"Lisbon" Virus
*********************************************
*** Reports collected and collated by ***
*** PC-Virus Index ***
*** with full acknowledgements ***
*** to the authors ***
*********************************************
===== Computer Virus Catalog 1.2: "Lisbon Virus" (5-June-1989) ======
Entry...............: "Lisbon" Virus
Alias(es)...........: ---
Virus strain........: Vienna Virus strain
Virus detected when.: ---
where.: ---
Classification......: Program virus (extending), direct action
Length of virus.....: 648 bytes
--------------------- Preconditions ----------------------------------
Operating system(s).: MS-DOS
Version/release.....: 2.0 and higher
Computer model(s)...: All MS-DOS machines
--------------------- Attributes -------------------------------------
Easy identification.: Last five bytes of file = "@AIDS" (Ascii)
Type of infection...: Self-Identification: The time stamp of an
infected file is changed: the seconds are
set to 62 (= 2 * 1Fh).
When infected file is executed, .COM-files
in the current directory as well as in the
directories in the DOS-PATH are extended by
appending the viral code; no infection if
the file size<10 or file size>64000 bytes.
Infection trigger...: A selected .COM-file is infected by "random" IF
(system seconds AND 58h) <> 0 ELSE damaged!
Storage media affected: Current media and media accessed via DOS-PATH.
Interrupts hooked...: --
Damage..............: A selected .COM-file is damaged permanently:
Overwriting the first five bytes by "@AIDS"
Damage trigger......: IF (system seconds AND 58h) = 0, ELSE infection!
Particularities.....: The virus ignores READ-ONLY and HIDDEN
attributes.
Similarities........: Dissimilarities to Vienna:
Different trigger byte (7);
the five damage bytes are changed.
--------------------- Agents -----------------------------------------
Countermeasures.....: Category 3: ANTI!LIS.EXE (d:) (/f)
Countermeasures successful: My Antivirus ANTI!LIS.EXE looks for
infected files on a given drive (d:) and
optionally removes the virus (if /f given).
Standard means......: ---
--------------------- Acknowledgement -------------------------------
Location............: Virus Test Center, University Hamburg, FRG
Classification by...: Daniel Loeffler
Documentation by....: Daniel Loeffler
Date................: June 5, 1990
Information Source..: ---
===================== End of "Lisbon"-Virus =========================
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comments
Post a Comment