VCS V1.0 Virus (15-July-1991) Entry................. VCS V1.0 Virus Alias(es)............. Virus-Construction-Set V1.0 = VDV Virus (VDV = "Verband Deutscher Virenliebhaber"; = "community of German virus lovers") Strain................ --- Detected: when........ March 1991 where....... Bulletin Board, Hamburg, Germany Classification........ Program Virus, direct action; overwriting AUTOEXEC and CONFIG.SYS; encrypted. Length of Virus....... File: 1077 bytes ---------------------- Preconditions --------------------------------- Operating System(s)... MS/PC-DOS Computer models....... All IBM PC compatibles. ---------------------- Attributes ------------------------------------ Easy identification... Files containing C350h at offset 03h regarded as infected (self identification) Search string at offset 00h: E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE Type of infection..... .COM files: increased by 1077 bytes; virus is not RAM resident, files can only be in- fected when an infected host is started; files are randomly infected in the current directory or in root directory and below. Files are not infected if word at offset 03h of file contains C350H. .COM files are infected only once. .EXE files: no infection. Infection trigger..... Any time an infected file is run, the virus infects up to 10 files, but only if the Int 26h (=absolute-disk-write-vector) is not hooked by a program. Interrupts hooked..... --- Damage................ Permanent damage: when triggered, the files 'C:\AUTOEXEC.BAT' and 'C:\CONFIG.SYS' will be overwritten with 512 bytes of text. Transient Damage: when AUTOEXEC and CONFIG.SYS have been overwritten, a text which was deliberately choosen by the installator (see: Particularities:Generating the virus) may be displayed. Damage trigger........ If generation counter > damage counter, the permanent/transient damage is performed. Particularities....... Virus is encrypted; on each infection, en- cryption key and generation counter are changed; virus therefore mutates. Files with ReadOnly attribute set will not be infected. .COM files longer than 64,190 bytes are no longer loadable. Particularities/Generating this virus: VCS virus was created by program VCS.EXE ('Virus Construction Set V1.0'), which was written by a "Verband Deutscher Virenliebhaber" (=community of German virus lovers) and was available via a BBS in Hamburg. Using VCS.BIN and a textfile, VCS.EXE generates the program VIRUS.COM (1077 bytes). In constructing this virus, the user can adjust the damage counter (1st active generation: 1..199) and specify his own textfile of 512 bytes. In VCS' menu (22 lines), detailed informa- tion is given how to generate 1st virus, ending with: "3) Start VIRUS.COM ... The infected program is now 1077 Bytes longer than before and can be given to known persons, friends and enemies.." The textfile (in German, 29 lines) distri- buted with VCS is essentially: "Virus Construction Set" "All have waited for it, here it is! Who didnot want to shove a little virus under his best enemy, but had none at his hand? ....." "This virus copies itself when invoked on .COM files in actual drive, after speci- fied number of generations a specified text will be displayed, AUTOEXEC.BAT and CONFIG.SYS will be deleted. Virus detects FLUSHOT in memory and keeps quiet." "This program is a community exercise of VDV Hamburg. We can be reached in BBS Hamburg (local tel#) under 'VDV'...." "In case of interest, version 2 of VCS will soon be available, with more possi- bilities to tune the virus." "Now to the legal aspect: herewith, a user is explicitly warned that this program generates viruses which may damage data. By using this program, the user accepts full responsibility for the viruses which he generates. We are not responsible under any circumstances. Nevertheless we renounce, due to evident reasons, to mention our adress here..." "... donate 20 DM to Red Cross. Generally, this program may be copied and used as desired." "We wish much fun with our viruses...." Similarities........... --- ---------------------- Agents ---------------------------------------- Countermeasures....... Searchstring at offset 00h of virus: E8 14 00 8A A4 2F 05 8D BC 20 01 B9 0F 04 89 FE - ditto - unsuccessful. McAfee's Scan version 75 and below - ditto - successful. Tode's NTI-VCS.EXE is an antivirus that only looks for VCS virus, and if requested will restore the file. Standard Means........ Notice file length. Use ReadOnly attribute. ---------------------- Acknowledgements ------------------------------ Location.............. Virus Test Center, University Hamburg, Germany Classification by..... Stefan Tode Documentation by...... Stefan Tode and Matthias Jaenichen Date.................. 15-July-1991 Information source.... --- .