-- Common Viruses: N to Z: _________________________________________________________________ NOMENKLATURA Synopsis: Destructive resident infector of .COM and .EXE files Damage: Severe random corruption of all areas of the disk. Symptoms: CHKDSK errors, damaged files, less total memory Details: Nomenklatura deliberately causes random corruption to your disk. This damage could affect any location on your disk including the boot sector. It decreases total memory by 1024 bytes and increases the size of all infected files by this amount. This increase is not concealed. OHIO Synopsis: Resident infector of floppy boot sectors Damage: Inadvertently damages 1.2mb and 3.5 inch diskettes Symptoms: Reduced total memory, slow disk accesses Details: Ohio will only correctly infect 360K diskettes, resulting in damage to all other types of disks. If Ohio finds the Brain virus present on a diskette, it will remove it and replace it with itself. PARITY BOOT Synopsis: Resident, stealth, DOS boot sector and partition sector virus Damage: Diskette corruption Symptoms: Reduced total memory, message and system hang Details: Another typical boot sector virus. Parity Boot will hide from inspection using stealth techniques and displays the message "PARITY CHECK" with a subsequent system hang. Any diskettes accessed with the virus resident in memory will be infected. PATHOGEN Aliases: SMEG Synopsis: Polymorphic, destructive, resident infector of programs Damage: Random sectors overwritten Symptoms: Program growth, less available memory, disk corruption, message display Details: Pathogen is spreading rapidly world-wide but most reports are coming from the UK. This virus claims to use a toolkit called SMEG. Integrity Master identifies Pathogen as SMEG and should identify any other viruses which would use the SMEG tool-kit. Most scanners can not detect Pathogen as this is written (mid 1994). The virus marks infected files by adding 100 years to the file date. On any Monday at 5PM this virus will write garbage to random sectors on the hard disk and then display this message: Your hard-disk is being corrupted, courtesy of PATHOGEN! Programmed in the U.K. (Yes, NOT Bulgaria!) [C] The Black Baron 1993-4 Featuring SMEG v0.1: Simulated Metamorphic Encryption Generator! 'Smoke me a kipper, I`ll be back for breakfast.....' Unfortunately some of your data won`t!!!!! PING PONG Aliases: Italian, Bouncing Ball, Bouncing Dot Synopsis: Resident infector of boot sectors and partition sectors. Symptoms: A bouncing ball appears, reduced total memory Details: The bouncing ball effect is triggered randomly a second after the system clock reaches a multiple of 30 minutes. The ball itself is the ASCII seven character that resembles a small rhombus. The original Ping Pong virus was discovered in March of 1988 and would only infect floppy disks. The version that is common today will also infect hard disk partition sectors. There is also a variant that does not have the bouncing ball effect. The virus will hide some of its code in an unused cluster that it marks as bad. S-BUG Aliases: Sbug, Satan-Bug Variants: FruitFly Synopsis: Polymorphic, resident, infector .COM and .EXE files Damage: Some programs are corrupted Symptoms: Reduced total memory, file growth, and system hangs Details: This is a memory resident polymorphic file infector. It reduces available memory by about 9K. S-Bug is very buggy and will hang on many PCs. Many S-bug infected programs will also hang. S-bug removes the validation codes added to files by McAfee scan and Central Point's "immunize" function. FruitFly is another (totally different) virus that uses almost the same polymorphic encryption/decryption code as that used by S-bug. Integrity Master will identify FruitFly as S-bug. STEALTH BOOT Aliases: Stelboo,Stealth_Boot.A Variants: Stealth_Boot.B,Stealth_Boot.C Synopsis: Resident, Stealth, DOS boot sector and partition sector virus Damage: Inadvertent disk corruption Symptoms: Message appears, reduced memory Details: This has become one of the most common viruses in the US. It is based on virus source code published in a book by a US company. Beyond its ability to conceal its presence on an infected system, this is a very non-exceptional boot sector virus similar to Stoned. When resident, it reduces total system memory by four thousand bytes. While it does not cause damage to the hard disk, we have numerous reports of corrupted files on infected floppies. SUNDAY Synopsis: Destructive resident infector of programs and overlays Damage: File corruption Symptoms: Message appearing on Sundays and reduced total memory Details: This appears to be a variant of Jerusalem that was modified to display this message on Sundays: "Today is Sunday! Why do you work so hard? All work and no play make you a dull boy! Come on! Let's go out and have some fun!" SVC Variants: SVC 3.1, SVC 4, SVC 5, SVC 6 Synopsis: Resident, infector .COM and .EXE files and of partition sectors (SVC 6 only) Damage: Some programs are corrupted Symptoms: Reduced total memory, file growth, and system hangs Details: These are memory resident file infecting viruses. With the virus resident in memory, any program executed will become infected. SVC 6, in addition to infecting programs, will infect the partition sector of your hard disk. TELECOM Aliases: Spanish Telecom, Telefonica, Campana, Kampana Synopsis: Destructive, resident, stealth infector of boot sectors, partition sectors and .COM files. Damage:Overwrites hard disks Symptoms: Message, reduced total memory Details: This is a family of three related viruses that were written to protest the Spanish telephone company. The .COM infecting virus will deposit the partition sector virus onto your hard disk. The .COM infecting virus is relatively rare but the other system sector virus has spread rather widely. After 400 boots, it will overwrite your hard disks and display the message: "VIRUS ANTITELIFONICA." The .COM infecting virus marks infected files by setting the year of the file's date stamp ahead 100 years. TEQUILA Synopsis: Resident, stealth infector of partition sectors and .EXE files Damage: Random corruption of files Symptoms: Colorful display and reduced total memory Details: Tequila was written by two young brothers in Switzerland, who were later arrested for their efforts. Tequila infects both .EXE files and hard disk partition sectors. As soon as an infected program is run, the virus will infect the partition sector. It reduces total memory by approximately 3000 bytes. Tequila will cause file corruption on many systems but this seems to be a bug rather than deliberate. Four months after infecting the PC, Tequila will display a crude but colorful character-based Mandelbrot image. Infected files will grow by 2468 bytes and high sectors of a hard disk will contain some virus code including this text: Welcome to T.TEQUILA's latest production. Contact T.TEQUILA/P.o.Box 543/6312 St'hausen/Switzerland. Loving thoughts to L.I.N.D.A BEER and TEQUILA forever ! TREMOR Synopsis: Resident, stealth infector of partition sectors and .EXE files Damage: Random corruption of files Symptoms: File date changes, screen tremor effect, reduced total memory Details: Tremor will infect primarily .EXE files (but also COMMAND.COM). Tremor marks files it infects by adding 100 years to their date. Tremor is highly polymorphic, uses stealth, and will disable memory resident anti-virus products. Tremor directly disables the resident virus protection provided by MS DOS 6.0 (Vsafe) and Central Point Anti-virus. Upon activation, Tremor creates a tremor effect by making the characters on your screen appear to shake. At this point the PC usually hangs. Tremor waits about three months before it displays this behavior. Tremor contains the text: -=>T.R.E.M.O.R was done by NEUROBASHER / May-June'92, Germany <- and also the message: .MOMENT.OF.TERROR.IS.THE.BEGINNING.OF.LIFE. Friday 14th of May 1993 TREMOR was sent out in an infected PKUNZIP.EXE together with McAfee's Scan on Channel Videodat (the PRO-7 TV-program received primarily in Europe) via Astra Satellite, terrestrial broadcast and via cable. Thousands of people may have downloaded the virus from this broadcast. Since their PC would become infected when they used the infected PKunzip to extract Scan, this enabled TREMOR to spread quite widely in very little time. VACSINA Variants: The TP##VIR series of viruses, Yankee Doodle Synopsis: Resident infector of programs Symptoms: Beeps and music Details: Vacsina has over 50 known variants. Yankee Doodle, TP04VIR, TP06VIR, TP16VIR, and TP23VIR are among the variants. Early versions of this virus only infected .COM files and sounded a beep whenever a file was infected. Later versions now infect .EXE files as well as other executable file types. Some later versions, such as Yankee Doodle, play music. Yankee Doodle will often play at 5PM or when the PC is booted. An interesting aspect of Vacsina viruses is that they contain a version number system; if Vacsina detects an earlier version of itself in a file, it will remove that version and replace it with itself. It's also remarkable that Vacsina will also search out and remove copies of the Ping Pong and Cascade viruses! VIENNA Aliases: Austrian, DOS62, UNESCO Variants: Lisbon, Dr.Q, Parasite, Violator, Viperize, Arf, and many more Synopsis: Nonresident infector of .COM files Symptoms: System hangs and unexpected reboots Details: Vienna viruses typically add between 600 to 3000 bytes to each infected .COM file although one variant (C-23693) is one of the largest viruses known. There are an overwhelming number of Vienna variants since the source code for this virus was printed in a book and widely distributed. Each time an infected program is executed, the virus will look for an uninfected program and infect that program before allowing the initial program to execute. To avoid reinfecting the same program, Vienna marks infected programs by setting the seconds field of the time stamp to 62. Since the seconds portion of the time stamp is not displayed by a DOS directory listing, this change usually goes unnoticed. Early Vienna versions damage (rather than infect) one of every six or eight programs by inserting instructions to force a reboot. When these programs are executed, the PC will reboot or hang and the program will never be executed. Since these programs are not infected by the virus but simply damaged, many people have no way of correcting or detecting this damage. _________________________________________________________________ -- Write to Stiller Research: 74777.3004@compuserve.com -- Back To The Stiller Research Home Page Copyright © 1995 Stiller Research. Document Last Modified 6/09/95.