home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- DATACRIME SERIES
- ================
-
- There are four versions of Datacrime:
-
- Version 1 - Infects only COM files (1168 bytes):
-
- The virus occurs attached to the end of a COM file. COM files
- increase in length by 1168 bytes. The first three bytes of the
- program are stored in the virus, and replaced by a branch to the
- beginning of the virus. The virus will search through full
- directory structure of the disks (in the order C, D, A, B) for a COM
- file other than COMMAND.COM
-
- It will also ignore any COM file if the 7th letter of the name is a
- D.
-
- If the date is after 12 October (any year) it will display the
- message: 'DATACRIME VIRUS' 'RELEASED: 1 MARCH 1989'
-
- and do a low level format on track zero, all heads, of the hard
- disk.
-
- The message is encrypted. There is an error in the way the format
- table is addressed, and there are several mistakes in the code
- involving the critical error handler.
-
-
- Version 2 - Infects: COM files only - (Length: 1280):
-
- Same as Version 1, except for the difference in length.
-
- Version 3 - Infects: COM and EXE files - (Length: 1480): (Also
- known as Datacrime II)
-
- This version is much the same as Version 1, but it will infect EXE
- files as well. The virus is encrypted except the first 42 bytes,
- and the message is separately encrypted. The message is now:
-
- 'DATACRIME II VIRUS'
-
- It will ignore any file if the 2nd letter of the name is a B. The
- addressing of the format table has been corrected.
-
-
- Version 4 - Infects: COM and EXE files - (Length: 1514) (Also known
- as Datacrime II)
-
- This version is much the same as Version 3. The virus is encrypted
- except the first 56 bytes, but the message is no longer separately
- encrypted. Code has been added to the encryption routine to prevent
- single-stepping. The message is now:
-
- '* DATACRIME II VIRUS *'
-
-
- ==== Computer Virus Catalog 1.2: DATACRIME Ib Virus (15-Feb-1990) ====
- Entry...............: DATACRIME Ib
- Alias(es)...........: DATACRIME 1280-Version = "1280" Virus
- Virus Strain........: DATACRIME
- Virus detected when.: ---
- where.: ---
- Classification......: Link-virus (extending), direct action
- Length of Virus.....: .COM file: filelength increases by 1280 byte
- --------------------- Preconditions ----------------------------------
- Operating System(s).: MS-DOS
- Version/Release.....: 2.xx upward
- Computer model(s)...: IBM-PC, XT, AT and compatibles
- --------------------- Attributes -------------------------------------
- Easy Identification.: ---
- Type of infection...: System: no infection.
- .COM file: Link-virus, increases COM files by
- 1280 Byte. A .COM- File is recognized as
- being infected if the time entry of the
- last program modification shows the fol-
- lowing particularities: the last signi-
- ficant three bytes of the minutes are the
- same as the seconds. Bit 4,5 of the
- seconds will be set to zero. For example:
- (H=Hours, M=Minutes, S=Seconds)
- H H H H H M M M M M M S S S S S
- ? ? ? ? ? ? ? ? 1 0 1 ? ? ? ? ?
- will be changed to
- H H H H H M M M M M M S S S S S
- ? ? ? ? ? ? ? ? 1 0 1 0 0 1 0 1
- .EXE file: no infection.
- Infection Trigger...: Every time the virus runs it looks for one other
- uninfected .COM- file using the DOS-func-
- tions Findfirst/Findnext in the current
- directory or any lower directory. If there
- is no file that can be infected the virus
- looks at the drive C: D: A: B: (in this
- order).
- Interrupts hooked...: Int 24 (only when infecting a file)
- Damage..............: Permanent Damage: the virus shows the message
- "DATACRIME VIRUS
- RELEASED: 1 MARCH 1989"
- then the first hard disk will be formatted
- (track 0, all heads). If formatting is
- finished the speaker will beep (endless
- loop).
- Damage Trigger......: if the Clock device is October the 13th or
- later (any year).
- Particularities.....: 1. The message "DATACRIME... 1989" is encrypted.
- 2. The virus detects a hard disk if the segment
- of INT 41 is not zero.
- 3. Cause of a mistake in the code the virus will
- not use it's format buffer.
- 4. Cause of a missing segment override the INT24
- can not be restored every time.
- 5. If the 7th letter of the program name is a
- 'D', the program will not be infected (e.g.
- COMMAND.COM).
-
- Similarities........: The differences between Datacrime Ia and Ib
- are minimal.
-
- --------------------- Agents -----------------------------------------
- Countermeasures.....: ---
- - ditto - successful: ---
- Standard means......: ---
-
- --------------------- Acknowledgement --------------------------------
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Michael Reinschmiedt
- Documentation by....: Michael Reinschmiedt
- Date................: 14-Feb-1990
-
-
- ===================== End of DATACRIME Virus ======================
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++