"Form" Virus

 


             *********************************************

             ***   Reports collected and collated by   ***

             ***            PC-Virus Index             ***

             ***      with full acknowledgements       ***

             ***            to the authors             ***

             *********************************************


 

======= Computer Virus Catalog 1.2: "Form" Virus (5-June-1990) =======


Entry.................. "Form" Virus

Alias(es).............. ---

Strain................. ---

Detected: when......... February 1990

          where........ Zuerich, Switzerland (reported to be very

                        widely spread amongst the Swiss schools in

                        canton Zug)


Classification.........  Boot sector virus Length of Virus........

                         Exactly 03F9h bytes (approx.  2 sectors)


------------------------ Preconditions---------------------------------


Operating System(s).... MS-DOS

Version/Release........ Any

Computer models........ IBM-PS and compatibles


-------------------------- Attributes----------------------------------


Easy identification.... The boot sector will contain the following

                        text (amongst others): "The FORM-Virus sends

                        greetings to everyone who's read this text.".

                        (See also:  Damage)


Type of infection...... Direct action: at boot time the virus will

                               attempt to infect the hard disk.

                               Indirect: At every read from a floppy,

                               an attempt will be made to infect it.


Infection trigger...... Every read any time.


Media affected......... Any floppy and the first active partition on

                        a harddisk.


Interrupts hooked...... Int 13 (disk) and Int 9 (keyboard) on every

                        24th of the month.


Damage................. The virus makes the keys click and delays key

                        action slightly.


Particularities........ Economically programed. It is a rare example

                        of both direct and indirect action in the same

                        virus.


Similarities........... ---


-------------------------- Agents------------------------------------


Countermeasures........


 - ditto - successful.. Most checksumming programs that check the boot

                        sector.


Standard Means......... The text mentioned above will be found in a

                        cluster marked as bad. Disks can usually be

                        disinfected by booting from a write protected

                        clean boot disk, and using the SYS command on

                        any infected disk.


--------------------- Acknowledgements-------------------------------


Location............... Virus Test Center, University of Hamburg, FRG

Classification by...... Morton Swimmer

Documentation by....... Morton Swimmer

Date................... 5-June-1990

Information source..... Ralf Brown's interrupt list.



===================== End of "FORM" Virus ===========================



  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

  ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++

  ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



Comments

Popular posts from this blog

BOTTOM LIVE script

Fawlty Towers script for "A Touch of Class"