home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- JERUSALEM precursors: SURIV 1, 2 & 3
- ====================================
-
- These are earlier versions of JERUSALEM and were once considered
- extinct. However versions were reported at large in the USSR, late
- 1990.
-
- SURIV 1 (897 bytes) Infects COM files only and displays
- message on 1st April, any year:
- 'APRIL 1ST HA HA HA YOU HAVE A VIRUS'
- and the machine locks.
- After 1st April 1988, the virus produces message:
- 'YOU HAVE A VIRUS!!!',
-
- SURIV 2 (1488 bytes) Infects EXE files only and displays
- similar effects on 1st April only.
- Machine also locks one hour after infection if
- the year is 1980 or if the date is 6th April 1988.
-
- SURIV 3 (1808 bytes) Infects both COM and EXE files and very
- similar to Jerusalem, the main difference being
- that the system slowdown occurs after 30 seconds,
- not 30 minutes.
-
- Detailed descriptions follow:
-
- === Computer Virus Catalog 1.2: "sURIV 1.01 Virus" (15-Feb-1990) =====
- Entry...............: "sURIV 1.01"
- Alias(es)...........:
- Virus Strain........: Jerusalem-Virus
- Virus detected when.:
- where.:
- Classification......: Link - Virus (extending), RAM - resident
- Length of Virus.....: .COM - Files: Program length increases
- by 897 bytes
- --------------------- Preconditions ----------------------------------
- Operating System(s).: MS-DOS
- Version/Release.....: 2.xx upward
- Computer model(s)...: IBM - PC, XT, AT and compatibles
- --------------------- Attributes -------------------------------------
- Easy Identification.: Typical text in Virus body (readable with
- HexDump-utilities): "sURIV 1.01"
-
- Type of infection...: System: RAM-resident.
- .COM file: extended by using EXEC-function. A
- file will not be infected more than once.
- 'COMMAND.COM' will not be infected.
- .EXE File: no infection.
- Infection Trigger...: When function 4B00H of INT 21H (EXEC) is called.
- Interrupts hooked...: INT 21H, INT 24H
-
- Damage..............: Permanent Damage: ---
- Transient Damage: The virus examines the current
- date. Every 1st April in a year greater
- than 1987, the virus will display the mes-
- sage "APRIL 1ST HA HA HA YOU HAVE A VIRUS"
- and the computer will hang in an endless
- loop. If day is greater than 1st April,
- only "YOU HAVE A VIRUS !!!" is displayed.
- Particularities.....: Programs longer than 64382 bytes are no longer
- loadable.
- --------------------- Agents -----------------------------------------
- Countermeasures.....:
- - ditto - successful:
- Standard means......:
- --------------------- Acknowledgement --------------------------------
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Thomas Lippke
- Documentation by....: Thomas Lippke
- Date................: February 20, 1990
-
- --------- more - Report on SURIV 2 follows ------------
-
-
- ====== Computer Virus Catalog 1.2: "SURIV 2.01" (5-June-1990) =======
- Entry...............: "SURIV 2.01"
- Alias(es)...........: "APRIL 1ST"
- Virus Strain........: Jerusalem-Virus
- Virus detected when.: ---
- where.: ---
- Classification......: Link - Virus (extending), RAM - resident
- Length of Virus.....: .EXE - Files: Program length increases
- by 1488 bytes
- ------------------- Preconditions -----------------------------------
- Operating System(s).: MS-DOS
- Version/Release.....: 2.xx upward
- Computer model(s)...: IBM - PC, XT, AT and compatibles
- ------------------- Attributes --------------------------------------
- Easy Identification.: Typical text in Virus body (readable with
- HexDump-utilities): "sURIV 2.01"
- Type of infection...: System: RAM-resident.
- .EXE file: extended by using EXEC-function;
- files will not be infected more than once.
- .COM File: no infection.
- Infection Trigger...: When function 4B00H of INT 21H (EXEC) is called.
- Interrupts hooked...: INT 1C, INT 21H, INT 24H
- Damage..............: Permanent Damage: --
- Transient Damage:
- The virus examines the current date. On every
- 1st April, the virus will display the message
- "APRIL 1ST HA HA HA YOU HAVE A VIRUS", and
- the computer will hang in an endless loop.
- In 1980 and on every Wednesday after 1. April
- 1988, the computer will hang at latest 55
- minutes after system infection in an endless
- loop.
- Particularities.....: One function (0DEH) used by Novell - Netware 4.0
- can't be used.
- -------------------- Agents ------------------------------------------
- Countermeasures.....: ---
- - ditto - successful: ---
- Standard means......: Notice .EXE file length.
- Typical text in virus body: "sURIV 2.01"
- -------------------- Acknowledgement ---------------------------------
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Thomas Lippke
- Documentation by....: Thomas Lippke
- Date................: 5-June-1990
-
- ------- more report on SURIV 3 follows ---------
-
- === Computer Virus Catalog 1.2: "Suriv 3.00" Virus (5-June-1990) =====
- Entry...............: Suriv 3.00
- Alias(es)...........: Jerusalem (B) = Israeli #3 Virus
- Virus Strain........: Israeli-Virus
- Classification......: Program Virus (extending), RAM-resident
- Length of Virus.....: .COM files: length increases by 1813 bytes.
- .EXE files: length increases by 1808-1823 bytes.
- (.EXE file length must be a multiple
- of 16 bytes, as in any .EXE file)
-
- ------------------ Preconditions -----------------------------------
- Operating System(s).: MS-DOS,PC-DOS
- Version/Release.....: 2.xx upward
- Computer model(s)...: IBM-PC, XT, AT and compatibles
- ------------------- Attributes --------------------------------------
- Easy Identification.: Typical texts in Virus body (readable with
- HexDump facilities): "sURIV 3.00".
-
- Type of infection...: System: infected if function E0h of INT 21h
- returns value 0300h in the AX-register.
- .Com files: program length increases by 1813;
- files are infected only once;
- COMMAND.COM will not be infected.
-
- .EXE files: program length increases by 1808
- - 1823 bytes, and no identification is
- used; therefore, .EXE files can be
- infected more than once.
-
- Infection Trigger...: Programs are infected at load time (using the
- function Load/Execute of MS-DOS).
- Interrupts hooked...: INT21h, INT08h
- Damage..............: 1. 30 seconds after the 1st infected program
- was run, the virus scrolls up 2 Lines in a
- small window of the screen ( left corner 5,5;
- right corner 16,16).
-
- 2. The virus slows down the system by about 10
- %.
-
- Damage Trigger......: Every time when the system is infected.
- Particularities.....: 1. The version of the Suriv 3.00 which we have
- analyzed compares the system-date with
- "Friday 13th", but is not able to recognize
- "Friday 13th", because of a "bug"; if it cor-
- rectly recognized this date, it would delete
- any program started on "Friday 13th".
- 2. .EXE files can be infected many times.
- 3. Novell Netware 4.0 functions, esp. "Print
- Spooling" (INT21h/E0h), "Set Error Mode"
- (INT21h/DDh) and "Set Broadcast Mode"
- (INT21/DEh) cannott be used.
-
- --------------------- Agents -----------------------------------------
-
- Countermeasures.....: The virus will be detected by :
- VIRSUCH 2.15 (D. Hoppenrath) as Israeli #3
- F-FCHK 1.08 (F. Skulason) as
- Israeli/Jerusalem
-
- SCAN 3.1 (McAfee) as Jerusalem Ver.
- B FINDVIRU 6.04 (Solomon) as Suriv 3
- Several Antiviruses do not work safely.
-
- -------------------- Acknowledgement ---------------------------------
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Jrg Steindecker
- Documentation by....: Jrg Steindecker, Joe Hirst (BCVRC)
- Date................: 5-June-1990
- Updates by..........: ---
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++