home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- ======= Computer Virus Catalog 1.2: "XA1" Virus (20-July-1990) =======
- Entry................. "XA1" Virus
- Alias(e).............. V1539 Virus
- Strain................ ---
- Detected: when........ March 1990
- where....... West-Germany (Altena)
- Classification........ Program virus, direct action COM infector
- Length of virus....... 163 bytes added to COM files
- ----------------------- Preconditions --------------------------------
- Operating System(s)... MS-DOS
- Version/Release....... 2.0 and up
- Computer models....... Any IBM-compatibles
- ------------------------Attributes -----------------------------------
- Easy identification... The virus contains the following German string:
- "Und er lebt doch noch : Der Tannenbaum !",0Dh,
- 0Ah,00h, "Frohe Weihnachten ...",0Dh,0Ah,07h,
- 00h (translated in English: "And he lives: the
- Christmas tree", "Happy Christmas").
-
- Type of infection..... Direct action; prepending 1539 bytes to
- COM files.
- Infection trigger..... Executing an infected file will trigger the
- multiple infection attempts searching the
- PATH variable in the environment.
- Interrupts hooked..... INT 24
- Damage................ When an infected program is run between
- December 24th and 31st (any year), the virus
- will display a full screen image of a
- christmas tree and german seasons greetings.
-
- When an infected program is run on April 1st
- (any year), it drops a code into the boot-
- sectors of floppy A: and B: as well as into
- the partition table of the harddisk. The old
- partition sectors are saved but most likely
- destroyed since running another infected
- file will save the modified partition table
- to the same location. On any boot attempt
- from an infected harddisk or floppy, the
- text "April April" will be displayed and the
- PC will hang.
-
- Particularities....... The virus is self-encrypting and tries to fool
- debuggers. The decrypting routine is
- slightly modified upon each infection.
-
- ----------------------- Acknowledgement ------------------------------
-
- Location.............. Micro-BIT Virus Center RZ Universitaet
- Karlsruhe
-
- Classification by..... Christoph Fischer
- Dokumentation by ..... Christoph Fischer
- Date.................. 16-March-1990
-
- ====================== End of "XA1" Virus ============================
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++