Requires Virus (31-July-1993) Entry...............: Requires Virus Alias(es)...........: Requires.981 = Demise = Later Virus Virus Strain........: --- Virus detected when.: Russia where.: --- Classification......: Resident, appending-EXE and prepending-COM file infector Length of Virus.....: In files: 981 bytes (EXE files are first padded to a multiple of 16 bytes). In memory: 1952 bytes after the last MCB. --------------------- Preconditions ------------------------------------ Operating System(s).: MS/PC DOS Version/Release.....: 3.0+ Computer model(s)...: Any MS-DOS compatible computer --------------------- Attributes --------------------------------------- Easy Identification.: All infected files contain the message "This program requires MS-DOS 3.00 or later$". Self Identification.: In memory: INT 21h/AH=0B3h returns 9051h in AX. In COM files: if the first two bytes of the file are 50h 8Ch, it is considered as infected. However, the first two bytes of the virus are actually 50h 0B4h, which causes COM files to be re-infected multiple times. In EXE files: if the two bytes at offset 10h in EXE header are 5Ch 09h (in the SP field), then file is considered as infected. Type of infection...: Files with extension 'COM' and 'EXE'. The true file type is determined by checking the first two bytes for 'MZ', however. No check is made for 'ZM'. Files ??????D.COM is not infected. Infection Trigger...: OpenFileHandle and LoadAndExec (INT 21h/AH=3Dh and INT 21h/AX=4B00h). Storage media affected: Any MS-DOS file system which contains infectable objects. Interrupts hooked...: INT 21h and INT 24h (only during infection). Damage..............: Transitive damage: infected programs executed under a version of DOS below 3.0 display message "This program requires MS-DOS 3.00 or later" and refuse to run. Permanent damage: --- Damage Trigger......: Transitive damage: Execution of an infected file under a version of DOS below 3.0. Permanent damage: --- Particularities.....: 1) When an infected file is executed,virus removes itself from there, in an attempt to hide the source of infection and to prevent from being detected by self-checking programs. 2) COM files can be infected multiple times. 3) Due to some bugs, multiply infected files can not always be restored to their original state but will still contain parts of the virus. Those parts, however, will be inactive and will never receive control. However, they may cause "ghost positive" alerts by some scanners (since a significant part of the virus potentially containing scan strings used by scanners, remain in such incompletely "cleaned" files). Similarities........: --- --------------------- Agents ------------------------------------------- Countermeasures.....: Virus uses no full stealth, tunneling, or poly- morphism, so most integrity checkers, monitors, and up-to-date scanners should have no problems detecting it. Countermeasures successful: F-Prot 2.04a was tested and was able to successfully remove virus when removable. Standard means......: If you can remove it without any anti-virus progs --------------------- Acknowledgement ---------------------------------- Location............: Virus Test Center, University of Hamburg, Germany Classification by...: Vesselin Bontchev Documentation by....: Vesselin Bontchev Date................: 27-Jul-1992 Information Source..: Reverse analysis of virus code .