home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
- ====== Computer Virus Catalog 1.2: Lehigh Virus (15-Feb-1990) ========
-
- Entry...............: Lehigh Virus
- Alias(es)...........: ---
- Virus strain........: ---
- Virus detected when.: November 1987
- where.: Lehigh University (Bethlehem/USA)
- Classification......: System virus (COMMAND.COM), RAM-resident
- Length of virus.....: 555 bytes
-
- --------------------- Preconditions ----------------------------------
-
- Operating system(s).: MS-DOS
- Version/release.....: 2.0 and higher
- Computer model(s)...: All MS-DOS machines
-
- --------------------- Attributes -------------------------------------
-
- Easy identification.: Last two bytes of COMMAND.COM = A9h 65h,
- COMMAND.COM grows by 555 bytes.
-
- Type of infection...: COMMAND.COM only (stack space at end of file
- overwritten); RAM resident (no check if
- RAM infected before).
-
- Infection trigger...: Uninfected COMMAND.COM in the root directory of
- used or current drive (checked by INT 21h)
-
- Storage media affected: Any COMMAND.COM on hard disk or diskette.
-
- Interrupts hooked...: INT 21h: Ah = 4Bh(load) and Ah = 4E(find file)
- INT 44H: Set as old INT 21h
-
- Damage..............: If A: or B: selected (if it is not the current
- drive), then sector 1 to 32 are overwritten
- with garbage read from BIOS and print-text
- (also from BIOS).
-
- Damage trigger......: Infection counter = 4
-
- Particularities.....: Not hardware-dependent: INT 21h, 26h used only
-
- Similarities........: ---
-
- --------------------- Agents -----------------------------------------
-
- Countermeasures.....: ---
-
- Countermeasures successful: Several antiviruses (McAfee, Solomon,
- Skulason et.al.) successfully detect and
- eradicate this virus.
-
- Standard means......: ---
-
- --------------------- Acknowledgement --------------------------------
-
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Daniel Loeffler (disassembly by Joe Hirst)
- Documentation by....: Daniel Loeffler
- Date................: December 18, 1989
- Information Source..: ---
-
-
- ========================= End of "Lehigh"-Virus ======================
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++