02.08.2013 Views

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

MS-DOS/PC-DOS Computer <strong>Virus</strong>es<br />

Name: Bob<br />

Aliases: Bob Type: Program.<br />

Disk Location: COM application.<br />

COMMAND.COM.<br />

Features:<br />

Damage: Size: 718 See Also:<br />

Notes: This virus activates in January 1993.<br />

Name: Bob Ross<br />

Aliases: Bob Ross, Beta Type: Program.<br />

Disk Location: Features:<br />

Damage: Size: Polymorphic: each<br />

infection different<br />

See Also: Screaming Fist<br />

virus<br />

Notes: Rumor: written by the group PHALCON/SKISM (like Screaming Fist virus)<br />

Polymorphic because it changes one byte in the middle of the decryption routine<br />

Name: Bones<br />

Aliases: Bones, Stoned-T, NOP Type: Boot sector.<br />

Disk Location: Floppy disk boot sector. Features: Trashes the hard disk.<br />

Hard disk partition table.<br />

On the 7th of any month it reatrranges the data<br />

on the hard disk.<br />

Damage: Trashes the hard Size: Overlays boot sector, no See Also:<br />

disk.<br />

increase<br />

On the 7th of any month it<br />

reatrranges the data on the<br />

hard disk.<br />

Reduces RAM by 1K.<br />

Notes: The virus is detected as Bones, Stoned-T, or NOP by different anti-virus products.<br />

********VirHUNT 4.0E does not detect it***********<br />

VirALERT does detect and stop the attempted infection, but VirHUNT 4.0E can not detect or<br />

identify it.<br />

F-PROT 2.16 calls it Bones<br />

Norman calls it Bones<br />

Vi-Spy 12 calls it Stoned-T<br />

SCAN 2.14e calls it NOP<br />

The virus uses stealth techniques, so most packages will not be able to detect it with the virus in<br />

memory. Most packages did discover the virus string in memory though they could not see the<br />

virus on disk.<br />

The virus is very destructive. On the 7th of any month, it will rearrange the data on your hard<br />

drive the first time you access an uninfected floppy. You can not recover from the destruction. All<br />

data on the hard drive is lost.<br />

Before it triggers, the virus can be removed by booting from a locked floppy and executing<br />

FDISK /MBR to write a new master boot record.<br />

May 21, 1998 CIAC Computer <strong>Virus</strong> <strong>Information</strong> Update 123<br />

PC

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!