02.08.2013 Views

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

PC<br />

MS-DOS/PC-DOS Computer <strong>Virus</strong>es<br />

Notes: When this virus activates it displays the text<br />

Kewl Dewdz!<br />

The virus contains the string,<br />

Made in STL (c) ’91<br />

Name: Diablo_Boot<br />

Aliases: Diablo_Boot Type: Boot sector.<br />

Disk Location: Floppy disk boot sector.<br />

MBR Hard disk master boot record-partition<br />

table.<br />

Features: No damage, only replicates.<br />

Damage: No damage, only<br />

replicates.<br />

Size: See Also:<br />

Notes: The Diablo_Boot virus is a simple master boot record, floppy boot sector infecting virus<br />

that does nothing more then replicate. A copy of the original master boot record is stored at<br />

physical location cylinder 0, side 0, sector 2. On floppy disks, a clean copy of the boot sector is<br />

stored within the last sector of the root directory (this could cause data loss on full floppy disks).<br />

Within the body of the virus is the following text (this text is never displayed):<br />

DIABLO r disk error<br />

Name: Diamond<br />

Aliases: Diamond, Italian Diamond, Damage, Damage-2, Type: Program.<br />

David, Greemlin, Lucifer, Rock Steady, Alfa, 1024<br />

Disk Location: COM application.<br />

Features: Attempts to format the disk.<br />

EXE application.<br />

Damage: Attempts to format<br />

the disk.<br />

Only the Rock Steady variant<br />

does this.<br />

Only the Rock Steady variant does this.<br />

Size: 1024<br />

See Also:<br />

666 - Rock Steady Variant<br />

Notes: mentioned in <strong>Virus</strong>-l, v4-224, v5-006<br />

Two variants were once uploaded to a BBS in Bulgaria.<br />

Relative of 1024/1024B<br />

The Rock Steady variant formats the hard disk on the 13th of any month.<br />

Name: Dichotomy<br />

Aliases: Dichotomy, Evil Avatar Type: Program.<br />

Disk Location: EXE application.<br />

Features: Causes system to hang.<br />

COM application.<br />

Corrupts some EXE file.<br />

Damage: Causes system to Size: Polymorphic: each See Also:<br />

hang.<br />

infection different<br />

Corrupts some EXE file. 2 block, 296 byte and 567<br />

byte.<br />

Notes: The following notes are extracted from VB:<br />

The name is taken from an internal text string ’ [ Dichotomy] (c) 1994 Evil Avatar [ Dichotomy] ’<br />

in the program.<br />

162 CIAC Computer <strong>Virus</strong> <strong>Information</strong> Update May 21, 1998

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!