Adolf Virus (20-FEB-1993) Entry...............: Adolf Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: --- where.: --- Classification......: Resident, appending COM-file infector. Length of Virus.....: 475 bytes on disk/memory --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx and above Computer model(s)...: IBM PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: The code contains the text: " Adolf Hitler ", and the fourth byte will be an ASCII '5' = 35h. Self Identification.: The virus will not infect a file, if fourth byte is 35h. It stores itself in memory, starting at position 0000:0200 if there isn't a BBh (the first code-byte). Type of infection...: Starting an infected file will make the virus resident before executing the file correctly. At execion time of an uninfected file, the virus appends itself to the file's code. Infection Trigger...: INT 21h load/execute function if the virus is active in memory. Storage media affected: All files at each locations. Interrupts hooked...: INT 21h functions 4Bh(load/execute) and 41h(delete), INT 24h. Damage..............: Nothing except infection. Damage Trigger......: --- Particularities.....: If the virus is active in memory and INT 21h function 41h is called, a deletion will only succeed if bits 0 and 1 of BIOS-parameter 046C (Timer) are not set both. Similarities........: --- --------------------- Agents ------------------------------------------ Countermeasures.....: Skulasons F-PROT 2.06a, McAfee SCAN V99. Standard means......: Reboot and delete infected files. --------------------- Acknowledgement --------------------------------- Location............: Virus Test Center, University of Hamburg, Germany. Classification by...: Stefan Haack Documentation by....: Stefan Haack Date................: 01-FEB-1993 Information Source..: Virus-code analysis .