The Dark Avenger virus

 


             *********************************************

             ***   Reports collected and collated by   ***

             ***            PC-Virus Index             ***

             ***      with full acknowledgements       ***

             ***            to the authors             ***

             *********************************************


  Vesselin Bontchev reported in May 1990:


  The Dark Avenger virus.

  ======================


  - I found two new mutations of this virus. Well, maybe "mutations"

  is not the correct word. In the first of them, the first 16

  characters of the string "Eddie lives...  somewhere in time!"  were

  replaced with blanks.


  In the second example, all strings (the message above, the copyright

  message and the "Diana P."  string) were replaced with blanks.  -

  The author of the Dark Avenger virus (The bastard!  I still cannot

  determine who he is.) has released the source code of his virus.


  It is full with ironic comments about me.  Of course, now we have to

  expect lots of new, similar viruses to appear.  At least, this

  leaded to one good thing - the source helped me very much in

  disassembling the V2000 virus.  - I received a rather offensive

  anonymous letter from this person.  In it he claims to be also the

  author of both the V2000 (I trust this) and the Number of the Beast

  viruses (the latter is unlikely).



=== Computer Virus Catalog 1.2: "Dark Avenger" Virus (15-Feb-1990) ===

Entry...............: Dark Avenger

Alias(es)...........: ---

Virus Strain........: Dark Avenger

Virus detected when.: November 1989

              where.: USA

Classification......: February 1990

Length of Virus.....: about 1800 Bytes

-------------------- Preconditions -----------------------------------

Operating System(s).: DOS

Version/Release.....:

Computer model(s)...: IBM-compatible

-------------------- Attributes --------------------------------------

Easy Identification.: Two Texts:

                      "Eddie lives...somewhere in time" at beginning

                      and

                      "This Program was written in the City of Sofia

                      (C) 1988-89 Dark Avenger" near end of file


Type of infection...: Link-virus

                      COM-files: appends to the program and installs a

                                 short jump

                      EXE-files: appends to the program at the

                                 beginning of the next paragraph


Infection Trigger...: COM and EXE files are corrupted on any read

                      attempt even when VIEWING!!!


Storage media affected: Any Drive


Interrupts hooked...: Int 21 DOS-services

                      Int 27 Terminate and Stay Resident


Damage..............: Overwrites a random sector with bootblock


Damage Trigger......: each 16th infection; counter located in

                      Bootblock


Particularities.....: -


Similarities........: -


-------------------- Agents ------------------------------------------


Countermeasures.....: NONE! All data can be destroyed !!!!

                      There is no way in retrieving lost data.

                      Backups will most probably be destroyed too.


Countermeasures successful: install McAfee's SCANRES.


Standard means......: Good luck! Hopefully the virus did not destroy

                      too many of your programs and data.


-------------------- Acknowledgement ---------------------------------


Location............: VTC Uni Hamburg

Classification by...: Matthias Jaenichen

Documentation by....: Matthias Jaenichen

Date................: 31.01.1990

Information Source..: ---



===================== End of "Dark Avenger" Virus ====================


  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

  ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++

  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



Comments

Popular posts from this blog

BOTTOM LIVE script

Fawlty Towers script for "A Touch of Class"