home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- ===== Computer Virus Catalog 1.2: "Flash" Virus (20-July-1990) =======
- Entry................. "Flash" Virus
- Alias(e).............. "688" Virus
- Strain................ ---
- Detected: when........ ---
- where....... ---
- Classification........ Program virus, resident virus
- Length of virus....... 688 bytes added to infected files
-
- --------------------- Preconditions ----------------------------------
-
- Operating System(s)... MS-DOS
- Version/Release....... 2.0 and up
- Computer models....... Any IBM-compatibles
-
- ------------------------Attributes -----------------------
- Easy identification... ---
-
- Type of infection..... The virus makes itself resident and intercepts
- INT 21 upon subfunction 4Bh (load+execute);
- the virus TSR tries to infect the loaded
- file by appending itself to it. If the file
- to be loaded has an extension starting with
- "E", the virus assumes it to be an EXE file.
-
- Infection trigger..... Loading of a file triggers infection mechanism.
-
- Interrupts hooked..... INT 21, INT 24 (during infection);
- INT08 (only upon payload trigger).
-
- Damage................ Starting with June 1990, the virus hooks INT
- 08, and after a random time it starts to
- flash the screen image every 7 minutes (5
- rapid on/off cycles). This effect is
- visible on MDA, Hercules, and CGA adapters,
- but *not* on EGA and VGA cards!
-
- Particularities....... The virus tries to fool debuggers when tracing
- by self modifying code that executes differ-
- ently due to the instruction prefetch queue-
- ing of 80x86 processors.
-
- The detection of write protected floppies uses
- a novel technique: a writeprotected floppy
- in drive A: will disable the infection
- mechanism of the resident copy of the virus.
-
- ----------------------- Acknowledgement ------------------------------
- Location.............. Micro-BIT Virus Center RZ Universitaet
- Karlsruhe
-
- Classification by..... Christoph Fischer
- Dokumentation by ..... Christoph Fischer
- Date.................. 3-July-1990
-
-
- ====================== End of "Flash" Virus ==========================
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++