Terminator II (31-July-1993) Entry...............: Terminator II Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: where.: Classification......: File virus (COM,EXE infector); memory resident; stealth. Length of Virus.....: 1.Length (Byte) on media: 2294 Bytes 2.Length (Byte) in RAM: 2448 Bytes. --------------------- Preconditions ------------------------------------ Operating System(s).: MSDOS Version/Release.....: Computer model(s)...: IBM PCs and Compatibles. --------------------- Attributes --------------------------------------- Easy Identification.: 1) Last two bytes of infected are equal to 1000h, seconds value of FileTime set to 56 (see: Self- Identification in files). 2) File allocation errors shown by CHKDSK. Amount of free memory is decreased by 2448 bytes. Type of infection...: File infection: virus appends itself to end of an EXE or COM file and changes the CS:IP in EXE header or places JMP to virus code in COM files. Only files larger than 1388 bytes will be in- fected. File with names containing "SCAN" in any place of name will not be infected. Self-Identification in files: Last two bytes of virus are equal to 1000h, seconds value of FileTime set to 56. System infection: When starting an infected file, virus makes itself memory resident at top of system memory but below 640K boundary (usually at 9f67:0000). Virus allocates memory by de- creasing size of the last "Z" Memory Control Block by 2448 bytes. Self-Identification in memory: function 4BFEh of DOS services reconstruct and execute program if virus is in memory, otherwise virus conti- nues execution and installs itself in memory. Infection Trigger...: Executing an infected file, or Opening, Loading and Executing any file when memory is infected. Storage media affected: Interrupts hooked...: INT 21h(Dos-Services): functions: 0Fh (Open_FCB), 11h (Find1st_FCB),12h (FindNxt_FCB),3dh (Open), 3eh (Close),3fh (Read),42h (Seek),4eh (Find1st), 4fh (FindNxt),4B00h (Load/Execute),4B01h (Load), 6ch (Extended_Open). Damage..............: Permanent Damage: 1) Virus slows down speed of computer, mixing output to printer: case of every 16th character will be reversed and 0 will be changed to 9. 2) Displays string "TERMINATOR", overwrites CMOS, overwrites 1 side of all hard drives. Transient Damage: --- Damage Trigger......: Permanent Damage: 1) Damage 1) will be triggered two month after infection, if second bit of date is non-zero. 2) Damage 2) will be triggered if date is bigger than date of infection plus two month plus ten days. Transient Damage: --- Particularities.....: Due to his setalth technique, virus is almost in- visible when active in memory. It has prevention from "curing" by packing infected files, mostly stealth viruses can be disinfected by such a trick, because usually stealth virus returns clean file to system, and file becomes clean during packing. Similarities........: NOT related to Terminator as described in VSUM! --------------------- Agents ------------------------------------------- Countermeasures.....: Countermeasures successful: Detection: Gobbler-II v3.0 Disinfection: Gobbler-II v3.0+ Standard means......: Delete infected files and replace with clean ones. --------------------- Acknowledgement ---------------------------------- Location............: Classification by...: Received from unnamed contributor outside VTC Documentation by....: Klaus Brunnstein (VTC, CVC entry) Date................: 31-July-1993 Information Source..: .