home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- ==== Computer Virus Catalog 1.2: Keypress Virus (10-February-1991) ===
- Entry...............: Keypress Virus
- Alias(es)...........: ---
- Virus Strain........: ---
- Virus detected when.: January 1991 (when VTC received virus copy)
- where.: Frankfurt (in an international hotel)
- Classification......: Program virus (extending), RAM-resident
- Length of Virus.....: .COM-file length increased by 1232-1247 bytes;
- .EXE-file length increased by 1472-1487 bytes.
- --------------------- Preconditions ----------------------------------
- Operating System(s).: MS-DOS
- Version/Release.....: 2.xx upward
- Computer model(s)...: IBM - PC, XT, AT and compatibles
- --------------------- Attributes -------------------------------------
- Easy Identification.: Typical text in virus body (readable with
- HexDump-utilities): ".COM",00h,".EXE",00h
- Type of infection...: System: RAM-resident, infected if the word
- 0001h is found at position 0000h:0600h.
- .COM - Files: if DOS version>=3.00 then ex-
- tended by using EXEC-function else ex-
- tended by using open file function and no
- system file infection. Only files with length
- from 1217 to 64064 bytes can be infected;
- files may only be infected once.
- .EXE - Files: if DOS version>=3.00 then extended
- by using EXEC-function else extended by using
- open file function and no system file infec-
- tion; files may only be infected once.
- Infection Trigger...: When function 4B00h (EXEC), or function 3D0x
- (open file) of INT 21h is called.
- Interrupts hooked...: INT 21h and INT 1Ch always; INT 23h and INT 24h
- during infection.
- Damage..............: Transient damage: every 10 minutes, the virus
- will look at INT 09h (keyboard interrupt) for
- 2 seconds; if a keystroke is recognized
- during this time, it will be repeated depend-
- ing on how long the key is pressed; it thus
- appears as a "bouncing key".
- Permanent damage: ---
- Particularities.....: Date and time of last file modification is set
- to the current date.
- .COM files longer than 64032 bytes are no longer
- loadable.
- --------------------- Agents -----------------------------------------
- Countermeasures.....: ---
- - ditto - successful: ---
- Standard means......: Notice file length.
- Notice date and time of last file modification.
- --------------------- Acknowledgement --------------------------------
- Location............: Virus Test Center, University Hamburg, Germany
- Classification by...: Thomas Lippke
- Documentation by....: Thomas Lippke
- Date................: 10-February-1991
-
- ===================== End of Keypress-Virus ==========================
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
-