home *** CD-ROM | disk | FTP | other *** search
-
- Name : Infiltrator
-
- Aliases : Klein virus
-
- Type/Size : Link/1052 bytes
-
- Incidence : Used to infiltrate a BBS?
-
- Discovered : By mr Peter Klein, Denmark 20-06-92
-
- Way to infect: When you are executing a infected program
-
- Rating : Dangerous
-
- Kickstarts : 2.04 - ?
-
- Damage : Links to other programs.
-
- Manifestation: Decoded you can read: This is the Infiltrator!
-
- Removal : Delete the infected program or link part
-
- Comments : Infected files are increased by 1052 bytes. This link
- virus have been very fast spreaden in Sweden and
- Denmark. I have got report by at least 6 infected
- harddisks within 2 days 20-06-92. The origin virus
- is spreaden by a fake DiskMaster 2.0+ (DM2.0+lha).
-
-
- The Infiltrator virus patches the 2.0 DOS LoadSeg
- vector and infects any files loaded by this routine;
- fonts, libraries and executables. Infected fonts or
- libraries can't be opened. The Infiltrator link virus
- cann't patch the 1.3 LoadSeg.
-
-
- The Infiltrator virus also scans for a file called
- 'user.data' and upon finding it performs some
- (presumably) horrid action, watch out for this file
- on your harddisk or bulletin board and tries to
- infect: libs, devices and so on
-
- NOTE. The virus is able to link the same file
- additional times too!!! by the consequence: NOT ALL
- infected files are able to run !!!
-
-
-
- The virus does not survive a reset, so it's not very
- dangerous to floppy users, but it is also very hard
- to detect for for example Action Replay, though you
- will get a report a suspicious LoadSeg vector
- (dos.library offset -150).
-
-
- ELS 11.93