Icelandic#1 Virus (Sept 20, 1989) Entry...............: "Icelandic virus" (Version #1) Alias(es)...........: Disk-eating virus Virus Strain........: Icelandic Virus Virus detected when.: Mid-June '89 where.: Iceland Classification......: .EXE file infecting virus/Extending/Resident Length of Virus.....: 1. 656-671 bytes added to file 2. 2048 bytes in RAM --------------------- Preconditions ------------------------------------ Operating System(s).: MS-DOS Version/Release.....: 2.0 or higher Computer model(s)...: IBM PC,XT,AT and compatibles --------------------- Attributes --------------------------------------- Easy Identification.: .EXE Files: Infected files end in 18 44 19 5F (hex). System: Byte at 0:37F contains FF (hex) Type of infection...: Extends .EXE files. Adds 656-671 bytes to the end of the file. Length MOD 16 will always be 0. Stays resident in RAM, hooks INT 21 and infects other programs when they are executed via function 4B. It will remove the Read-Only attribute if necessary, but it is not replaced. .COM files are not infected. Infection Trigger...: Every tenth program run is checked. If it is an uninfected .EXE file it will be infected. Storage media affected: --- Interrupts hooked...: INT 21 Damage..............: If the current drive is a hard disk larger than 10M bytes, the virus will select one cluster and mark it as bad in the first copy of the FAT. Diskettes and 10M byte disks are not affected. Damage Trigger......: The damage is done whenever a file is infected. Particularities.....: The virus modifies the MCBs in order to hide from detection. It will not be activated if INT 13 contains something other than 0070:xxxx or F000:xxxx when an infected program is run. Similarities........: --- --------------------- Agents ------------------------------------------- Countermeasures.....: All programs which check for .EXE file length changes will detect infections. Any virus prevention program that changes INT 13 will prevent the activation of the virus. F-SYSCHK (by the author of this article) will detect the system infection. F-FCHK (by the author of this article) will identify infected files. Countermeasures successful: F-SYSCHK, F-FCHK (from F.Skulason's ANTIVIRUS package) Standard means......: Use DEBUG to check the byte at 0:37F. Running any program which stays resident and modifies INT 13 (like PRINT) will prevent the virus from being activated. --------------------- Acknowledgement ---------------------------------- Location............: University of Iceland/Computing Services Classification by...: Fridrik Skulason (frisk@rhi.hi.is) Documentation by....: Fridrik Skulason Date................: July 8, 1989 Information Source..: .