home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: riordan.cybec@tmx.mhs.oz.au (Roger Riordan)
- Newsgroups: comp.virus
- Subject: "LARRY ON A SCREEN" Virus (PC)
- Message-ID: <0003.9211101943.AA07075@barnabas.cert.org>
- Date: 4 Nov 92 08:22:50 GMT
- Sender: virus-l@lehigh.edu
- Lines: 38
- Approved: news@netnews.cc.lehigh.edu
-
- This virus was first reported (to our knowledge) by Brian Mariott,
- Dept of Computer Science, University of Tasmania, on Virus L, on 7th
- Oct. They received it from a computer shop, which had found it on a
- PC brought in by a customer. We received a sample on Oct 20th.
-
- It is a resident .COM & .EXE infector, adding 491 & 507 bytes
- respectively. Like Troi2, recently reported, it hides in the 2nd half
- of the interrupt table, overwriting interrupts 80 to FF, and, like
- Troi 2, it frequently crashed in our tests, again presumably because
- it overloads the system stack. It has one most unusual bug; it gives
- a "Write protect error writing drive .." message (and usually hangs),
- if you run a program from a write protected disk - even if the file is
- already infected!
-
- The virus uses the word 'GM' (474dh) as the signature. This is found
- at offset 4 in .COM files, and at offset 12h (the checksum field) in
- the .EXE header. The message below can be seen almost at the end of
- infected files.
-
- It includes a counter (set to 19 in our sample) which is decremented
- each time a program is infected. When the counter reaches zero the
- message
-
- Larry on a Screen
-
- is displayed instead of running the program.
-
- This virus does not pose a serious threat, as it does no deliberate
- damage, and is so unreliable that most users will realise something is
- wrong, even before they get the message.
-
- VET 7.06 will detect this virus, and restore infected files. It will
- also detect and repair files infected with Shifter (also recently
- found in Australia), and will detect a number of viruses recently
- discovered overseas.
-
- Roger Riordan. CYBEC Pty Ltd Ph: +61 3 521 0655
- PO Box 205, Hampton. Vic 3188 AUSTRALIA Fax +61 3 521 0727
-