"Flash" Virus

 


             *********************************************

             ***   Reports collected and collated by   ***

             ***            PC-Virus Index             ***

             ***      with full acknowledgements       ***

             ***            to the authors             ***

             *********************************************



===== Computer Virus Catalog 1.2: "Flash" Virus (20-July-1990) =======

Entry................. "Flash" Virus

Alias(e).............. "688" Virus

Strain................ ---

Detected: when........ ---

          where....... ---

Classification........ Program virus, resident virus

Length of virus....... 688 bytes added to infected files


--------------------- Preconditions ----------------------------------


Operating System(s)... MS-DOS

Version/Release....... 2.0 and up

Computer models....... Any IBM-compatibles


------------------------Attributes -----------------------

Easy identification...  ---


Type of infection..... The virus makes itself resident and intercepts

                          INT 21 upon subfunction 4Bh (load+execute);

                          the virus TSR tries to infect the loaded

                          file by appending itself to it. If the file

                          to be loaded has an extension starting with

                          "E", the virus assumes it to be an EXE file.


Infection trigger..... Loading of a file triggers infection mechanism.


Interrupts hooked..... INT 21, INT 24 (during infection);

                          INT08 (only upon payload trigger).


Damage................ Starting with June 1990, the virus hooks INT

                          08, and after a random time it starts to

                          flash the screen image every 7 minutes (5

                          rapid on/off cycles).  This effect is

                          visible on MDA, Hercules, and CGA adapters,

                          but *not* on EGA and VGA cards!


Particularities....... The virus tries to fool debuggers when tracing

                          by self modifying code that executes differ-

                          ently due to the instruction prefetch queue-

                          ing of 80x86 processors.


                       The detection of write protected floppies uses

                          a novel technique: a writeprotected floppy

                          in drive A: will disable the infection

                          mechanism of the resident copy of the virus.


----------------------- Acknowledgement ------------------------------

Location.............. Micro-BIT Virus Center RZ Universitaet

                       Karlsruhe


Classification by..... Christoph Fischer

Dokumentation by ..... Christoph Fischer

Date.................. 3-July-1990



====================== End of "Flash" Virus ==========================


  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

  ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++

  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



Comments

Popular posts from this blog

WHAT THE WATCH TOWER BIBLE AND TRACT SOCIETY OF PENNSYLVANIA HAD TO SAY ABOUT WHAT WERE SUPPOSED TO HAVE HAPPENED in 1874

Uninterruptable Power Source (UPS) FAQ

Blade Runner FAQ