                    Ŀ
                            VIRUS REPORT         
                               Suriv03           
                    

Synonyms: Israeli, Suriv 3.00

Place of Origin: Israel.

Host Machine: PC compatibles.

Host Files: Remains resident. Infects COM, EXE, overlay files. Does not
infect COMMAND.COM

OnScreen Symptoms: A black square may appear on the screen after
activation.

Increase in Size of Infected Files: 1813 bytes (COM files) and 1808 bytes
(EXE files).

Nature of Damage: Affects system run-time operation. Corrupts program or
overlay files.

Detected by: Scanv56+, F-Prot, Pro-Scan.

Removed by: CleanUp, Scan/D, F-Prot, or UnVirus.

Derived from: Suriv02.

Scan Code: You can search at offset 099H for FC B4 E0 CD 21 80 FC E0 73
16.

     This virus is nearly identical to the Jerusalem virus, which is much
better known, and which was derived from it. The virus activates on
Friday the 13 when an infected program is run.

     It does not delete files, due to a bug in its code. On other days,
after the virus is memory resident for 30 seconds, an area of the screen
is turned into a "black window" and a time wasting loop is executed.

     Differences from the Jerusalem virus:

*   the string "sUMsDos" found in the Jerusalem is "sURIV 3.00" in this
    version.

*   the 30 minute delay (before machine slow-down) in the Jerusalem is 30
    seconds in this version (making detection easier with this virus than
    with the Jerusalem);

*   there is a bug in the program delete function of the virus, making
    this version less lethal than the Jerusalem.


ͻ
  This document was adapted from the book "Computer Viruses",       
  which is copyright and distributed by the National Computer       
  Security Association. It contains information compiled from       
  many sources. To the best of our knowledge, all information       
  presented here is accurate.                                       
                                                                    
  Please send any updates or corrections to the NCSA, Suite 309,    
  4401-A Connecticut Ave NW, Washington, DC 20008. Or call our BBS  
  and upload the information: (202) 364-1304. Or call us voice at   
  (202) 364-8252. This version was produced May 22, 1990.           
                                                                    
  The NCSA is a non-profit organization dedicated to improving      
  computer security. Membership in the association is just $45 per  
  year. Copies of the book "Computer Viruses", which provides       
  detailed information on over 145 viruses, can be obtained from    
  the NCSA. Member price: $44; non-member price: $55.               
                                                                    
            The document is copyright (c) 1990 NCSA.                
                                                                    
  This document may be distributed in any format, providing         
  this message is not removed or altered.                           
ͼ

Downloaded From P-80 International Information Systems 304-744-2253
