Icelandic#2 Virus (Sept. 20, 1989) Entry...............: "Icelandic virus" (Version #2) Alias(es)...........: Virus Strain........: Icelandic Virus Virus detected when.: July 20 1989 where.: Iceland Classification......: .EXE file infecting virus/Extending/Resident Length of Virus.....: 1. 632-647 bytes added to file 2. 2048 bytes in RAM --------------------- Preconditions ------------------------------------ Operating System(s).: MS-DOS Version/Release.....: 2.0 or higher Computer model(s)...: IBM PC,XT,AT and compatibles --------------------- Attributes --------------------------------------- Easy Identification.: .EXE Files: Infected files end in 18 44 19 5F (hex). System: Byte at 0:37F contains FF (hex) Type of infection...: Extends .EXE files. Adds 632-647 bytes to the end of the file. Stays resident in RAM, hooks INT 21 and infects other programs when they are executed via function 4B. It will remove the Read-Only attribute if necessary, but it is not restored. .COM files are not infected. Infection Trigger...: Every tenth program run is checked. If it is an uninfected .EXE file it will be infected. Storage media affected: --- Interrupts hooked...: INT 21 Damage..............: none Damage Trigger......: Particularities.....: The virus modifies the MCBs in order to hide from detection. The INT 13 checking in the Icelandic-1 has been removed. The virus uses the name of the file to determine if it is an .EXE file, but not the true type, as determined by the first 2 bytes. The virus assumes the program reserves all available memory (FFFF paragraphs needed). Programs that donot will cause a system crash when infected and run. This virus is a version of the Icelandic-1 virus, modified so that it does not use INT 21 calls to DOS services. This is done to bypass monitoring programs. Similarities........: --------------------- Agents ------------------------------------------- Countermeasures.....: All programs which check for .EXE file length changes will detect infections. Countermeasures successful: Detection of infection: F-FCHK (from F.Skulason's F-PROT package) VIRUSCAN Prevention of infection: F-FCHK Removal: F-FCHK Standard means......: Use DEBUG to check the byte at 0:37F. --------------------- Acknowledgement ---------------------------------- Location............: University of Iceland/Computing Services Classification by...: Fridrik Skulason (frisk@rhi.hi.is) Documentation by....: Fridrik Skulason Date................: Sept 20, 1989 Information Source..: .