The Dark Avenger virus
*********************************************
*** Reports collected and collated by ***
*** PC-Virus Index ***
*** with full acknowledgements ***
*** to the authors ***
*********************************************
Vesselin Bontchev reported in May 1990:
The Dark Avenger virus.
======================
- I found two new mutations of this virus. Well, maybe "mutations"
is not the correct word. In the first of them, the first 16
characters of the string "Eddie lives... somewhere in time!" were
replaced with blanks.
In the second example, all strings (the message above, the copyright
message and the "Diana P." string) were replaced with blanks. -
The author of the Dark Avenger virus (The bastard! I still cannot
determine who he is.) has released the source code of his virus.
It is full with ironic comments about me. Of course, now we have to
expect lots of new, similar viruses to appear. At least, this
leaded to one good thing - the source helped me very much in
disassembling the V2000 virus. - I received a rather offensive
anonymous letter from this person. In it he claims to be also the
author of both the V2000 (I trust this) and the Number of the Beast
viruses (the latter is unlikely).
=== Computer Virus Catalog 1.2: "Dark Avenger" Virus (15-Feb-1990) ===
Entry...............: Dark Avenger
Alias(es)...........: ---
Virus Strain........: Dark Avenger
Virus detected when.: November 1989
where.: USA
Classification......: February 1990
Length of Virus.....: about 1800 Bytes
-------------------- Preconditions -----------------------------------
Operating System(s).: DOS
Version/Release.....:
Computer model(s)...: IBM-compatible
-------------------- Attributes --------------------------------------
Easy Identification.: Two Texts:
"Eddie lives...somewhere in time" at beginning
and
"This Program was written in the City of Sofia
(C) 1988-89 Dark Avenger" near end of file
Type of infection...: Link-virus
COM-files: appends to the program and installs a
short jump
EXE-files: appends to the program at the
beginning of the next paragraph
Infection Trigger...: COM and EXE files are corrupted on any read
attempt even when VIEWING!!!
Storage media affected: Any Drive
Interrupts hooked...: Int 21 DOS-services
Int 27 Terminate and Stay Resident
Damage..............: Overwrites a random sector with bootblock
Damage Trigger......: each 16th infection; counter located in
Bootblock
Particularities.....: -
Similarities........: -
-------------------- Agents ------------------------------------------
Countermeasures.....: NONE! All data can be destroyed !!!!
There is no way in retrieving lost data.
Backups will most probably be destroyed too.
Countermeasures successful: install McAfee's SCANRES.
Standard means......: Good luck! Hopefully the virus did not destroy
too many of your programs and data.
-------------------- Acknowledgement ---------------------------------
Location............: VTC Uni Hamburg
Classification by...: Matthias Jaenichen
Documentation by....: Matthias Jaenichen
Date................: 31.01.1990
Information Source..: ---
===================== End of "Dark Avenger" Virus ====================
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comments
Post a Comment