"Flash" Virus (20-July-1990) Entry................. "Flash" Virus Alias(e).............. "688" Virus Strain................ --- Detected: when........ --- where....... --- Classification........ Program virus, resident virus Length of virus....... 688 bytes added to infected files ----------------------- Preconditions ---------------------------------------- Operating System(s)... MS-DOS Version/Release....... 2.0 and up Computer models....... Any IBM-compatibles ------------------------Attributes ------------------------------------------- Easy identification... --- Type of infection..... The virus makes itself resident and intercepts INT 21 upon subfunction 4Bh (load+execute); the virus TSR tries to infect the loaded file by appending itself to it. If the file to be loaded has an extension starting with "E", the virus assumes it to be an EXE file. Infection trigger..... Loading of a file triggers infection mechanism. Interrupts hooked..... INT 21, INT 24 (during infection); INT08 (only upon payload trigger). Damage................ Starting with June 1990, the virus hooks INT 08, and after a random time it starts to flash the screen image every 7 minutes (5 rapid on/off cycles). This effect is visible on MDA, Hercules, and CGA adapters, but *not* on EGA and VGA cards! Particularities....... The virus tries to fool debuggers when tracing by self modifying code that executes differ- ently due to the instruction prefetch queue- ing of 80x86 processors. The detection of write protected floppies uses a novel technique: a writeprotected floppy in drive A: will disable the infection mechanism of the resident copy of the virus. ----------------------- Acknowledgement ------------------------------ Location.............. Micro-BIT Virus Center RZ Universitaet Karlsruhe Classification by..... Christoph Fischer Dokumentation by ..... Christoph Fischer Date.................. 3-July-1990 .