The Toothless virus
*********************************************
*** Reports collected and collated by ***
*** PC-Virus Index ***
*** with full acknowledgements ***
*** to the authors ***
*********************************************
Vesselin Bontchev reported in May 1990:
The Toothless virus (V534) - Listed as: W13-534
===============================================
This virus came from the Soviet Union and is probably created there.
I have a Russian program against it. In the accompanying
documentation the virus is called "a version of the 648 (Vienna)
virus, made by a clumsy programmer". This definition is quite exact.
The virus is really very similar to the Vienna one, with some parts
of code removed and other slightly changed. It is a non-resident
virus. It infects only .COM files in the current and in the root
directory. The directories, listed in the PATH variable are *not*
searched - the code for finding this variable in the environment is
entirely removed. The destructive function is also removed. The
infected files are marked not with a 62 seconds mark in their time
of last update. Instead, a month equal to 13 in the date of last
update is used. This is rather boring, since it can be easily seen
(by obtaining a directory listing) and some programs (e.g., Norton
Utilities) treat such things as "not a proper directory entry". The
virus increases the length of the infected files by 534 bytes. Only
files with length between 256 and 64000 bytes are attacked (the
first of these numbers was 10 in the Vienna virus). The virus is
not very virulent - I have only one report about it. The man who
reported it brought me an infected COMMAND.COM and said that its
length had changed once a bit - "about 500 bytes" - and the month in
the file date has changed to 13. When I was able to confirm that
this is indeed a new virus, I checked all his files, but found
nothing more than that infected COMMAND.COM.
If the virus infects a file with the ReadOnly attribute set, this
attribute is cleared after the infection. This is due to a bug in
the virus code.
The virus is assembled with a strange assembler (A86?). Its
disassembly listing cannot be assembled back with MASM or TASM to
produce exactly the same code.
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comments
Post a Comment