home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!think.com!yale.edu!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: riordan.cybec@tmx.mhs.oz.au (Roger Riordan)
- Newsgroups: comp.virus
- Subject: Another new version of Zerotime. (PC)
- Message-ID: <0005.9212212018.AA02123@barnabas.cert.org>
- Date: 17 Dec 92 22:24:11 GMT
- Sender: virus-l@lehigh.edu
- Lines: 40
- Approved: news@netnews.cc.lehigh.edu
-
- We have just received another version of Zerotime (or Slow) virus,
- which would appear to have been patched locally. Two instructions
- have been swapped, as shown below. The only existing program we
- have tried which will find it is F-Prot, which identifies it as "a
- new strain of Slow".
-
- This would have been fairly trivial if the finder had not had many
- files in which the virus was protected by a CPAV product, supposed
- to provide integrity checking. This is reported in another note.
-
- The effects of this virus do not seem to be well known. It is
- Jerusalem derived, is not obvious, and does not make the PC run
- slow. However for every 2nd file closed during business hours on
- any Friday it sets the file date & time to zero (ie midnight on Jan
- 1st, 1980). This would appear to be intended to trick accounting
- and backup software into thinking that the the latest weeks results
- are incredibly boring old rubbish, and throwing them away.
-
- It also mutates, and occasionally generates a version with a new
- randomly derived signature (used by the virus when checking if a
- file is already infected). The new version recognises, and will not
- re-infect, files infected by its parent. As no reputable scanner
- uses this signature this has no practical significance. Zerotime is
- quite common in Australia.
-
- Oddly DIR does not show a date or time for files dated Jan 1, 1980.
-
- Normal Zerotime 3
-
- 0107 90 NOP 0107 90 NOP
- 0108 81C61B00 ADD SI,001B 010C B9900C MOV CX,0690
- 010C B9900C MOV CX,0690 0108 81C61B00 ADD SI,001B
- 010F 2E CS: 010F 2E CS:
- 0110 803471 XOR BYTE PTR.. 0110 803471 XOR BYTE PTR..
-
-
- Roger Riordan riordan.cybec@tmxmelb.mhs.oz.au
-
- CYBEC Pty Ltd. Tel: +613 521 0655
- PO Box 205, Hampton Vic 3188 AUSTRALIA Fax: +613 521 0727
-