home *** CD-ROM | disk | FTP | other *** search
- ------ Computer Virus Catalog 1.2: "JINX" (12.7.1994) -----------------
-
- Entry...............: JINX
- Alias(es)...........:
- Virus Strain........:
- Virus detected when.:
- where.:
- Classification......: BootBlock (System), Reset-Resident
- Length of Virus.....: 1.Length (1024) on storage medium
- 2.Length (1040) in RAM
-
- --------------------- Preconditions -----------------------------------
-
- Operating System(s).: AMIGA-DOS
- Version/Release.....: 1.2, 1.3, 2.0, 3.0
- Computer model(s)...: All Amigas
-
- --------------------- Attributes -------------------------------------
-
- Easy Identification.: -
-
- Type of infection...: Self-Identification methods:
- - Virus checks Byte $42(Bootblock)
- System infection:
- - RAM-Resident (Vertb, Sumkickdata,td_globalvec
- - Reset-Resident (KickTag,KickCheckSum)
-
- Infection Trigger...: Acessing any floppy disk
-
- Storage media affected: Diskettes
-
- Interrupts hooked...: KICKTAG, KICKCHECKSUM, IV_VERTB, SUMKICKDATA,
- TD_GLOBALVEC
-
- Damage..............: Permanent Damage:
- - overwriting bootblock
- - headstep (trashing disk)
- Transient Damage: -
- Transient/Permanent damage:
- - Due to not allocating used memory-areas in the
- stack raange the system will probably crash.
-
- Damage Trigger......: Disk-Acess, Counter
-
- Particularities.....: The virus is encrypted with a variable key and
- has stealth capabilities. The virus catches
- specific format-disk commands and replys an error
- on them.
-
- Stealth.............: The virus hides itself from normal disk-editors
- with stealth-capabilities
-
- Similarities........: The stealth-routine is related to the lamer
- strain.
-
-
- --------------------- Agents ------------------------------------------
-
- Countermeasures.....: VT 2.64, VW 3.7
- Countermeasures successful: All of the above
- Standard means......: Replace the original bootblock with "install"
-
- --------------------- Acknowledgement ---------------------------------
-
- Location............: Virus Test Center, University Hamburg, FRG
- Classification by...: Soenke Freitag
- Documentation by....: Soenke Freitag
- Date................: 12.7.1994
- Information Source..: Reverse analysis of virus-code
-
- --------------------------End of "JINX"-Virus--------------------------
-
-