virus Catalog 1.2: "982" Virus (15-July-1991) ====== Entry...............: 982 Virus Alias(es)...........: (Klaeren Virus; see: Particularities/Remark) Virus Strain........: --- Virus detected when.: March 1991 where.: University of Tuebingen (South-West Germany) Classification......: Resident File Infector Length of Virus.....: 972-982 Bytes (file) --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: --- Scanner Signature...: at end of infected file: 9C FF 1E EB 04 53 51 E8 00 00 5B 81 EB AF 03 B9 A5 03 80 37 ?? 43 E2 FA 59 5B 3B C1 C3 32 C0 CF 4D 5A Type of infection...: Program Infector: virus appends itself at end of .COM and .EXE files, enlarging the filesize between 972 and 982 bytes. Infection Trigger...: Interrupts hooked...: Damage..............: On trigger condition (in May, each year), transient damage is produced. Transient Damage: On trigger condition (May), virus writes several screen pages with text "Klaeren, Ha^s, Ha^s!" (^s = scharfes s, ascii 225; Ha^s=hate), and subsequently erases CMOS RAM thus making disks etc. inaccessible. Permanent Damage: beyond consequences of lost access to devices (e.g. lost data), no permanent damage has been observed. Side Effects: ??? Damage Trigger......: Damage occurs when month=5 (May), each year Particularities.....: Virus was found in a publicly accessible PC at University of Tuebingen (South-West Germany). The "ha^s" (=hate) message adresses Professor Klaeren (University of Tuebingen). Remark: some antiviruses identify this virus as "Klaeren"; though this name is observed when the virus action is triggered, names of innocent victims should not be used. In- stead, the length-oriented name "982" is preferred as main name. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Countermeasures successful: Standard means......: Delete infected EXE&COM files, copy uninfected versions from original write-protected disk. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Klaus Brunnstein Documentation by....: Klaus Brunnstein Date................: 15-July-1991 Information source..: (original virus analysis) ===================== End of "982" Virus =============================