home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
- ==== Computer Virus Catalog 1.2: Merritt Virus (June 5, 1989) =======
-
- Entry...............: Merritt
- Alias(es)...........: =Yale =Alameda (A) -Virus
- Virus Strain........: Merritt/Alameda-Strain
- Virus detected when.: November 24, 1988
- where: University of New Brunswick, Fredericton, CANADA
- First detection: Merritt College, California,
- 1987
-
- Classification......: System Virus (= BootSector-Virus)
- Length of Virus.....: 512 Bytes
-
-
- ------------------- Preconditions -----------------------------------
-
- Operating System(s).: MS-DOS
- Version/Release.....:
- Computer Models.....: IBM PCs and Compatibles (not ATs=80286).
-
- -------------------- Typical Attributes ------------------------------
-
- Easy Identification.: No characteristic text (in code, Vol-labels
- etc).
-
- Type of infection...: Boots when infected disk is inserted and system
- is booted. Installs itself in high memory,
- removes that memory from DOS. Installs itself
- as the Warm-start (CTRL+ALT+DEL) interrupt
- handler (actually the keyboard handler); spreads
- by CTRL+ALT+DEL interrupt handler. Moves "real"
- boot sector to track 39, sector 8. Does not
- infect .COM or .EXE files.
-
- Damage..............: Permanent Damage: moves boot block to track 39,
- sector 8 (if there was a file, it is corrupted).
- This sector is not marked as bad, so a file may
- overwrite the real boot block so that the disk
- may become "NOT bootable". It will count to 39
- and Blast the FAT (`0'). It counts a certain
- key stroke (there is also code for decrementing
- the count by another keystroke).
-
- Particularities.....: Hangs-up 80286-systems.
-
- Similarities........: With other members of Merritt/Alameda-strain.
-
- ------------------- Agents -----------------------------------------
-
- Tested vaccines.....: Michael MacDonalds own vaccine, which identifies
- virus and overwrites the boot block.
-
- Vaccines successful.: Michael MacDonald's own vaccine.
-
- Standard means......: Compare boot sector of infected disk with a
- "real" system disk. If different: check track
- 39, sector 8; if this contains the real boot
- block, execute a SYS command to reinstall real
- boot block and system files.
-
- -------------------- Classification ---------------------------------
-
- Location............: School of Computer Science,
- University of New Brunswick
- Classification by...: Michael J. MacDonald
- Documentation by....: Michael J. MacDonald, Software Specialist
- University of New Brunswick, P.O.Box 4400
- Fredericton, New Brunswick, CANADA E3B 5A3
- BITNET: MIKEMAC@UNB.CA
- Date of Entry.......: June 5, 1989
- Information Source..: ---
-
- ==================== End of Merritt Virus ===========================
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++