home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- THE YANKEE-2 VIRUS
- ===================
-
- Extract from Virus-L
-
- Date: 24 Jan 90 11:14:00 +0700
- From: Vesselin Bontchev
-
- In fact, I'm a bit guilty for the creation of this virus. At that
- good old time (about 18 months ago), there was only one virus in
- Bulgaria. This was the VHP-648 (Vienna) virus. Since it infects
- only .COM-files, I thought that infecting an .EXE-file is much more
- difficult. And I was fool enough to express my thought publicly.
- The challenge was taken immediately and the virus was created in
- less than a month.
-
- It infects .EXE-files only since the infection method for the .COM-
- ones was very well known and therefore was not interesting to bother
- with. Files of any length can be infected. However, if the program
- CodeView (a debugger which comes with the Microsoft programming
- languages) gets infected, it does not work any more. I cannot
- figure out the reason for this.
-
- The virus is not memory-resident. It activates only when an
- infected program is run. When activated, it searches the whole
- directory tree on the current drive for a still non-infected
- .EXE-file and infects it. (The directory tree is searched in a
- depth-first method. This means that first all the subdirectories
- are searched and then the current directory is searched.) On each
- run of an infected program one more .EXE-file of the file system
- gets infected. Then the virus plays the "Yankee Doodle" melody and
- starts the original program. It has no other effect.
-
- Please note, that this virus is not the one, known in the Western
- countries as the "Yankee Doodle virus". The later infects both
- .COM- and .EXE-files, is memory-resident, and plays the melody
- *only* at 5 pm. The Yankee virus is not memory-resident, infects
- only .EXE-files and plays the melody *every time* when an infected
- file is run.
-
- The infected files are recognized by the virus by the string
- "motherfucker" (excuse me) which appears at the very end of the
- file. Note that the string is in lower case only.
-
- The author of the virus did not spread the virus itself. In fact he
- did even worse --- he spread its source code. Now there is at least
- one mutation of the virus. It does not play the melody and is a
- little bit shorter. There were rumors about another mutation which
- is able to format the hard disk, but they are still not confirmed.
-
- This virus is not very widely spread in our country. The main
- reason should be that it infects only the files on the current drive
- - --- i.e. is not very "virulent".
-
- I wrote a program which can recognize the two known versions of the
- virus and is able to cure the infected files.
-
- Vesselin
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++