Junior Virus (31-July-1993) Entry...............: Junior Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: July, 1992 where.: Sofia, Bulgaria Classification......: Memory resident, appending, COM file infector Length of Virus.....: 234 bytes --------------------- Preconditions ------------------------------------ Operating System(s).: PC/MS-DOS. Uses several undocumented and version- dependent tricks. Does not work under DR-DOS. Version/Release.....: Works under PC-DOS 3.30. Haven't checked for other versions. Computer model(s)...: Any MS-DOS computer --------------------- Attributes --------------------------------------- Easy Identification.: --- Self Identification.: The first instruction of infected files is a JMP which points at 56 bytes before end of file. Type of infection...: Any executable file, the first 2 bytes of which are not 'MZ' or 0C4h. Virus is appended to file. Infection Trigger...: Execution of a file. Storage media affected: Any storage media with MS-DOS compatible file system. Interrupts hooked...: INT 78h, 21h, 24h (only during infection), INT 13h (only during infection, and only if it is not already intercepted). Damage..............: --- Damage Trigger......: --- Particularities.....: The virus traps INT 21h/AX=4B00h in a very unusual way. It puts an INT 78h instruction at TerminateAddress-2 and intrcepts INT 78h itself. Similarities........: --- --------------------- Agents ------------------------------------------- Countermeasures.....: Any up-to-date scanner; any integrity checker. Monitoring programs which trap only INT 13h may not be able to detect the virus. Countermeasures successful: --- Standard means......: Delete infected files, restore clean copies. --------------------- Acknowledgement ---------------------------------- Location............: Virus Test Center, University of Hamburg, Germany Classification by...: Vesselin Bontchev Documentation by....: Vesselin Bontchev Date................: 10-August-1992 Information Source..: Reverse analysis of virus code .