About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
Viruses
Virus Information
Virus Zines - 40HEX, Crypt, etc.
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it

NCSA Virus Report #7


NOTICE: TO ALL CONCERNED Certain text files and messages contained on this site deal with activities and devices which would be in violation of various Federal, State, and local laws if actually carried out or constructed. The webmasters of this site do not advocate the breaking of any law. Our text files and message bases are for informational purposes only. We recommend that you contact your local law enforcement officials before undertaking any project based upon any information obtained from this or any other web site. We do not guarantee that any of the information contained on this system is correct, workable, or factual. We are not responsible for, nor do we assume any liability for, damages resulting from the use of any information on this site.
???????????????????????????????
? VIRUS REPORT ?
? 1536 ?
???????????????????????????????

Synonyms: Zero Bug.

Date of Origin: September, 1989.

Place of Origin: the Netherlands.

Host Machine: PC compatibles.

Host Files: Remains resident. Infects COM files.

OnScreen Symptoms: A smiley face character
may appear on the screen and "eat" any 0's it can find.

Increase in Size of Infected Files: 1536 bytes.

Nature of Damage: Affects system run-time
operation. Corrupts program or overlay files.

Detected by: Scanv38+, F-Prot

Removed by: CleanUp, Scan/D, F-Prot, or delete
infected files.

The Zero Bug virus was first isolated in the Netherlands by Jan
Terpstra in September, 1989. This virus is a memory resident .COM file
infector. Infected .COM files will increase in size by 1,536 bytes,
however the increase in file length will not show up when the disk
directory is displayed.

The virus's main objective is to infect the copy of COMMAND.COM
indicated by the environment variable COMSPEC. If COMSPEC doesn't point
to anything, the Zero Bug virus will install itself memory resident
using INT 21h.

After the virus has either infected COMMAND.COM or become memory
resident, it will infect all COM files that are accessed, including
those accessed by actions such as COPY or XCOPY. Any COM file created on
an infected system will also be infected.

If the currently loaded COMMAND.COM is infected, the virus will hook
into the timer interrupt 1Ch, and after a certain amount of time has
past, a smiley face character (ASCII 01) will appear and eat all the
zeros it can find on the screen. The virus does not delete files or
format disks in its present form.

??????????????????????????????????????????????????????????????????????
? This document was adapted from the book "Computer Viruses", ?
? which is copyright and distributed by the National Computer ?
? Security Association. It contains information compiled from ?
? many sources. To the best of our knowledge, all information ?
? presented here is accurate. ?
? ?
? Please send any updates or corrections to the NCSA, Suite 309, ?
? 4401-A Connecticut Ave NW, Washington, DC 20008. Or call our BBS ?
? and upload the information: (202) 364-1304. Or call us voice at ?
? (202) 364-8252. This version was produced May 22, 1990. ?
? ?
? The NCSA is a non-profit organization dedicated to improving ?
? computer security. Membership in the association is just $45 per ?
? year. Copies of the book "Computer Viruses", which provides ?
? detailed information on over 145 viruses, can be obtained from ?
? the NCSA. Member price: $44; non-member price: $55. ?
? ?
? The document is copyright © 1990 NCSA. ?
? ?
? This document may be distributed in any format, providing ?
? this message is not removed or altered. ?
??????????????????????????????????????????????????????????????????????
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
If you have any questions about this, please check out our Copyright Policy.

 

totse.com certificate signatures
 
 
About | Advertise | Bad Ideas | Community | Contact Us | Copyright Policy | Drugs | Ego | Erotica
FAQ | Fringe | Link to totse.com | Search | Society | Submissions | Technology
Hot Topics
Php
Withstanding an EMP
Good computer destroyer?
Wow, I never thought the navy would be so obvious.
Alternatives Internets to HTTP
Anti-Virus
a way to monitor someones AIM conversation
VERY simple question: browser history
 
Sponsored Links
 
Ads presented by the
AdBrite Ad Network

 

TSHIRT HELL T-SHIRTS

 
www.pigdog.org