"Suriv 3.00" Virus (5-June-1990) Entry...............: Suriv 3.00 Alias(es)...........: Jerusalem (B) = Israeli #3 Virus Virus Strain........: Israeli-Virus Classification......: Program Virus (extending), RAM-resident Length of Virus.....: .COM files: length increases by 1813 bytes. .EXE files: length increases by 1808-1823 bytes. (.EXE file length must be a multiple of 16 bytes, as in any .EXE file) --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS,PC-DOS Version/Release.....: 2.xx upward Computer model(s)...: IBM-PC, XT, AT and compatibles --------------------- Attributes -------------------------------------- Easy Identification.: Typical texts in Virus body (readable with HexDump facilities): "sURIV 3.00". Type of infection...: System: infected if function E0h of INT 21h returns value 0300h in the AX-register. .Com files: program length increases by 1813; files are infected only once; COMMAND.COM will not be infected. .EXE files: program length increases by 1808 - 1823 bytes, and no identification is used; therefore, .EXE files can be infected more than once. Infection Trigger...: Programs are infected at load time (using the function Load/Execute of MS-DOS). Interrupts hooked...: INT21h, INT08h Damage..............: 1. 30 seconds after the 1st infected program was run, the virus scrolls up 2 Lines in a small window of the screen ( left corner 5,5; right corner 16,16). 2. The virus slows down the system by about 10 %. Damage Trigger......: Every time when the system is infected. Particularities.....: 1. The version of the Suriv 3.00 which we have analyzed compares the system-date with "Friday 13th", but is not able to recognize "Friday 13th", because of a "bug"; if it cor- rectly recognized this date, it would delete any program started on "Friday 13th". 2. .EXE files can be infected many times. 3. Novell Netware 4.0 functions, esp. "Print Spooling" (INT21h/E0h), "Set Error Mode" (INT21h/DDh) and "Set Broadcast Mode" (INT21/DEh) cannott be used. --------------------- Agents ----------------------------------------- Countermeasures.....: The virus will be detected by : VIRSUCH 2.15 (D. Hoppenrath) as Israeli #3 F-FCHK 1.08 (F. Skulason) as Israeli/Jerusalem SCAN 3.1 (McAfee) as Jerusalem Ver. B FINDVIRU 6.04 (Solomon) as Suriv 3 Several Antiviruses do not work safely. --------------------- Acknowledgement --------------------------------- Location............: Virus Test Center, University Hamburg, FRG Classification by...: J|rg Steindecker Documentation by....: J|rg Steindecker, Joe Hirst (BCVRC) Date................: 5-June-1990 Updates by..........: --- .