BFD Virus (25-July-1992) Entry...............: BFD Virus Standard CARO Name..: BootEXE.452 Virus Alias(es)...........: BootEXE-452 = Sector Eleven Virus Virus Strain........: BootEXE Virus Strain Virus detected when.: July 7, 1992 where.: U.S. Classification......: Multipartite (=Program & System) Virus: Resident EXE file (converts EXE format to COM format), diskette boot and system boot infector Length of Virus.....: System infection: 1 sector on infected disks File infection: 0x01C3h bytes (but files do NOT grow in length) --------------------- Preconditions ----------------------------------- Operating System(s).: PC-DOS Version/Release.....: Any? Computer model(s)...: Any? --------------------- Attributes -------------------------------------- Easy Identification.: Infected EXE files begin with EB 39 rather than with "MZ". Self Identification.: 1) If virus is active in memory, INT13 with F0 in AH returns 19 in AH. 2) Infected files do not begin with "MZ". 3) Infected disks/diskettes contain virus in boot records (compares). Type of infection...: Any file that begins with "MZ", contains fewer than 0x80 512-bytes pages, has not too many relocation items in the table, has FFFF in the Max Req Para field, and a header size of 0x20 paragraphs. Any diskette read from, and the first partition on the first hard disk, if it starts on a head other than zero. Infection Trigger...: Any INT13 that reads the first sector of the file. Storage media affected: Any diskette can be infected, but only 360K 5.25" diskettes will boot properly. Any hard disk. Interrupts hooked...: INT13 only. Damage..............: No apparent intentional damage Damage Trigger......: --- Particularities.....: An unusual infection method; the virus installs itself in unused EXE header space when the start of the EXE file is read via INT13. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Not stealthed, so scanners with a signature, and modification detectors, should have no trouble. INT21-based monitors won't notice it. Countermeasures successful: ? Standard means......: Infected files can be made to work again by changing the first two bytes back to "MZ" (zeroing out the virus code in the unused header space is also a good idea). --------------------- Acknowledgement -------------------------------- Location............: IBM High Integrity Computing Laboratory, USA Classification by...: David Chess Documentation by....: David Chess Date................: 9-July-1992 Information Source..: Analysis of original virus .