  
  =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
                                    DisCoVir
  
                               Virus Information
  
  
  
                             Program Documentation
  
                                       by
  
                             Cesar I. Gulmatico Jr.
  
  
  
  
               Copyright (c) 1997-1999 by Cesar I. Gulmatico Jr.
  ___________________________________________________________________________
  =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
  
  
  The virus information module contains description of viruses known to 
  DisCoVir. It is invoked by using the /VI option on the command line.
  
                                  DisCoVir /VI
  
  The virus information is only available to REGISTERED users of DisCoVir. If 
  invoked in the shareware version, DisCoVir will either display the help 
  screen and terminate, or ignore the option and scan the specified drive. 
  
  The virus information data file, DCVIRNFO.DAT, should be present in the 
  drive and directory where DisCoVir was executed from. The virus information 
  data file is version specific. For example, the data file of DisCoVir 1.04 
  cannot be used by DisCoVir 1.05, and vice versa. 
  
  DisCoVir Virus Information is a text mode DOS program and should only be 
  executed from the DOS command line. 
  
  If DisCoVir Virus Information is used on a multitasking system, make sure 
  that there are no other active applications. This is to avoid possible 
  complications because the program assumes that it is the only active 
  program.
  
  DisCoVir Virus Information format is loosely patterned after F-Prot's virus 
  information. F-Prot is a shareware program by Fridrik Skulason and is 
  copyrighted by Frisk Software International. 
  
  
  
  
  SYSTEM REQUIREMENT
  
  DisCoVir requires a color graphics adapter (CGA, EGA, VGA) for the virus 
  information module. DisCoVir will terminate if it detects a monochrome 
  adapter.
  
  No additional memory is required at the moment. If you can execute DisCoVir 
  without getting memory allocation errors, the virus information module will 
  load without problem. Otherwise, LOADHIGH DisCoVir [LH DISCOVIR /VI] so that 
  the virus information data can be loaded entirely in conventional memory.
  
  DisCoVir supports the use of a mouse. The mouse driver should be installed 
  prior to the execution of DisCoVir. Your mouse should be configured as 
  Microsoft mouse compatible.
  
  
  
  
  HOW TO USE THE PROGRAM
  
  You will be presented with a message when you execute the virus information 
  module. A prompt at the bottom of the message requests you to click your 
  mouse or press a key. If the mouse part of the prompt is not displayed, it 
  means that you do not have a mouse or DisCoVir does not recognize your mouse 
  driver. 
  
  When asked to CLICK the mouse, you will have to point the mouse cursor to an 
  item, press and then release the mouse button. The left and right mouse 
  buttons are not differentiated and may be used interchangeably. If your 
  mouse does not seem to work, check if it is properly attached.
  
  
  Main Virus Menu
  ~~~~~~~~~~~~~~~
  
          Close Button                   Main Virus Menu Ŀ 
                                                                   
      Ŀ      Menu Cursor                                   
      ĳĳĿ
                                                                   
          Ŀ                                                  
           1575       Dir-II        Matthew           Possessed      
                                                            
            AntiExe     E_Bukid       Michelangelo      Quox           
  
  
    The Main Virus Menu is made up  of the names of viruses arranged 
    alphabetically top to bottom, left to right. The close button is on the 
    upper left corner of the menu.
  
    KEYBOARD: The menu cursor is moved by using the arrow keys (up, down, 
      left, right). The Home key brings the menu cursor to the first virus on 
      the menu and the End key brings it to the last entry. 
  
      Press the Enter key to display the information on the virus where the 
      menu cursor is currently at. 
  
      The pressing of the PgUp (Page Up) and PgDn (Page Down) keys change the 
      currently displayed page of the Main Virus Menu. At present, the Main 
      Virus Menu has two pages.
  
    MOUSE: The hot spot for the menu cursor is defined by the longest virus 
      name in a column. It is one character before the virus name up to a 
      character after the longest name. A mouse click that is not within a 
      menu cursor hot spot is ignored.
  
      Click on a virus name (or anywhere in the hot spot) to move the menu 
      cursor to that virus name. Click on the menu cursor (or double click on 
      a virus name) to display the information for that virus.
  
      Clicking in the scroll bar (located at the right side of the Main Virus 
      Menu) also moves the menu cursor or switches between Main Virus Menu 
      pages depending on where on the scroll bar the mouse was pointing when 
      you made a click.
  
  Virus Information Screen
  ~~~~~~~~~~~~~~~~~~~~~~~~
  
     Virus Information Box                 Status Ŀ     Current Page
                        Virus Name Bar                      Number 
                                                                 of Pages
     ĿĿ
                                 Possessed             Page 1 of 6  
     
     Ŀ
      Name  : Possessed                                               
     CARO  : Possessed                                               
       Type  : Resident File                                           
       Target: COM, EXE, COMMAND.COM                                   
       Description:                                                    
  
                                                                       
          Key                               
                                    Guide   
                                                                       
  
  
  The Virus Information Screen is divided into two, the Virus Name Bar at the 
  top and the Virus Information Box which occupies most of the screen. The 
  Status, located at the left end of the Virus Name Bar, tells you what page 
  you are currently at and the number of information pages for that particular 
  virus. 
  
  The Key Guide ( ) will appear on both sides of the Virus Information Box 
  for a virus whose description is contained in two or more pages. The 
  presence of  in the Key Guide means that there is at least a page preceding 
  the current one and  means that there are one or more succeeding virus 
  information pages.
  
  KEYBOARD: The Esc key returns you to the Main Virus Menu. The Page Down 
      (PgDn) and Page Up (PgUp) keys changes the current page for viruses 
      whose information are in multiple pages. 
  
      The PgUp key is only accepted if   is present in the Key Guide and the 
      PgDn key if  is present. DisCoVir only waits for the Esc key for 
      viruses with only one information page.
  
  MOUSE: Click at the lower half of the Virus Information Box to display the 
      next information page. Click at the upper half of the Virus Information 
      Box to display the preceding page. The Key Guide delineates the upper 
      and lower half of the Virus Information Box.
  
      Click at the Virus Name Bar to return to the Main Virus Menu.
  
      A click at the upper half of the Virus Information Box is processed if  
      is present in the Key Guide and also at the lower half if  is present. 
      DisCoVir only waits for a click at the Virus Name Bar for viruses with 
      one information page. 
  
  Drop-Down Menu
  ~~~~~~~~~~~~~~
  
      Ŀ      Drop-Down Menu
      ĳĳĿ
        Ŀ                                                      
       Help...        Dir-II        Matthew           Possessed       
       Tune...  e     E_Bukid       Michelangelo      Quox            
       About... l     Fairz         Microbe           Sampo           
      ĳ      Illusion      Monkey            SaptaWahyu      
       Quit           Jerusalem     NiceDay           SayhaWatpu      
            Joshi         Njh-Lbc           Stoned          
  
  
  The drop-down menu offers the user access to the program's help screen; 
  tunes used in viruses' activation routine; and information about the 
  program. Program termination can only be made from the drop-down menu.
  
  The Help option has a menu which includes instructions on how to use the 
  mouse and keyboard, and a brief explanation of the terms used in the Virus 
  Information Heading. 
  
  The Tune option presents the melodies played by known viruses when 
  activated. The routines used to play the tunes were lifted from virus codes 
  (and adapted to the program). So what you are going to hear is exactly the 
  same melody as if the virus has activated. The program uses your system 
  speaker. If you can hardly hear the beeps your computer makes, you might not 
  be able to hear the tunes available in this option. When a virus is 
  selected, the tune it plays (if known) and the playing time is displayed. 
  
      Ŀ
                                                                       
                               R E M I N D E R                         
                                                                       
        As most of the routines used to play the tunes use the clock   
        interrupt, your system  clock  might be delayed by a couple of 
        seconds everytime you play a tune.                             
                                                                       
      
  
  
  KEYBOARD: The Esc key toggles the display of the drop-down menu. Use the Up 
      and Down arrow keys to move the menu cursor. You can also use the Home 
      and End keys to move to the first or last entry of the menu. The Enter 
      key selects the option where the menu cursor is positioned.
  
      The Help menu uses the same keys as that of the drop-down menu. 
  
      The Tune menu uses the same keys as that of the drop-down menu. You can 
      stop the playing of a melody anytime by pressing the F10 key. 
  
      The Esc key closes the selected option.
      
  MOUSE: Press a mouse button on the close button to display the drop-down 
      menu. Click on an option to move the menu cursor to that option. Click 
      on the menu cursor to select the option. 
  
      Clicking outside the drop-down menu hides the menu.
  
      Click at the menu option "Close Help" to hide the Help menu.
  
      In the Tune menu, the mouse is disabled while a melody is playing. It is 
      enabled after the completion of a tune or it is aborted. There is no 
      mouse counterpart for termination of a melody.
  
      Click on the close button to close a selected option.
  
  
                                       - o -
  
  
  VIRUS INFORMATION
  
  Virus Information Heading
  ~~~~~~~~~~~~~~~~~~~~~~~~~
  The first page of the information for a virus contains a heading consisting 
  of Name, CARO, Type, Target and Description.
  
    Name is the name used by DisCoVir to identify viruses.
  
    CARO is the CARO virus name as used by F-Prot to identify viruses. CARO 
    virus name for viruses with variants is enclosed in square brackets after 
    the variant name. F-Prot (Version 2.16 January 1995) is used as reference 
    because it is consistent with the name it uses to identify viruses. 
  
    Type describes the general characteristics of the virus. A virus may have 
    any of the following characteristics:
  
      Resident - the virus installs itself in memory.
  
      NonResident - the virus is not memory resident.
  
      File - the virus only infects files.
  
      Boot - the virus infects boot sectors and/or master boot record only.
  
      Multipartite - the virus infects both files, and boot sectors and/or 
         master boot record. A file virus that drops a non-replicating code in 
         the boot sector and/or MBR is not considered in this type. A boot 
         virus that converts files into virus droppers is also not included.
  
      Macro - a file virus that was created using a program's macro language. 
         It only infects files associated with that program. However, it might 
         have additional manipulation routines to infect or alter files not 
         associated to that particular program.
  
      Overwriting - the virus overwrites and destroys the host program. All 
         viruses overwrites a part of the host program but only those that do 
         not preserve the overwritten code are considered in this type. Those 
         that overwrite uninitialized data or the stack area are not included. 
         This is only applied to file infecting viruses even if it can also be 
         used to describe some boot infecting viruses (NiceDay).
  
      Stealth - the virus contains instructions to hide an infection.
  
      Encrypted - portion of a virus' executable code is encrypted. Those that 
         only encrypt their text string (messages) or data are not included.
  
      SingleStep - the virus contains instructions that (intentionally or 
         unintentionally) prevents tracing of the virus code. Some viruses 
         uses anti-debugging tricks in their install routine and others in 
         their interrupt handlers, or both. 
  
    Target includes the part of the disk, and files infected by a virus. Files 
    infected are identified by their file extension. The filename is specified 
    if the virus infects a specific file. COMMAND.COM is specified since newer 
    viruses avoid infecting this file. 
  
    Description is my interpretation of the virus code.
  
  
  Description of the Virus
  ~~~~~~~~~~~~~~~~~~~~~~~~
  The program presents as much as possible a detailed description of a virus. 
  Some descriptions, however, have been intentionally generalized. Information 
  for some viruses (DieHard2, Dir-II, SayhaWatpu) are from partial analysis of 
  their codes. The information provided by the program includes the following:
  
  - The memory size of the virus, where it resides, how it checks memory for 
    residency and the redirected interrupts.
  
  - The virus' payload or activation routine. If the payload is a screen 
    display in 80x25 text mode, it will be presented without animation.
  
  - The location of the original boot sector and the rest of the virus code 
    for boot infecting viruses.
  
  - How the virus infects files, its length and where it is located.
  
  - Texts found in the virus code and other identifying characteristics.
  
  - Other interesting features of the virus, if any.
  
  
  Clarifications and Notes
  ~~~~~~~~~~~~~~~~~~~~~~~~
  Numbers are in decimal notation. A number is in hexadecimal notation if 
  specified as hexadecimal, hex or suffixed with a lower case h.
  
  A memory location is always in hexadecimal notation. It is presented in 
  double word SEGMENT:OFFSET format.
  
  Physical disk addressing is used throughout the program in side-track-sector 
  format. Some refer to track as cylinder and side as head when used to 
  address hard disks. DisCoVir uses track and side regardless of disk media.
  
  For viruses with variants, the general description of the virus strain is 
  presented first. Any deviation from the general description is noted under 
  the description of the variant. The characteristics which will differentiate 
  variants are also noted in the variant's description.
  
  A file infecting virus is usually installed in the 640 Kb conventional 
  memory. If upper memory is available, a virus is installed there if the host 
  program is executed with the LOADHIGH or DEVICEHIGH commands, or its 
  equivalent in third party memory managers/drivers. This is applicable to 
  viruses that install as a TSR or those that manipulate the MCBs. Unless 
  otherwise specified as limited to conventional memory, a virus can reside in 
  either low or high memory. 
  
  A file virus is installed as a TSR if it becomes memory resident through 
  Interrupt 27h or Interrupt 21h Function 31h. The TSRs are installed in the 
  lowest available memory segment. A file virus that manipulates the MCBs 
  usually installs at the top of memory (highest available memory segment). 
  Those that handle the MCBs directly, as well as boot viruses, are also TSRs. 
  But only those defined above as TSR are being referred to whenever TSR is 
  mentioned in the virus information.
  
  A boot virus is always installed at the top of conventional memory after 
  booting from an infected disk, including non-bootable diskettes. 
  
  A multipartite virus is installed either as a file or a boot virus.
  
  The memory size of a file infecting virus that installs as a TSR is made up 
  of the program block and the environment block, if not released. The memory 
  size of a virus that does not release the environment will vary since the 
  length of this block is not constant. Its length will depend on the 
  variables set in your system and the path of the host program. However, the 
  length of the virus' program block is constant. The 16-byte memory arena is 
  not included in the memory size of TSRs.
  
  A boot virus infects when a disk is accessed. This usually happens when the 
  disk is read (Int 13h Fn 02). Some boot viruses also infect when other Int 
  13h functions are invoked. These functions are not specified in the virus 
  description. Let it be known that by changing to a floppy disk drive (such 
  as typing A: and pressing the Enter key) the write-enabled diskette in that 
  drive will become a candidate for infection. The hard disk? It is infected 
  when you boot from an infected floppy, execute a file infected by a 
  multipartite virus or execute a virus dropper. Majority of boot viruses only 
  infect the first physical hard disk (which can be partitioned into one or 
  more logical drives). Almost all boot viruses will only infect the Master 
  Boot Record. But there are viruses that will only infect the boot sector of 
  the hard disk's bootable partition (PingPong).
  
  The description of the Dir-II virus is based on its behavior in floppy 
  disks. I have not tested the virus on a hard disk.
  
  
                                     - o -
  
  
  A WORD FROM THE AUTHOR
  
  The information provided by this program is the result of my own disassembly 
  of virus codes and observations of their behavior. This should therefore be 
  considered as my interpretation which may not necessarily agree with yours.
  
  Some texts and screen display of viruses might offend your sensibility. 
  These texts and messages are reproduced in the program for the sole purpose 
  of documenting the virus. This also does not mean that I agree with the 
  virus author's intention.
   
  Your comments on DisCoVir Virus Information are welcome. 
  
  This program is written by:
  
        CESAR I. GULMATICO JR.
  
        16 Agno Street
        NIA Village, Tandang Sora 
        Quezon City
        Philippines
