Su Virus (31-July-1993) Entry...............: Su Virus Alias(es)...........: Susan Virus Virus Strain........: --- Virus detected when.: April 1993 where.: USA Classification......: Overwriting File (EXE) Virus, memory resident Length of Virus.....: 1.Length (Byte) on media: 864 Bytes 2.Length (Byte) in RAM: 571 Bytes --------------------- Preconditions ------------------------------------ Operating System(s).: MSDOS Version/Release.....: MSDOS>=3.30 (Bug: Checks for DOS 3.03) Computer model(s)...: IBM PCs and Compatibles --------------------- Attributes --------------------------------------- Easy Identification.: Virus contains the following texts, unencrypted: "Bad command or file name", "Susan", "*.*", "*.EXE", "DIR" Type of infection...: File infection: Virus infects EXE files by over- writing it's code over the first 864 bytes. Self-Identification in files: FileTime.Seconds=1Fh System infection: Upon executing an infected EXE file, virus makes itself memory resident (in low memory) Self-Identification in files: if given value in INT 2Fh register found. Infection Trigger...: If (a single "DIR" issued) AND (FindFirst finds an uninfected .EXE file) Storage media affected: Interrupts hooked...: INT 2F/10F, 2F/AE00, 2F/AE01 Damage..............: Permanent Damage: 1) Infected files are overwritten and destroyed. 2) Deletion of all files in current directory. Transient Damage: Instead of executing the infected program, virus displays the message: "Bad command or file name" and then terminates. Damage Trigger......: Permanent Damage: 1) Upon infection (see Infection Trigger) 2) 16 Infections since activation Transient Damage: Staring an infected program. Particularities.....: 1) Virus does not hand control over to infected program; instead, it terminates with afore- mentioned message. 2) Virus uses INT 21;AX=5D00h to delete files. 3) Hooked interrupts (AH=0AEh) are reportedly called by COMMAND.COM just before executing commands from keyboard. 4) Naming: "Susan" found in text; "Su" used as register content. Similarities........: --- --------------------- Agents ------------------------------------------- Countermeasures.....: Countermeasures successful: Standard means......: Delete infected files and replace with clean ones. --------------------- Acknowledgement ---------------------------------- Location............: Classification by...: Snorre Fagerland Documentation by....: Snorre Fagerland (CAROBase entry) Klaus Brunnstein (VTC, Virus Catalog entry) Date................: 25-June-1993 Information Source..: Reverse analysis of virus code .