XREH Virus (25-July-1992) Entry...............: XPEH-4016 Virus in (kyrillic letters) CHREN-4016 Virus (in Latin letters) Alias(es)...........: --- Virus Strain........: XREH Virus Strain Virus detected when.: ? where.: Russia Classification......: Program (COM & EXE) Virus, memory-resident Length of Virus.....: 1. Length on media: 4016 bytes (appended) 2. Length in memory: 3872 bytes. --------------------- Preconditions ----------------------------------- Operating System(s).: MS-DOS Version/Release.....: DOS 2.x and above Computer model(s)...: IBM & Compatibles --------------------- Attributes -------------------------------------- Easy Identification.: Total memory size decreased by 4032 bytes, disk access slows down, when virus is active. Scan signature......: The following bytes can be found at the INT-21- entrypoint: 80 FC 4E 74 12 80 FC 4F 74 0D 2E 3A Type of infection...: a) COM-files : The virus appends itself to the end of the file, changing the first 32 Bytes of the victim (restored later). b) EXE-Files : Virus uses standard ways of infecting EXE-files. Infection Trigger...: Execution of COM & EXE files, when month>March and year>1991. Usage of INT 21, AH=4E/4F (FindFirst/FindNext), when the date is above March and 1991. (For details ). Storage media affected: Files on all accessible media are affected. Interrupts hooked...: INT 21, functions: AH=4E (FindFirst), AH=4F (FindNext), AH=4B (Load&Execute) INT 1C (Timer), INT 01 (Trace) and INT 03 are hooked temporarily (For details see Particularities) Damage..............: Files with the Extension ". ", ".LEX", ".TXT", ".BAK" can be garbled, during September-December of any year above 1991. Damage Trigger......: System-date (see Damage). Particularities.....: The virus hooks INT 21, AH=4E/4F for infecting files and encrypting files (damage!), as well as subtracting his length from COM/EXE with filetime 30 seconds. Filetime will be set to 30 sec, when it has been infected or garb- led. This routine will garble files, in months >=September of any year above 1991 and in- fecting COM and EXE files in months >=March of any year above 1991, using a 1:4 random- routine to determine whether to be active. The virus uses the EXE-signature (MZ/ZM) to recognize EXE-files. COM files will only be infected, when their size is >=288 and <=61,815 bytes. As the maximum size of COM-files seems to have been forgotten to be changed, while writing a new version of the virus (there are shorter versions!), COM- files can get bigger than 65k and won't run. If the date is >=September and >1991, ". ", ".LEX", ".TXT", ".BAK" files can be garbled, decrypting up to 64k of them with the kyrillic letters XPEH (hex: 95 80 85 8D) (xor). The INT 1C (Timer) is used to check, wether the entrance of INT 1 and INT 3 (Trace/Breakpoint) is an IRET-instruction; if not, the entrypoint is overwritten with a CALL FAR into the virus. Here the virus determines, from where the INT has been called, and if it was a INT 1 or INT 3. After that, it is decided whether only the Trace-flag is disabled, or if it should hang the system. The virus copies itself to the top of RAM, de- creasing the total amount of memory by 4032 bytes. When the virus installs itself into memory, it uses a kind of TRACER, to find the original INT 21 entry (decission is made via the seg- ment: if it is below 200, virus assumes that original INT 21 entry has been reached). While running, the virus constantly de/encrypts parts of it to disable reassembling of itself, making analysis very difficult. Similarities........: XREH variants --------------------- Agents ----------------------------------------- Countermeasures.....: F-PROT 2.02D in Quick-scan recognises the virus as a new variant of Cascade. Countermeasures successful: The Antiviral Package v. 4.6 from Kaspersky (Moscow) recognizes and removes the virus. Standard means......: Delete and replace infected files. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Toralv Dirro Documentation by....: Toralv Dirro Date................: 05-May-1992 Information Source..: Original virus analysis .