home *** CD-ROM | disk | FTP | other *** search
/ ProfitPress Mega CDROM2 …eeware (MSDOS)(1992)(Eng) / ProfitPress-MegaCDROM2.B6I / UTILITY / VIRUS / PCV4RPT.ZIP / SADDAM.RPT < prev    next >
Encoding:
Text File  |  1991-05-09  |  4.1 KB  |  78 lines

  1.  
  2.              *********************************************
  3.              ***   Reports collected and collated by   ***
  4.              ***            PC-Virus Index             ***
  5.              ***      with full acknowledgements       ***
  6.              ***            to the authors             ***
  7.              *********************************************
  8.  
  9.  
  10.  
  11. ===== Computer Virus Catalog 1.2: Sadam Virus (14-February-1991) =====
  12. Entry...............: Sadam Virus
  13. Alias(es)...........: =Saddam Virus
  14. Virus strain........: Stupid Virus Strain (?)
  15. Virus detected when.: 1-October-1989
  16.               where.: BBS in Israel
  17. Classifications.....: COM file infecting virus/extending, resident.
  18. Length of virus.....: 917-924 bytes, depending on size of name
  19.                           of infected file.
  20. Length of Virus.....: 919 bytes appendend (CBh+2CCh)
  21. --------------------- Preconditions ----------------------------------
  22. Operating system(s).: MS-DOS
  23. Version/release.....: 2.0 or higher
  24. Computer model(s)...: IBM PC,XT,AT and compatibles
  25. --------------------- Attributes -------------------------------------
  26. Identification......: Memory: INT 6Bh points to original INT 21h.
  27.                          (see Particularities [4])
  28.                       .COM files: The encryped message; to decrypt
  29.                          the string, add 6 to each char, the terminat-
  30.                          ing char is 24h before adding 6. The name of
  31.                          the infected file is stored with the virus.
  32.                          (name is stored at infection time; later
  33.                          renaming will not be recognized!)
  34. Type of infection...: System: The virus copies itself to high memory
  35.                          at the adress    [0:413]*40h-867h.
  36.                          The virus does not diminish the memory size
  37.                          by what is written in [0:413], nor will DOS
  38.                          regard that area as used; therefore, big
  39.                          programs may hang-up the system.
  40.                       .COM files: Extends .COM files; appends 919
  41.                          bytes to the end of the file.
  42.                       .EXE files: Not infected.
  43. Infection trigger...: Several file services of INT 21h
  44. Interrupts hooked...: INT 21h, INT 6Bh.
  45. Damage..............: Displays the message:
  46.                          "HEY SADAM"{LF}{CR}
  47.                          "LEAVE QUEIT BEFORE I COME" (wrong syntax)
  48. Damage trigger......: Counts the number of infections; on every 8th
  49.                          infection, the string will be displayed.
  50. Particularities.....: 1. Many programs load themself to this area and
  51.                          therefore erase the virus from memory.
  52.                       2. The virus uses INT 6BH replacement for the
  53.                          original INT 21H.
  54.                       3. The virus infects just files in the current
  55.                          directory.
  56.                       4. If the disk is write-protected, the message
  57.                          from DOS about write protection will be dis-
  58.                          played when the virus tries to spread.
  59.                       5. The virus will not be able to change files
  60.                          that have the Read-Only attribute set.
  61. --------------------- Agents -----------------------------------------
  62. Countermeasures.....: F-Prot 1.13 RESIDENT PART ONLY: identifies the
  63.                          virus as The Stupid Virus and does not let
  64.                          the program get into memory.
  65. --------------------- Acknowledgement --------------------------------
  66. Classification by...: Baruch Even (NYEVENBA@WEIZMANN.BITNET)
  67.                       Matthias Jaenichen, VTC-Hamburg
  68. Documentation by....: Matthias Jaenichen, VTC-Hamburg
  69. Date................: 5-October-1990
  70. Update..............: 14-February-1991
  71. Information Source..: ---
  72. ===================== End of Sadam - Virus ===========================
  73.  
  74.  
  75.   ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
  76.   ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
  77.   +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
  78.