home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- Vesselin Bontchev reported in May 1990:
-
- The Toothless virus (V534) - Listed as: W13-534
- ===============================================
-
- This virus came from the Soviet Union and is probably created there.
- I have a Russian program against it. In the accompanying
- documentation the virus is called "a version of the 648 (Vienna)
- virus, made by a clumsy programmer". This definition is quite exact.
- The virus is really very similar to the Vienna one, with some parts
- of code removed and other slightly changed. It is a non-resident
- virus. It infects only .COM files in the current and in the root
- directory. The directories, listed in the PATH variable are *not*
- searched - the code for finding this variable in the environment is
- entirely removed. The destructive function is also removed. The
- infected files are marked not with a 62 seconds mark in their time
- of last update. Instead, a month equal to 13 in the date of last
- update is used. This is rather boring, since it can be easily seen
- (by obtaining a directory listing) and some programs (e.g., Norton
- Utilities) treat such things as "not a proper directory entry". The
- virus increases the length of the infected files by 534 bytes. Only
- files with length between 256 and 64000 bytes are attacked (the
- first of these numbers was 10 in the Vienna virus). The virus is
- not very virulent - I have only one report about it. The man who
- reported it brought me an infected COMMAND.COM and said that its
- length had changed once a bit - "about 500 bytes" - and the month in
- the file date has changed to 13. When I was able to confirm that
- this is indeed a new virus, I checked all his files, but found
- nothing more than that infected COMMAND.COM.
-
- If the virus infects a file with the ReadOnly attribute set, this
- attribute is cleared after the infection. This is due to a bug in
- the virus code.
-
- The virus is assembled with a strange assembler (A86?). Its
- disassembly listing cannot be assembled back with MASM or TASM to
- produce exactly the same code.
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++