home *** CD-ROM | disk | FTP | other *** search
/ ProfitPress Mega CDROM2 …eeware (MSDOS)(1992)(Eng) / ProfitPress-MegaCDROM2.B6I / UTILITY / VIRUS / PCV4RPT.ZIP / PERFUME.RPT < prev    next >
Encoding:
Text File  |  1991-05-09  |  3.8 KB  |  83 lines

  1.  
  2.              *********************************************
  3.              ***   Reports collected and collated by   ***
  4.              ***            PC-Virus Index             ***
  5.              ***      with full acknowledgements       ***
  6.              ***            to the authors             ***
  7.              *********************************************
  8.  
  9.  
  10. ===== Computer Virus Catalog 1.2: "Perfume" Virus (20-July-1990) =====
  11. Entry................. "Perfume" Virus
  12. Alias(e).............. = "4711" = "765" Virus
  13. Strain................ ---
  14. Detected: when........ ---
  15.           where....... ---
  16. Classification........ Program virus, resident COM infector
  17. Length of virus....... 765 bytes added to COM files
  18.  
  19. ----------------------- Preconditions --------------------------------
  20.  
  21. Operating System(s)... MS-DOS
  22. Version/Release....... 2.0 and up
  23. Computer models....... Any IBM-compatibles
  24.  
  25. ------------------------Attributes -----------------------------------
  26.  
  27. Easy identification... Contains in one version the following strings:
  28.                           "G-VIRUS V2.0",0Ah,0Dh,
  29.                           "Bitte gebe den G-Virus Code ein : $" <CRLF>
  30.                           0Ah,0Dh,"Tut mir Leid !",0Ah,0Dh,"$";
  31.                           (trans- lated 2nd and 3rd strings:  "please
  32.                           input G-virus code"; "sorry"); in another
  33.                           version there is a block of 88(dec) bytes
  34.                           that contain 00h.
  35.  
  36. Type of infection..... The virus makes itself resident and intercepts
  37.                           INT 21 upon subfunction 4Bh (load+execute);
  38.                           virus TSR tries to infect the loaded file
  39.                           by appending itself to it. Infectable files
  40.                           have extension COM and are less than FC00h
  41.                           (64512d) bytes long.
  42.  
  43. Infection trigger..... Loading of a file triggers infection mechanism.
  44.  
  45. Interrupts hooked..... INT 21
  46.  
  47. Damage................ A password is demanded after an infected file
  48.                           has been invoked more than 80 times. Initial
  49.                           message is the first string given above. If
  50.                           the given password is not "4711" (name of a
  51.                           well known German perfume), the virus will
  52.                           display the second message and terminate the
  53.                           program. In the hacked version of the virus,
  54.                           all messages have been zeroed out including
  55.                           the termination characters ("$") which
  56.                           causes the virus to output its code as text
  57.                           till the first $-character.  Also the input
  58.                           buffer size for the password iterrogation
  59.                           has been zeroed which causes unpredictable
  60.                           results upon entry of too many characters.
  61.  
  62. Particularities....... Under a rare circumstance, the virus can
  63.                           produce a variant of itself which won't be
  64.                           able to identify itself and thus will infect
  65.                           a file more than once; this is one of
  66.                           several bugs in the virus.
  67.  
  68. ----------------------- Acknowledgement ------------------------------
  69.  
  70. Location.............. Micro-BIT Virus Center RZ Universitaet
  71.                           Karlsruhe
  72.  
  73. Classification by..... Christoph Fischer
  74. Dokumentation by ..... Christoph Fischer
  75. Date.................. 14-April-1990
  76.  
  77. ====================== End of "Perfume" Virus ========================
  78.  
  79.  
  80.   ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
  81.   ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
  82.   ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
  83.