Clone Virus (31-July-1993) Entry...............: Clone Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: Spring 1993 where.: Sydney, Australia Classification......: File virus (EXE companion), memory resident. Length of Virus.....: 1.Length (Byte) on media: 833 Bytes (companion) 2.Length (Byte) in RAM: --------------------- Preconditions ------------------------------------ Operating System(s).: MSDOS Version/Release.....: Computer model(s)...: IBM PCs and Compatibles --------------------- Attributes --------------------------------------- Easy Identification.: Companion file contains following text at the end: "Your PC is Cloned!! Clone Virus ver 2.0 .. (c) Cataclysm 1992 Sydney, Australia ....To Create and Mutate...." Type of infection...: File infection: Upon executing an infected EXE file (precisely: it's hidden COM companion of same name), virus "infects" EXE files by crea- ting a COM file with same name, 833 bytes long, with hidden, system and read only attributes. Self-Identification in file: once in memory, virus intercepts all Int 21 calls with AH = 4B (Load & Execute), 4E (Find First) and 4F (Find Next). Whenever an EXE file is loaded, a com- panion file is first created (if not already present). Whenever a call to 4E or 4F finds a COM file, it checks if file is one of its companion files; if so, it simply repeats the call until an uninfected file is found. Stealth: By hooking on INT 21 calls Load&Execute, FindFirst and FindNext, used by many utilities e.g. DIR and scanners, virus will not be de- tected by such methods. System infection: virus uses an undefined DOS call to INT 21, to see if it's already in memory; when not yet in memory (=given value in INT 21 register), virus hooks INT 21 and makes itself memory resident. Self-Identification in memory: Checks INT 21 functions 4B (Load&Execute), 4E (FindFirst) and 4F (Find Next) register for given value. Infection Trigger...: Running an infected EXE file (i.e. file with companion virus) Storage media affected: Interrupts hooked...: INT 21 functions 4B (Load & Execute), 4E (Find First) and 4F (Find Next) Damage..............: Because of the way COMMAND.COM searches for pro- grams, the hidden .COM files will be run in- stead of user's specified program. Companion will execute it's intended function (see Tran- sient Damage) and subsequently load and start the user's intended "original" program. Permanent Damage: no intended permanent damage. Transient Damage: On trigger condition, following text will be displayed: "Your PC is Cloned!!" Damage Trigger......: Permanent Damage: --- Transient Damage: If Date = April 1st. Particularities.....: --- Similarities........: --- --------------------- Agents ------------------------------------------- Countermeasures.....: AntiVirus programs Countermeasures successful: VET 7.3 (CYBEC); no other products tested Standard means......: Boot from a clean diskette; use proper tool to change Read-Only attribute and delete companion COM file --------------------- Acknowledgement ---------------------------------- Location............: CYBEC Pty, Hampton Victoria/Australia Classification by...: Roger Riordan (riordan.cybec@mhs.oz.au> Documentation by....: Roger Riordan Klaus Brunnstein (CVC entry) Date................: 31-July-1993 Information Source..: Analysis of Virus .