Nomenklatura Virus (15-July-1991) Entry...............: Nomenklatura Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: where.: Classification......: RAM-resident Program (COM & EXE) Infector Length of Virus.....: COM & EXE fles: 1024 Bytes Memory: 1072 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MS-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM compatibles --------------------- Attributes ------------------------------------- Easy Identification.: Textstring: 'Nomenklatura' at offset 4 followed by string "00 80 FC 4B 74 0A 80 FC 3D 74 14" Self Identification : Checks length of code after execution of initial jump; infects only if this length isnot 1024. Type of infection...: System: Allocates a memory block at high end of memory, finds original adress of INT 13h handle, collects and changes INT 21h vector. COM&EXE files: program length increased by 1024. Required size of files for infection: .EXE: more than 1024 bytes .COM: filesize between 1024 and 64000 bytes. Files will only be infected once. COMMAND.COM is normally first file that will be infected. If ReadOnly attribute of file is set, virus is not able to infect it. File date & time will not be changed. Infection Trigger...: Programs are infected at load time (using MsDos function 4Bh) as well as when MsDos function 3Dh is invoked. Storage media affected: Any drive Interrupts hooked...: INT 13h during virus installation in RAM, INT 21h hooked by resident part of virus. INT 13h, INT 24h during infection. Damage..............: Permanent Damage: by exchanging random words. Any file containing exchanged words will sud- denly contain totally different data. Any type of file and both FATs may be affected. Transient damage: --- Damage Trigger......: random trigger Particularities.....: While virus is in memory, every virus scanning program will infect all files on the system, as virus uses MsDos function 3Dh (open file). Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Detection in RAM: McAfee's Scan 7.2V77 Skulason's f-syschk V 1.16+ Countermeasures successful: Detection in files & succesful desinfect: Skulason's f-fchk V 1.15+ Standard means......: Set ReadOnly attribute --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification......: Soenke Spehr Documentation by....: Soenke Spehr Date................: 15-July-91 Information Source..: --- .