"Lisbon" Virus

 


             *********************************************

             ***   Reports collected and collated by   ***

             ***            PC-Virus Index             ***

             ***      with full acknowledgements       ***

             ***            to the authors             ***

             *********************************************


 

 

===== Computer Virus Catalog 1.2: "Lisbon Virus" (5-June-1989) ======


Entry...............: "Lisbon" Virus

Alias(es)...........: ---

Virus strain........: Vienna Virus strain

Virus detected when.: ---

              where.: ---

Classification......: Program virus (extending), direct action

Length of virus.....: 648 bytes


--------------------- Preconditions ----------------------------------


Operating system(s).: MS-DOS

Version/release.....: 2.0 and higher

Computer model(s)...: All MS-DOS machines


--------------------- Attributes -------------------------------------


Easy identification.: Last five bytes of file = "@AIDS" (Ascii)


Type of infection...: Self-Identification: The time stamp of an

                           infected file is changed: the seconds are

                           set to 62 (= 2 * 1Fh).

                           When infected file is executed, .COM-files

                           in the current directory as well as in the

                           directories in the DOS-PATH are extended by

                           appending the viral code; no infection if

                           the file size<10 or file size>64000 bytes.


Infection trigger...: A selected .COM-file is infected by "random" IF

                           (system seconds AND 58h) <> 0 ELSE damaged!


Storage media affected: Current media and media accessed via DOS-PATH.


Interrupts hooked...: --


Damage..............: A selected .COM-file is damaged permanently:

                           Overwriting the first five bytes by "@AIDS"


Damage trigger......: IF (system seconds AND 58h) = 0, ELSE infection!


Particularities.....: The virus ignores READ-ONLY and HIDDEN

                      attributes.


Similarities........: Dissimilarities to Vienna:

                           Different trigger byte (7);

                           the five damage bytes are changed.


--------------------- Agents -----------------------------------------


Countermeasures.....: Category 3: ANTI!LIS.EXE (d:) (/f)


Countermeasures successful: My Antivirus ANTI!LIS.EXE looks for

                           infected files on a given drive (d:) and

                           optionally removes the virus (if /f given).


Standard means......: ---


--------------------- Acknowledgement -------------------------------


Location............: Virus Test Center, University Hamburg, FRG

Classification by...: Daniel Loeffler

Documentation by....: Daniel Loeffler

Date................: June 5, 1990

Information Source..: ---



===================== End of "Lisbon"-Virus =========================

 


  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

  ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++

  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



Comments

Popular posts from this blog

WHAT THE WATCH TOWER BIBLE AND TRACT SOCIETY OF PENNSYLVANIA HAD TO SAY ABOUT WHAT WERE SUPPOSED TO HAVE HAPPENED in 1874

Uninterruptable Power Source (UPS) FAQ

Blade Runner FAQ