"Lisbon" Virus

 


             *********************************************

             ***   Reports collected and collated by   ***

             ***            PC-Virus Index             ***

             ***      with full acknowledgements       ***

             ***            to the authors             ***

             *********************************************


 

 

===== Computer Virus Catalog 1.2: "Lisbon Virus" (5-June-1989) ======


Entry...............: "Lisbon" Virus

Alias(es)...........: ---

Virus strain........: Vienna Virus strain

Virus detected when.: ---

              where.: ---

Classification......: Program virus (extending), direct action

Length of virus.....: 648 bytes


--------------------- Preconditions ----------------------------------


Operating system(s).: MS-DOS

Version/release.....: 2.0 and higher

Computer model(s)...: All MS-DOS machines


--------------------- Attributes -------------------------------------


Easy identification.: Last five bytes of file = "@AIDS" (Ascii)


Type of infection...: Self-Identification: The time stamp of an

                           infected file is changed: the seconds are

                           set to 62 (= 2 * 1Fh).

                           When infected file is executed, .COM-files

                           in the current directory as well as in the

                           directories in the DOS-PATH are extended by

                           appending the viral code; no infection if

                           the file size<10 or file size>64000 bytes.


Infection trigger...: A selected .COM-file is infected by "random" IF

                           (system seconds AND 58h) <> 0 ELSE damaged!


Storage media affected: Current media and media accessed via DOS-PATH.


Interrupts hooked...: --


Damage..............: A selected .COM-file is damaged permanently:

                           Overwriting the first five bytes by "@AIDS"


Damage trigger......: IF (system seconds AND 58h) = 0, ELSE infection!


Particularities.....: The virus ignores READ-ONLY and HIDDEN

                      attributes.


Similarities........: Dissimilarities to Vienna:

                           Different trigger byte (7);

                           the five damage bytes are changed.


--------------------- Agents -----------------------------------------


Countermeasures.....: Category 3: ANTI!LIS.EXE (d:) (/f)


Countermeasures successful: My Antivirus ANTI!LIS.EXE looks for

                           infected files on a given drive (d:) and

                           optionally removes the virus (if /f given).


Standard means......: ---


--------------------- Acknowledgement -------------------------------


Location............: Virus Test Center, University Hamburg, FRG

Classification by...: Daniel Loeffler

Documentation by....: Daniel Loeffler

Date................: June 5, 1990

Information Source..: ---



===================== End of "Lisbon"-Virus =========================

 


  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

  ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++

  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



Comments

Popular posts from this blog

BOTTOM LIVE script

Fawlty Towers script for "A Touch of Class"