"Flash" Virus
*********************************************
*** Reports collected and collated by ***
*** PC-Virus Index ***
*** with full acknowledgements ***
*** to the authors ***
*********************************************
===== Computer Virus Catalog 1.2: "Flash" Virus (20-July-1990) =======
Entry................. "Flash" Virus
Alias(e).............. "688" Virus
Strain................ ---
Detected: when........ ---
where....... ---
Classification........ Program virus, resident virus
Length of virus....... 688 bytes added to infected files
--------------------- Preconditions ----------------------------------
Operating System(s)... MS-DOS
Version/Release....... 2.0 and up
Computer models....... Any IBM-compatibles
------------------------Attributes -----------------------
Easy identification... ---
Type of infection..... The virus makes itself resident and intercepts
INT 21 upon subfunction 4Bh (load+execute);
the virus TSR tries to infect the loaded
file by appending itself to it. If the file
to be loaded has an extension starting with
"E", the virus assumes it to be an EXE file.
Infection trigger..... Loading of a file triggers infection mechanism.
Interrupts hooked..... INT 21, INT 24 (during infection);
INT08 (only upon payload trigger).
Damage................ Starting with June 1990, the virus hooks INT
08, and after a random time it starts to
flash the screen image every 7 minutes (5
rapid on/off cycles). This effect is
visible on MDA, Hercules, and CGA adapters,
but *not* on EGA and VGA cards!
Particularities....... The virus tries to fool debuggers when tracing
by self modifying code that executes differ-
ently due to the instruction prefetch queue-
ing of 80x86 processors.
The detection of write protected floppies uses
a novel technique: a writeprotected floppy
in drive A: will disable the infection
mechanism of the resident copy of the virus.
----------------------- Acknowledgement ------------------------------
Location.............. Micro-BIT Virus Center RZ Universitaet
Karlsruhe
Classification by..... Christoph Fischer
Dokumentation by ..... Christoph Fischer
Date.................. 3-July-1990
====================== End of "Flash" Virus ==========================
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comments
Post a Comment