home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- STONED aka NEW ZEALAND, also KOREA
- ==================================
-
- This virus was written late 1987 in Wellington, New Zealand. The
- author, who has been identified, was then a high-school student who
- later went to university. It seems that another individual was
- responsible for spreading the virus.
-
- There were two similar versions of the original virus the difference
- being where the original Boot Sector is stored. One version is
- described in detail below, the second one uses the following
- address:
- * at Track Zero, Head One, Sector Three on a floppy disk and
- * at Track Zero, Head Zero, Sector Two on a Hard Disk.
-
- There are now very variants ranging from simple character for
- character substitutions (to change the message); minor 'hacks' to
- evade a particular detection program to major rewrites.
-
- || The displaced boot sector is now relocated to a variety of
- || sectors on the hard disk thus complicating disinfection, even
- || though positive identification has apparently been made.
-
-
- ===== Computer Virus Catalog 1.2: Marijuana Virus (15-Feb-1990) ===
-
-
- Entry...............: Marijuana Virus
- Alias(es)...........: Stoned Virus, New Zealand Virus
- Classification......: System Virus (= Bootsector virus)
-
- Length of Virus.....: 440 bytes (occupies one sector on storage
- medium) 2 kbyte in RAM
-
- --------------------Preconditions -----------------------------------
- Operating System(s).: MS-DOS,
- Version/Release.....: 2.xx and upward
- Computer model(s)...: IBM-PC/XT/AT
-
- ------------------- Attributes --------------------------------------
-
- Easy Identification.: 'Your PC is now Stoned!.....LEGALISE MARIJUANA!'
- in the bootsector at offset 18Ah
-
- Type of infection...: Self-identification: The virus regards a disk as
- infected if the bootsector starts with
- EA 05 00 C0. The virus installs itself 2 kbyte
- below the end of available memory, removes that
- space from DOS, and infects the first hard disk
- when booting from an infected floppy disk. It
- captures all read and write calls to drive A:,
- checks for infection and if not present, infects
- the disk. Infection occurs by transferring the
- original bootsector on a floppy drive to head 1,
- track 0, sector 3 or on a hard disk to head 0,
- track 0, sector 7, and the original bootsector
- is replaced with the virus bootsector. When the
- virus installs itself from a floppy drive and
- the last three bits of the system clock counter
- are all zero, the PC beeps and the message 'Your
- PC is now Stoned!' is printed on the screen.
-
- Infection Trigger...: Infection of drive A: disks at any activity
- that invokes an int 13h read or write call
- (e.g. DIR, TYPE)
- Infection of the hard disk: when booting from an
- infected floppy disk.
-
- Storage media affected: Infects only disks in drive A: (media type
- doesn't matter) and the first hard disk
-
- Interrupts hooked...: Int 13h functions 2, 3 (read, write)
-
- Damage..............: Indirect damage through infection:
- 1. Floppy disks: The overwritten sector is
- usually a part of the root directory, so
- directory entries may be destroyed.
- 2. Hard disk: Overwrites sector 7. Usually this
- sector is not used, but in some non-standard
- cases the hard disk may become inaccessible.
-
- Damage Trigger......: Infection, booting
-
- Particularities.....: Normal formating will not remove the virus from
- an infected hard disk
-
- ------------------- Agents ------------------------------------------
-
- Countermeasures.....: Category 3: ANTIMARI.COM (VTC Hamburg)
-
- Countermeasures successful: ANTIMARI.COM deactivates the resident
- Marijuana-Virus in RAM and restores the
- bootsector to its correct place
-
- ------------------- Acknowledgement ---------------------------------
-
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Rainer Anscheit
- Documentation by....: Rainer Anscheit
- Date................: Jan. 14, 1990
-
-
- =================== End of Marijuana-Virus ==========================
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++