home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- ====== Computer Virus Catalog 1.2: "5120" Virus (5-June-1990) =======
-
- Entry.................. "5120" virus
- Alias(es).............. ---
- Strain................. ---
- Detected: when......... January 1990
- where........ Wuerzburg, West Germany
- Classification......... Program virus
- Length of Virus........ 5120-5135 for EXE and COM files (virus resides
- on a paragraph boundery)
-
- ---------------------- Preconditions---------------------------------
- Operating System(s).... MS-DOS
- Version/Release........ 2.00 and upwards
- Computer models........ IBM PCs and compatibles
-
- ------------------------ Attributes----------------------------------
-
- Easy identification.... The following texts are contained in the
- virus: "BASRUN", "BRUN", "IBMBIO.COM",
- "IBMDOS.COM", "COMMAND.COM", "Access denied"
-
- Type of infection...... Program virus. The virus infects in direct
- action (ie. it only infects on run time), by
- searching through the directories recursively
- starting on paths "C:\", "F:\" as well as the
- current drive an EXE and a COM file to infect.
- It will infect all files it can find.
-
- EXE files will be infected if the length as
- reported by DOS is less that the file length
- as reported by the EXE header plus one page.
- COM files will be infected if the file length
- is less than 60400 bytes.
-
- The virus turns Ctrl-C checking and verify
- off while in operation.
-
- Infection trigger...... The virus will infect any time it is executed
- after the 6th of July 1989. However, if an
- infected file will infect before this date, if
- it has already been executed once. It doesn't
- load itself memory resident.
-
- Media affected......... Any logical drive
-
- Interrupts hooked...... ---
-
- Damage................. Any infected file will terminate with the
- message "Access denied" (this comes from the
- virus, not from DOS). The file is NOT deleted
- in any way.
-
- Damage trigger......... Any date after the 1st of June 1992
-
- Particularities........ It seems to be written in a HLL, but I haven't
- found out which.
-
- Similarities........... ---
-
- --------------------------- Agents------------------------------------
- Countermeasures........ ---
-
- - ditto - successful.. Most checksumming programs will find this
- virus. The program NTI5120 (Virus Test
- Center) will find and destroy any 5120 virus
- found.
-
- Standard Means......... Do a string search for any of the strings
- mentioned above.
-
- ---------------------- Acknowledgements-------------------------------
- Location............... Virus Test Center, University of Hamburg
- Classification by...... Morton Swimmer
- Documentation by....... Morton Swimmer
- Date................... 5-June-1990
- Information source..... ---
-
- ===================== End of "5120" Virus ===========================
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++