"Form" Virus
*********************************************
*** Reports collected and collated by ***
*** PC-Virus Index ***
*** with full acknowledgements ***
*** to the authors ***
*********************************************
======= Computer Virus Catalog 1.2: "Form" Virus (5-June-1990) =======
Entry.................. "Form" Virus
Alias(es).............. ---
Strain................. ---
Detected: when......... February 1990
where........ Zuerich, Switzerland (reported to be very
widely spread amongst the Swiss schools in
canton Zug)
Classification......... Boot sector virus Length of Virus........
Exactly 03F9h bytes (approx. 2 sectors)
------------------------ Preconditions---------------------------------
Operating System(s).... MS-DOS
Version/Release........ Any
Computer models........ IBM-PS and compatibles
-------------------------- Attributes----------------------------------
Easy identification.... The boot sector will contain the following
text (amongst others): "The FORM-Virus sends
greetings to everyone who's read this text.".
(See also: Damage)
Type of infection...... Direct action: at boot time the virus will
attempt to infect the hard disk.
Indirect: At every read from a floppy,
an attempt will be made to infect it.
Infection trigger...... Every read any time.
Media affected......... Any floppy and the first active partition on
a harddisk.
Interrupts hooked...... Int 13 (disk) and Int 9 (keyboard) on every
24th of the month.
Damage................. The virus makes the keys click and delays key
action slightly.
Particularities........ Economically programed. It is a rare example
of both direct and indirect action in the same
virus.
Similarities........... ---
-------------------------- Agents------------------------------------
Countermeasures........
- ditto - successful.. Most checksumming programs that check the boot
sector.
Standard Means......... The text mentioned above will be found in a
cluster marked as bad. Disks can usually be
disinfected by booting from a write protected
clean boot disk, and using the SYS command on
any infected disk.
--------------------- Acknowledgements-------------------------------
Location............... Virus Test Center, University of Hamburg, FRG
Classification by...... Morton Swimmer
Documentation by....... Morton Swimmer
Date................... 5-June-1990
Information source..... Ralf Brown's interrupt list.
===================== End of "FORM" Virus ===========================
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comments
Post a Comment