
















                     Virus Clean Reference Manual







                  Copyright (c) Joe Hirst 1989-1992.

                         Telephone 0273-26105
                              Contents


1  Introduction. . . . . . . . . . . . . . . . . . . . . . . . . .  7

2  How to use the programs.. . . . . . . . . . . . . . . . . . . .  7
     2.1  Installation . . . . . . . . . . . . . . . . . . . . . .  7

3  Virus Monitor (VM.COM). . . . . . . . . . . . . . . . . . . . .  8
     3.1  Special Considerations . . . . . . . . . . . . . . . . .  8

4  Virus Clean (VC.COM). . . . . . . . . . . . . . . . . . . . . .  9

5  Menu Mode . . . . . . . . . . . . . . . . . . . . . . . . . . .  9
     5.1  The Main Menu. . . . . . . . . . . . . . . . . . . . . .  9
          5.1.1  Choose options. . . . . . . . . . . . . . . . . . 10
          5.1.2  Scan for viruses. . . . . . . . . . . . . . . . . 10
          5.1.3  Return to default options . . . . . . . . . . . . 10
          5.1.4  Write options to disk . . . . . . . . . . . . . . 10
          5.1.5  List known viruses. . . . . . . . . . . . . . . . 10
          5.1.6  Exit to DOS . . . . . . . . . . . . . . . . . . . 10
     5.2  Option Selection Menu. . . . . . . . . . . . . . . . . . 10
          5.2.1  Search options. . . . . . . . . . . . . . . . . . 10
          5.2.2  Removal options . . . . . . . . . . . . . . . . . 10
          5.2.3  Other options . . . . . . . . . . . . . . . . . . 11
     5.3  Search Options Menu. . . . . . . . . . . . . . . . . . . 11
          5.3.1  Search for Boot viruses . . . . . . . . . . . . . 11
          5.3.2  Search for Parasitic viruses. . . . . . . . . . . 11
          5.3.3  Examine All files . . . . . . . . . . . . . . . . 11
          5.3.4  Examine entered file Extensions . . . . . . . . . 11
          5.3.5  List all files examined . . . . . . . . . . . . . 12
     5.4  Removal Options Menu . . . . . . . . . . . . . . . . . . 12
          5.4.1  Remove Boot viruses from disks. . . . . . . . . . 12
          5.4.2  Remove Parasitic viruses from COM files . . . . . 12
          5.4.3  Remove Parasitic viruses from EXE files . . . . . 12
          5.4.4  Delete infected files . . . . . . . . . . . . . . 12
     5.5  Other Options Menu . . . . . . . . . . . . . . . . . . . 13
          5.5.1  Output messages to disk file. . . . . . . . . . . 13
          5.5.2  More? - pause when screen is full . . . . . . . . 13
          5.5.3  Scan a single drive . . . . . . . . . . . . . . . 13
          5.5.4  Return to menu after scan . . . . . . . . . . . . 13
          5.5.5  Black and white menu display. . . . . . . . . . . 13

6  Command Line Mode . . . . . . . . . . . . . . . . . . . . . . . 14
     6.1  Specifying a Disk. . . . . . . . . . . . . . . . . . . . 15
     6.2  All. . . . . . . . . . . . . . . . . . . . . . . . . . . 15
     6.3  Boot Only. . . . . . . . . . . . . . . . . . . . . . . . 15
     6.4  Deletion.. . . . . . . . . . . . . . . . . . . . . . . . 15
     6.5  Extension list.. . . . . . . . . . . . . . . . . . . . . 15
     6.6  List.. . . . . . . . . . . . . . . . . . . . . . . . . . 16
     6.7  More.. . . . . . . . . . . . . . . . . . . . . . . . . . 16
     6.8  No Menu. . . . . . . . . . . . . . . . . . . . . . . . . 16
     6.9  No Specified Disk. . . . . . . . . . . . . . . . . . . . 16
     6.10  No Output File. . . . . . . . . . . . . . . . . . . . . 16
     6.11  Output File.. . . . . . . . . . . . . . . . . . . . . . 16
     6.12  Parasitic Only. . . . . . . . . . . . . . . . . . . . . 17
     6.13  Removal.. . . . . . . . . . . . . . . . . . . . . . . . 17

7  VM_TEST . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17

8  What the programs do. . . . . . . . . . . . . . . . . . . . . . 18
     8.1  Integrity Checks . . . . . . . . . . . . . . . . . . . . 18
     8.2  Memory Checks. . . . . . . . . . . . . . . . . . . . . . 18
     8.3  Virus Monitor. . . . . . . . . . . . . . . . . . . . . . 19
     8.4  Virus Clean. . . . . . . . . . . . . . . . . . . . . . . 20
     8.5  New variants . . . . . . . . . . . . . . . . . . . . . . 21
     8.6  Return codes . . . . . . . . . . . . . . . . . . . . . . 21
     8.7  Updates. . . . . . . . . . . . . . . . . . . . . . . . . 22

9  The Viruses.. . . . . . . . . . . . . . . . . . . . . . . . . . 23
     9.1  Virus names. . . . . . . . . . . . . . . . . . . . . . . 23
     9.2  List of viruses. . . . . . . . . . . . . . . . . . . . . 25
          405. . . . . . . . . . . . . . . . . . . . . . . . . . . 25
          Aircop . . . . . . . . . . . . . . . . . . . . . . . . . 25
          Alabama. . . . . . . . . . . . . . . . . . . . . . . . . 25
          Anticad (1). . . . . . . . . . . . . . . . . . . . . . . 25
          Anticad (2). . . . . . . . . . . . . . . . . . . . . . . 26
          Anticad (3). . . . . . . . . . . . . . . . . . . . . . . 26
          Anticad (4). . . . . . . . . . . . . . . . . . . . . . . 26
          Anticad (5). . . . . . . . . . . . . . . . . . . . . . . 26
          Antipascal (1) . . . . . . . . . . . . . . . . . . . . . 26
          Antipascal (2) . . . . . . . . . . . . . . . . . . . . . 26
          Antipascal (3) . . . . . . . . . . . . . . . . . . . . . 27
          Antipascal (4) . . . . . . . . . . . . . . . . . . . . . 27
          Antipascal (5) . . . . . . . . . . . . . . . . . . . . . 27
          Azusa. . . . . . . . . . . . . . . . . . . . . . . . . . 27
          Brain (1). . . . . . . . . . . . . . . . . . . . . . . . 27
          Brain (2). . . . . . . . . . . . . . . . . . . . . . . . 28
          Brain (3). . . . . . . . . . . . . . . . . . . . . . . . 28
          Burger . . . . . . . . . . . . . . . . . . . . . . . . . 28
          Cascade (1). . . . . . . . . . . . . . . . . . . . . . . 28
          Cascade (2). . . . . . . . . . . . . . . . . . . . . . . 29
          Cascade (3). . . . . . . . . . . . . . . . . . . . . . . 29
          Dark Avenger (1) . . . . . . . . . . . . . . . . . . . . 29
          Dark Avenger (2) . . . . . . . . . . . . . . . . . . . . 29
          Dark Avenger (3) . . . . . . . . . . . . . . . . . . . . 29
          Datacrime (1). . . . . . . . . . . . . . . . . . . . . . 30
          Datacrime (2). . . . . . . . . . . . . . . . . . . . . . 30
          Datacrime (3). . . . . . . . . . . . . . . . . . . . . . 30
          Datacrime (4). . . . . . . . . . . . . . . . . . . . . . 31
          Den Zuk. . . . . . . . . . . . . . . . . . . . . . . . . 31
          Devil's Dance. . . . . . . . . . . . . . . . . . . . . . 31
          Disk Killer. . . . . . . . . . . . . . . . . . . . . . . 32
          EDV. . . . . . . . . . . . . . . . . . . . . . . . . . . 32
          Form . . . . . . . . . . . . . . . . . . . . . . . . . . 32
          Green Caterpillar. . . . . . . . . . . . . . . . . . . . 32
          Hacker (1) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hacker (2) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hacker (3) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hacker (4) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hacker (5) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hacker (6) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hacker (7) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hidden (1) . . . . . . . . . . . . . . . . . . . . . . . 33
          Hidden (2) . . . . . . . . . . . . . . . . . . . . . . . 34
          Horse. . . . . . . . . . . . . . . . . . . . . . . . . . 34
          Icelandic (1). . . . . . . . . . . . . . . . . . . . . . 34
          Icelandic (2). . . . . . . . . . . . . . . . . . . . . . 34
          Icelandic (3). . . . . . . . . . . . . . . . . . . . . . 35
          Icelandic (4). . . . . . . . . . . . . . . . . . . . . . 35
          Icelandic (5). . . . . . . . . . . . . . . . . . . . . . 35
          Italian (1). . . . . . . . . . . . . . . . . . . . . . . 35
          Italian (2). . . . . . . . . . . . . . . . . . . . . . . 36
          Italian (3). . . . . . . . . . . . . . . . . . . . . . . 36
          Italian (4). . . . . . . . . . . . . . . . . . . . . . . 36
          Jerusalem (S1) . . . . . . . . . . . . . . . . . . . . . 36
          Jerusalem (S2) . . . . . . . . . . . . . . . . . . . . . 37
          Jerusalem (S3) . . . . . . . . . . . . . . . . . . . . . 37
          Jerusalem (1). . . . . . . . . . . . . . . . . . . . . . 37
          Jerusalem (2). . . . . . . . . . . . . . . . . . . . . . 38
          Jerusalem (3). . . . . . . . . . . . . . . . . . . . . . 39
          Jerusalem (4). . . . . . . . . . . . . . . . . . . . . . 39
          Jerusalem (5). . . . . . . . . . . . . . . . . . . . . . 39
          Jerusalem (6). . . . . . . . . . . . . . . . . . . . . . 39
          Jerusalem (7). . . . . . . . . . . . . . . . . . . . . . 40
          Jerusalem (8). . . . . . . . . . . . . . . . . . . . . . 40
          Jerusalem (9). . . . . . . . . . . . . . . . . . . . . . 40
          Jerusalem (10) . . . . . . . . . . . . . . . . . . . . . 41
          Jerusalem (11) . . . . . . . . . . . . . . . . . . . . . 41
          Jerusalem (12) . . . . . . . . . . . . . . . . . . . . . 41
          Joshi. . . . . . . . . . . . . . . . . . . . . . . . . . 41
          June 16th. . . . . . . . . . . . . . . . . . . . . . . . 42
          Kennedy. . . . . . . . . . . . . . . . . . . . . . . . . 42
          Keypress . . . . . . . . . . . . . . . . . . . . . . . . 42
          Lehigh . . . . . . . . . . . . . . . . . . . . . . . . . 42
          New York (1) . . . . . . . . . . . . . . . . . . . . . . 43
          New York (2) . . . . . . . . . . . . . . . . . . . . . . 43
          New Zealand (1). . . . . . . . . . . . . . . . . . . . . 44
          New Zealand (2). . . . . . . . . . . . . . . . . . . . . 44
          New Zealand (3). . . . . . . . . . . . . . . . . . . . . 44
          New Zealand (4). . . . . . . . . . . . . . . . . . . . . 44
          New Zealand (5). . . . . . . . . . . . . . . . . . . . . 45
          New Zealand (6). . . . . . . . . . . . . . . . . . . . . 45
          New Zealand (7). . . . . . . . . . . . . . . . . . . . . 45
          New Zealand (8). . . . . . . . . . . . . . . . . . . . . 45
          Nomenklatura . . . . . . . . . . . . . . . . . . . . . . 45
          Nothing. . . . . . . . . . . . . . . . . . . . . . . . . 46
          Omicron (1). . . . . . . . . . . . . . . . . . . . . . . 46
          Omicron (2). . . . . . . . . . . . . . . . . . . . . . . 46
          Oropax . . . . . . . . . . . . . . . . . . . . . . . . . 46
          Pentagon . . . . . . . . . . . . . . . . . . . . . . . . 47
          Perfume. . . . . . . . . . . . . . . . . . . . . . . . . 47
          Pixel (1). . . . . . . . . . . . . . . . . . . . . . . . 48
          Pixel (2). . . . . . . . . . . . . . . . . . . . . . . . 48
          Pixel (3). . . . . . . . . . . . . . . . . . . . . . . . 48
          Pixel (4). . . . . . . . . . . . . . . . . . . . . . . . 48
          Saturday 14th. . . . . . . . . . . . . . . . . . . . . . 48
          Shake. . . . . . . . . . . . . . . . . . . . . . . . . . 49
          Sylvia . . . . . . . . . . . . . . . . . . . . . . . . . 49
          Syslock (1). . . . . . . . . . . . . . . . . . . . . . . 49
          Syslock (2). . . . . . . . . . . . . . . . . . . . . . . 49
          Telefon. . . . . . . . . . . . . . . . . . . . . . . . . 50
          Tequila. . . . . . . . . . . . . . . . . . . . . . . . . 50
          Tiny (1) . . . . . . . . . . . . . . . . . . . . . . . . 50
          Tiny (2) . . . . . . . . . . . . . . . . . . . . . . . . 50
          Tiny (3) . . . . . . . . . . . . . . . . . . . . . . . . 51
          Tiny (4) . . . . . . . . . . . . . . . . . . . . . . . . 51
          Tiny (5) . . . . . . . . . . . . . . . . . . . . . . . . 51
          Traceback (1). . . . . . . . . . . . . . . . . . . . . . 51
          Traceback (2). . . . . . . . . . . . . . . . . . . . . . 51
          V512 (1) . . . . . . . . . . . . . . . . . . . . . . . . 52
          V512 (2) . . . . . . . . . . . . . . . . . . . . . . . . 52
          V512 (3) . . . . . . . . . . . . . . . . . . . . . . . . 52
          V512 (4) . . . . . . . . . . . . . . . . . . . . . . . . 52
          Vacsina (4). . . . . . . . . . . . . . . . . . . . . . . 52
          Vacsina (5). . . . . . . . . . . . . . . . . . . . . . . 53
          Vacsina (6). . . . . . . . . . . . . . . . . . . . . . . 53
          Vacsina (16) . . . . . . . . . . . . . . . . . . . . . . 53
          Vacsina (23) . . . . . . . . . . . . . . . . . . . . . . 53
          Vacsina (24) . . . . . . . . . . . . . . . . . . . . . . 54
          Vacsina (25) . . . . . . . . . . . . . . . . . . . . . . 54
          Vacsina (33) . . . . . . . . . . . . . . . . . . . . . . 54
          Vacsina (34) . . . . . . . . . . . . . . . . . . . . . . 54
          Vacsina (38) . . . . . . . . . . . . . . . . . . . . . . 54
          Vacsina (39) . . . . . . . . . . . . . . . . . . . . . . 54
          Vacsina (41) . . . . . . . . . . . . . . . . . . . . . . 55
          Vacsina (42) . . . . . . . . . . . . . . . . . . . . . . 55
          Vacsina (44) . . . . . . . . . . . . . . . . . . . . . . 55
          Vacsina (45) . . . . . . . . . . . . . . . . . . . . . . 55
          Vacsina (46) . . . . . . . . . . . . . . . . . . . . . . 55
          Valert . . . . . . . . . . . . . . . . . . . . . . . . . 55
          Vcomm. . . . . . . . . . . . . . . . . . . . . . . . . . 56
          Victor . . . . . . . . . . . . . . . . . . . . . . . . . 56
          Vienna (1) . . . . . . . . . . . . . . . . . . . . . . . 56
          Vienna (2) . . . . . . . . . . . . . . . . . . . . . . . 56
          Vienna (3) . . . . . . . . . . . . . . . . . . . . . . . 57
          Vienna (4) . . . . . . . . . . . . . . . . . . . . . . . 57
          Vienna (6) . . . . . . . . . . . . . . . . . . . . . . . 57
          Vienna (7) . . . . . . . . . . . . . . . . . . . . . . . 57
          Vienna-Camouflage. . . . . . . . . . . . . . . . . . . . 57
          Yale . . . . . . . . . . . . . . . . . . . . . . . . . . 58
          Zerobug. . . . . . . . . . . . . . . . . . . . . . . . . 58
     9.3  Pseudonyms.. . . . . . . . . . . . . . . . . . . . . . . 59
     9.4  Lengths of Parasitic viruses.. . . . . . . . . . . . . . 61

                    Virus Clean and Virus Monitor 

1  Introduction

     This is an anti-virus package for the IBM PC or compatible
     (including PC/XT, PC/AT or PS/2).

     It is the only such package which will not only recognise known
     PC viruses, but can remove them, prevent infected programs from
     executing, and disable memory-resident viruses without requiring
     a "clean" system disk to boot from.

     It will also warn you about infected floppy disks.

     It consists of two programs:  Virus Clean (VC.COM) & Virus
     Monitor (VM.COM).

2  How to use the programs.

     There are two kinds of viruses on the PC.  Boot viruses infect
     disks, and Parasitic viruses infect program files.  Virus Clean
     and Virus Monitor will recognise and can remove both kinds.

     2.1  Installation

          The simplest way to use these programs is to copy VM.COM
          and VC.COM onto your hard disk, either into the root
          directory or into a directory which is in the PATH= list of
          the AUTOEXEC.BAT.

          If VM.COM is in your root directory, add the command:

               VM

          to your AUTOEXEC.BAT.

          If VM.COM is not in your root directory, the pathname
          should be included.  If, for example, VM.COM is copied into
          the directory UTIL on your C-drive, you would have:

               C:\UTIL\VM

          This will install the Virus Monitor in your system.  Each
          time you start the machine, it will check for
          memory-resident viruses before becoming memory-resident
          itself.  Any that it finds will be reported to you and
          disabled.  Virus Monitor will test every program before it
          is run to see if it is infected.  Infected programs will be
          prevented from executing.  You will also be warned about
          infected disks.
          VM would normally be the first active line of your
          AUTOEXEC.BAT (after ECHO OFF, if you have this line).  This
          will allow Virus Monitor to check all of your programs for
          viruses before execution, including those run from the
          AUTOEXEC.BAT file.


          If you do get any messages from Virus Monitor, you should
          run Virus Clean.  Virus Clean will report any infected
          files or disks, and can either remove the virus or (for
          Parasitic viruses) delete the infected programs if these
          options have been set.

3  Virus Monitor (VM.COM)

     The command format for Virus Monitor is:

          VM   


     3.1  Special Considerations

          There are special problems with networks (e.g. Novell and
          Banyan) and other similar programs (such as Windows Version
          2) as they control the execution of other programs
          themselves instead of allowing DOS to do so.

          If Virus Monitor is loaded before such a program, it will
          not be able to check other programs for viruses.  The
          answer is to load Virus Monitor after the network control
          program but before connecting (logging-on) to the network. 
          If you have any doubts, the program VM_TEST is supplied to
          ensure that Virus Monitor is correctly installed (see
          paragraph 7).

          There are no such problems with Windows Version 3, but
          there is a problem when Windows 3.0 is used in conjunction
          with a Novell Network.  In this situation (which applies to
          any TSR loaded between the Netware and Windows) output to
          the network print spooler will be corrupted.  This has been
          fixed in Windows 3.1.

4  Virus Clean (VC.COM)

     The program can be run in either Menu or Command Line mode.  All
     of the options are available in both modes.

     The default options are those set on the original master disk. 
     These can be changed (see paragraph 5.1.4), but when received
     they should be as illustrated in paragraphs 5.3, 5.4 & 5.5.

     If nothing is entered after the program name, Virus Clean will
     default to Menu mode.  If no other options are required, Virus
     Clean can be run in Command Line mode by specifying the option
     'No Menu' (/N).

5  Menu Mode

     The format for Menu mode is:

          VC

     The menus operate as a single pass preliminary to the operation
     of Virus Clean itself.  The program does not return to the menus
     after scanning a disk or displaying a list of viruses (unless
     this option has been changed by the user).

     Movement within a menu is by the cursor keys (up and down
     arrows, Home and End), or by entering the highlighted letter.

     The Enter key will take you down into the next menu, if there is
     one, or toggle an option between 'Yes' and 'No'.  Escape will
     generally take you to a higher menu while retaining selected
     options.

     Some options (File extensions, Output file & Single drive)
     require additional information to be keyed.  During this input,
     the Enter key will mean 'accept the information as it stands'
     and the Escape key will mean 'discard this information and
     switch the option off again'.

     5.1  The Main Menu

          The choices available from the Main Menu are:

               Choose options
               Scan for viruses
               Return to default options
               Write options to disk (change defaults)
               List known viruses
               Exit to DOS

          5.1.1  Choose options

               This leads to the Option Selection Menu.

          5.1.2  Scan for viruses

               Run the virus scan using the default options as
               modified in paragraph 5.1.1 above (and successive
               menus).

          5.1.3  Return to default options

               Discard any modification to the options made in
               paragraph 5.1.1 above (and successive menus).

          5.1.4  Write options to disk

               Change the Virus Clean program on disk so that the
               options just selected in paragraph 5.1.1 (and
               successive menus) will apply to all future runs.

          5.1.5  List known viruses

               Display a list of the viruses which this version of
               Virus Clean will detect and remove.

          5.1.6  Exit to DOS

               Abandon this run without saving any options which have
               been changed.

     5.2  Option Selection Menu

          The choices available from the Option Selection Menu are:

               Search options
               Removal options
               Other options

          5.2.1  Search options

               This leads to the Search Options Menu.

          5.2.2  Removal options

               This leads to the Removal Options Menu.

          5.2.3  Other options

               This leads to the Other Options Menu.

     5.3  Search Options Menu

          The choices available from the Search Options Menu are:

               Search for Boot viruses                        Yes
               Search for Parasitic viruses                   Yes
               Examine All files                              No
               Examine entered file Extensions                No
               List all files examined                        No

          5.3.1  Search for Boot viruses

               When this option is on Virus Clean will search for
               Boot viruses on any disk which it scans.  The default
               for this option is on.

          5.3.2  Search for Parasitic viruses

               When this option is on Virus Clean will search for
               Parasitic viruses on any disk which it scans.  The
               default for this option is on.

               You will not be allowed to switch off both this option
               and the previous one, as this would leave the program
               with nothing to do.

          5.3.3  Examine All files

               Test every file on the selected disk(s) for viruses
               regardless of its extension name.  Normally Virus
               Clean will only scan those files with an extension of
               COM or EXE.  The default for this option is off.

          5.3.4  Examine entered file Extensions

               Specify the extension names of those files to be
               scanned in addition to COM and EXE.  If this option is
               selected, a further screen will be displayed for entry
               (or modification) of the extension names - up to ten
               may be specified.  The default for this option is off.

               You will not be allowed to select both this option and
               the previous one.

          5.3.5  List all files examined

               If this option is selected the name of each file
               scanned will be displayed irrespective of whether it
               is infected.  The default for this option is off.

     5.4  Removal Options Menu

          The choices available from the Removal Options Menu are:

               Remove Boot viruses from disks                 No
               Remove Parasitic viruses from COM files        No
               Remove Parasitic viruses from EXE files        No
               Delete infected files                          No

          5.4.1  Remove Boot viruses from disks

               When this option is selected, any Boot virus found on
               a scanned disk will be removed.  The default for this
               option is off.

          5.4.2  Remove Parasitic viruses from COM files

               When this option is selected, any Parasitic virus
               found infecting a COM file will be removed from that
               file, provided that the file appears to be undamaged. 
               The default for this option is off.

          5.4.3  Remove Parasitic viruses from EXE files

               When this option is selected, any Parasitic virus
               found infecting a EXE file will be removed from that
               file, provided that the file appears to be undamaged. 
               The default for this option is off.

               WARNING:  It is recommended, for reasons explained in
               paragraph 6.13, that this option be reserved for
               emergency use only.

          5.4.4  Delete infected files

               If this option is selected, any files which are still
               infected after applying any selected removal options
               will be deleted.  The default for this option is off.

               It is recommended that if this option is used the
               Output option (paragraph 5.5.1) should also be
               selected to provide an audit trail.

     5.5  Other Options Menu

          The choices available from the Other Options Menu are:

               Output messages to disk file                   No
               More? - pause when screen is full              No
               Scan a single drive  (C:)                      No
               Return to menu after scan                      No
               Black and white menu display                   No

          5.5.1  Output messages to disk file

               This option will cause all messages displayed on the
               screen (other than those within the Menu system) to be
               duplicated in a disk file.  If this option is
               selected, a further screen will be displayed for entry
               (or modification) of the pathname of the output file. 
               The default for this option is off.

          5.5.2  More? - pause when screen is full

               This option will halt the display of messages to the
               screen when the screen is full.  Display will continue
               after the user hits any key.  The default for this
               option is off.

          5.5.3  Scan a single drive

               This option allows the user to specify which single
               disk is to be scanned.  If this option is not
               selected, Virus Clean will ask which disk to scan next
               until the user signifies (by the Escape key) that the
               run is to be terminated.  If this option is selected,
               a further screen will be displayed for entry of the
               disk letter.  The default for this option is off.

          5.5.4  Return to menu after scan

               This option will bring the program back to the menu
               after scanning the disk.  If this option is not
               selected the program will terminate after scanning for
               viruses or after listing known viruses.  The default
               for this option is off.

          5.5.5  Black and white menu display

               This option will change the menu display from colour
               to black and white.  The default for this option is
               off.

6  Command Line Mode

     The Command Line format for Virus Clean is:

          VC   [d:] [options]
               or
          VC   ? [/M] [/Ofilename]

     ?    =    Generate a list of viruses the program will detect
               (including variants).  All other options invalid
               except /M and output to file.
     d:   =    Scan specified disk only - non-interactive form.  d
               can be any valid drive.

     Options:

     /A                 Search all files.
     /B                 Search for Boot virus only.
     /D                 Delete infected file if virus is not removed.
     /Eextensions       Extension list (extensions to scan in
                        addition to COM & EXE).  e.g. /EOVLBIN will
                        scan for OVL & BIN files.
     /L                 List all files checked by program.
     /M                 More - pause after outputting 23 lines to the
                        display screen.
     /N[D][O]           No menu [No specified disk][No output file]
     /Ofilename         Output all messages to file.  e.g.
                        /OA:\INFECTED.TXT will output to file
                        A:\INFECTED.TXT
     /P                 Search for Parasitic virus only.
     /R[options]        Remove virus.  The options will specify which
                        categories are to be removed.

                        Categories are:

                             B =  Boot (remove Boot virus from disk)
                             C =  COM (remove Parasitic virus from
                                  COM files)
                             E =  EXE (remove Parasitic virus from
                                  EXE files)
                             A =  All (equivalent to BCE)
                             N =  None - do not remove any viruses.

                        If no removal option is specified, the
                        default removal option of Boot & COM
                        (equivalent to /RBC) is used.  Please read
                        the section on removal before using the /RA
                        or /RE options.

     All options are case-insensitive, and '-' can be used instead of
     '/'.  No option may be used more than once, and program will not
     run if an option is not recognised.

     '/A' is incompatible with '/E'.

     6.1  Specifying a Disk.

          If the program is run for a specific disk, no further
          instructions are required from the user.  The disk will be
          checked for viruses, and the program will terminate.  If no
          disk is specified, one will be requested.  After each disk
          is checked, the program will return to request another disk
          until the user presses the Escape key.

     6.2  All.

          This option will make the program check every file whatever
          its extension.

     6.3  Boot Only.

          This option is supplied to allow a number of floppy disks
          to be checked for Boot viruses (and for them to be removed)
          without having to wait while the files on the disks are
          checked.

     6.4  Deletion.

          If deletion of infected files is requested, this takes
          place after any removal option.  In other words an infected
          file will only be deleted if the virus has not been
          removed.

          If you use the delete option, you should also use the
          output file option, so that you have an audit trail of
          which programs have been deleted.

     6.5  Extension list.

          This option allows a list of file extensions (up to ten) to
          be specified for checking.  At least one extension must be
          specified.  These extensions are in addition to COM & EXE,
          and there will be no necessity to repeat them.  i.e. if you
          specify /EOVLBIN, the program will check all files with
          extension of OVL or BIN in addition to files with
          extensions of EXE or COM.

          The space character may be specified in an extension by
          using the substitute character '?'.  Please note that,
          contrary to normal DOS usage, this will only allow a space
          character in that position.

     6.6  List.

          This will produce a list of every file checked by the
          program, whether infected or not.  The full pathname will
          be given for every file listed.

     6.7  More.

          This option causes the program to pause when the screen is
          full until the user responds by pressing a key.  Please
          remember that no processing will be done until the user has
          responded.  The prompt '-More-' will only appear on the
          screen, not in any output file.

     6.8  No Menu

          This option makes the program bypass the menu.  Any command
          line option will have this effect, but this option is
          supplied for those occasions where other options would be
          unnecessary or inappropriate.

     6.9  No Specified Disk

          This option is a sub-function of No Menu.  It is used when
          the default options have been changed to scan a specified
          disk, but on this occasion the user wishes to use the disk
          loop to scan a number of disks in one run.

     6.10  No Output File

          This option is a sub-function of No Menu.  It is used when
          the default options have been changed to specify an output
          file, but on this occasion the user does not wish messages
          to be output to it.

     6.11  Output File.

          If this option is requested, all messages which appear on
          the screen (except '-More-') will also go to the specified
          file.  This will be appended to the file so as to produce a
          cumulative record.

          These messages will show the start date and time of the
          run, and the finish time, as well as the full pathname of
          any infected files

          The program will assume that there is room for the output
          file on the specified disk, and no checking will be done. 
          For this reason it is recommended that the output be
          directed to the hard disk (if possible).

     6.12  Parasitic Only.

          This option is less useful than Boot only, but is supplied
          for compatibility and future development.  Removal or
          deletion will not occur if checksum does not match.

     6.13  Removal.

          Viruses will not be removed unless requested by a removal
          option.  The default removal option is to remove Boot
          viruses from disks and Parasitic viruses from COM files,
          but not Parasitic viruses from EXE files.  COM files can be
          recovered intact from most viruses.  Although most EXE
          files can be recovered, there are a number which can not.

          An EXE file will sometimes have a portion at the end which
          is not loaded by the system when the program is executed. 
          This is usually used as an overlay.  When a program of this
          type is infected, this end portion is overwritten by the
          virus.

          If this end portion is longer than the virus, the EXE file
          will not increase in length as a result of the infection
          and Virus Clean will describe the infected file as
          'damaged'.  Virus Clean will not remove viruses from
          damaged files.

          If the end portion is shorter than the virus, it will not
          be possible to tell if there ever was an end portion before
          infection.  Because the Jerusalem virus infects an EXE file
          more than once, it will eventually overwrite the whole of
          the end portion no matter how long it is.

          For these reasons it is recommended that you do not use the
          option to remove viruses from EXE files unless absolutely
          necessary.  Instead, infected EXE files should be deleted
          and replaced from backup.

          The removal options B, C & E can be combined in any order
          (only once each).  The options A & N cannot be combined
          with any others.  The N option has no effect at the moment,
          but is supplied for future development.

7  VM_TEST

     Because most users do not have access to any actual viruses, it
     is difficult for them to determine whether Virus Monitor has
     been correctly installed.  VM_TEST is supplied for this purpose. 
     VM_TEST is not a virus, and if executed it will not infect other
     programs nor will it hang the machine.

     The Vienna (2) virus will corrupt one in eight COM files without
     infecting them, by overwriting the start of the COM file with
     spaces.  When a COM file has been corrupted in this way it will
     not execute correctly, and cannot be recovered.

     VM_TEST will appear to both VC & VM to have been corrupted in
     this way.  It will be identified by VC as
          "Vienna (2) virus - overwritten"
     and by VM as
          "corrupted by Vienna (2) virus".

8  What the programs do.

     8.1  Integrity Checks

          Each of these programs will perform two integrity checks on
          itself when first loaded.  The first is a check of its own
          length - if this is incorrect the program will issue a
          warning, but will still continue:

               Program is the wrong length, check for virus infection
                      Press any key to continue

          The second is an internal checksum of itself - if this is
          incorrect the program will refuse to continue, and suggest
          loading a replacement copy from backup.  

     8.2  Memory Checks

          Each of these programs will check RAM for any
          memory-resident viruses.  Any that are found will be
          disabled.  This means that although the virus will still be
          in memory, it will not be able to function as a virus any
          more.

          If no virus is found in RAM memory, the following messages
          will be displayed:

               No Boot virus found in system
               No Parasitic virus found in system

          If a virus is found, one or other of the above messages
          will be replaced by a message in the form:

               *** System is infected by Jerusalem (1A) virus ***
                 It has been disabled

          If this is the second time this session that one of the
          programs is run, the following will appear instead:

               *** System is infected by Jerusalem (1A) virus ***
                 It was already disabled - no action taken

     8.3  Virus Monitor

          Virus Monitor is a memory resident program which will not
          allow an infected program to be executed.  It does this by
          examining each program before DOS loads it.  If the program
          is found to be infected, a warning message will be
          displayed (with an audible alarm) and execution is stopped
          without affecting any other currently executing program. 
          There will be no appreciable performance degradation.

          The message produced is in the following form:

                    ****    V I R U S    A L E R T    ****
               Program:  C:\DATA\VIRUS\INFECT\TESTJR1A.COM
               Program is infected by one of the Jerusalem viruses
                      Press any key to continue

          After a key has been pressed as acknowledgement of the
          message, the system message:

               Access denied

          is displayed.

          Virus Monitor also examines the boot sector of any floppy
          disk accessed by the system, and will produce a warning
          message if any known Boot virus exists on the disk.  This
          will not prevent access to the disk.

          The message produced is in the following form:

                    ****    V I R U S    A L E R T    ****
               Disk is infected by New Zealand (2) virus
                      Press any key to continue

          Normal access of the infected disk will continue after a
          key has been pressed as acknowledgement.

          Virus Monitor will also block any low-level formatting of a
          hard disk, displaying the following message:

                    ****    V I R U S    A L E R T    ****

             ͻ
                 A low level format to the hard disk    
                has just been intercepted and stopped.  
                      Press any key to continue.        
             ͼ

          Virus Monitor uses approximately 6K of memory (including
          the Program Segment Prefix), so is unlikely to create a
          problem for most users.

          The identification of viruses is not so precise in Virus
          Monitor as it is in Virus Clean (apart from the checks for
          memory-resident viruses), because Virus Monitor will not
          attempt to remove them.  A warning from Virus Monitor is a
          signal to run Virus Clean.

     8.4  Virus Clean.

          If the program is run interactively (no drive specified),
          the following prompt will be displayed after RAM memory has
          been checked:

               Enter drive letter, or Escape to exit: 

          Each clean disk will produce the following messages:

               No Boot virus found on disk
               No Parasitic virus found on disk

          A disk infected by a Boot virus will, instead of the first
          message, show one in the form:

               Disk is infected by New Zealand (2) virus

          For Parasitic viruses, messages are in the form:

               A:\TSTEJR1A.EXE    Jerusalem (1A) virus - infected

          This identification line will be followed, if appropriate,
          by an action line such as:

                 Virus removed

               or

                 Program deleted

          If there is a reason why the requested removal cannot be
          done, this will be explained in the action line:

                 File overwritten - Virus not removed

               or

                 File is wrong length - Virus not removed

          If removal or deletion is attempted on a write-protected
          floppy disk, the program will only attempt to remove or
          delete the first virus it finds.  An error message will be
          displayed, and infected files will only be listed for the
          remainder of that disk.

     8.5  New variants

          Virus Clean will not attempt to remove, delete or alter a
          virus which it does not completely recognise.  This is
          because it is not safe to assume that a new variant can be
          removed in the same way as a familiar one.

          All identified viruses are checksummed, and the result is
          compared with that expected from the known variants.  If a
          virus is identified, but does not pass this final test,
          Virus Clean will show the following message:

             ͻ
                  Virus appears to be a new variety.    
                  It will not be modified or removed.   
                      Please keep a copy of the         
                    infected file or disk for us.       
             ͼ

          If you are not sure how to do this, we will be pleased to
          advise you.

          In return we will supply, free of charge, a copy of the
          program which will deal with this new variant.

     8.6  Return codes

          Both Virus Clean and Virus Monitor generate a return code
          which will give information about the types of viruses
          found (if any).  The following values are added together to
          produce the final figure:

               1 - Boot virus found in memory
               2 - Parasitic virus found in memory
               4 - Boot virus found on disk (Virus Clean only)
               8 - Parasitic virus found on disk (Virus Clean only)

          These return codes are most useful when running the program
          from a batch file for a specific disk.

          A return code of 16 indicates a fatal error of some kind
          (e.g. invalid option, cannot open output file, program
          corrupt, etc.).

     8.7  Updates

          Updates will normally be issued quarterly, although there
          will be occasions when there is an over-riding need for a
          special update.

          It is expected that code to deal with new viruses will be
          incorporated into the programs within a few weeks of their
          discovery. 

          Each program will, on request, supply a list of the viruses
          (including variations) which it can recognise.


9  The Viruses.

     9.1  Virus names.

          The names assigned to viruses tend to be arbitrary and
          confusing.  They usually relate to the place or country of
          discovery, a name or message included by the author, or the
          description of an observed feature.  Unless the virus has
          been widely reported it is likely to be given a new name
          with each new occurrence.

          To add to the confusion there was at one time an attempt to
          name Parasitic viruses after their infective lengths.  This
          was supposed to be more scientific, and to not 'glamorise'
          viruses by giving them names.  The obvious drawbacks are
          that numbers are more difficult to remember, that the
          infective length can vary with the file type of the host
          program (and often changes with new variants), and that new
          viruses are starting to appear with the same lengths as
          already known but unrelated ones.  Thankfully this fashion
          seems to be dying out.

          It is unlikely that there will ever be universal agreement
          on names, as individuals have a personal stake in those
          names they first encountered (or have personally assigned). 
          Another factor is that some anti-virus packages like to
          include as many virus names as possible regardless of how
          trivial the differences. 

          We have decided to adopt a new strategy of using only
          'family' names for viruses.  We will use what seems to be
          the most acceptable name for the first virus in any
          recognisable chain of development to describe all the
          variants of that family.

          As long as there is only one virus in such a family, the
          virus name will be the same as the family name.  As
          variants appear they will be assigned numbers (for major
          variants) or letters (for minor variants).

          Normally the first virus in a family will be given the
          number (1), unless the second such virus appears to be an
          earlier version.  Once numbers have been assigned to the
          first two versions, new family members will receive the
          next consecutive number regardless of any apparent
          historical sequence.

          Thus the Jerusalem virus becomes Jerusalem (1A) because it
          has a number of minor variants with the same length, and
          these will be Jerusalem (1B), (1C), etc.  Fu Manchu, as the
          first major variant, is now Jerusalem (2).  Jerusalem is a
          special case because it has three known precursors,
          sometimes referred to as the 'Suriv' viruses from their
          signatures.  We will refer to these as Jerusalem (S1), (S2)
          and (S3) because it could cause more confusion to give them
          later numbers.

          Another special case is the sequence including Vacsina and
          Yankee Doodle.  These are already part of a recognisable
          numbered sequence, and so we will refer to them by their
          version numbers (e.g. Vacsina (5) and Vacsina (44)).

          In the following lists we will give short descriptions and
          pseudonyms for our names, and this will be followed by an
          reference list of pseudonyms and of lengths.

          It should be noted that pseudonyms often relate to a
          particular minor variant.


    9.2  List of viruses.

     405 (Parasitic - non-resident, overwriting)

          Length: 405
          Pseudonyms: 
          Infects: COM files only

               Virus occurs overwriting the first 405 bytes of a COM
               file.  The virus will attempt to infect one COM file
               on a different disk to the current one.  If the length
               of the file to be infected is less than 405 bytes, the
               length will be increased to 405.  Due to mistakes in
               the code it is not able to infect other than in the
               current directory, nor is it able to recognise an
               infected file.

     Aircop (Boot - floppy only)

          Length:  1 sector on disk, 1K in memory
          Pseudonyms: 

               Similar to Yale.  The original boot sector is held at
               track thirty-nine, head one, sector nine.  Infects
               when the directory of the floppy disk is read, and
               after eight infections it displays the message:

                   .RED STATE, Germ offensing  --Aircop

     Alabama (Parasitic - resident)

          Length: 1408
          Pseudonyms: 
          Infects: EXE files only

     Anticad (1) (Parasitic - resident)

          Length: 2900
          Pseudonyms: Plastique
          Infects: COM and EXE files

               This virus is a variant of Jerusalem, but sufficiently
               different to constitute a new family.  It infects when
               a program is executed and also (like Dark Avenger)
               when a file is opened.  When the virus becomes memory
               resident it either installs a timer delay routine or a
               music routine.  The music routine activates after five
               minutes and plays a tune which has not yet been
               identified.  If ACAD.EXE is executed, the first two
               floppy disks and the first two hard disks are
               overwritten, followed by the CMOS.  If Ctrl-Alt-Del is
               pressed after the first five minutes this will also
               activate the disk overwriting routine, unless the
               music routine has been installed - in which case only
               the CMOS is overwritten.

     Anticad (2) (Parasitic - resident)

          Length: 4096
          Pseudonyms: Plastique
          Infects: COM and EXE files

               Very similar to Anticad (1)

     Anticad (3) (Parasitic - resident)

          Length: 4096
          Pseudonyms: Plastique, Invader
          Infects: COM and EXE files

               Very similar to Anticad (1)

     Anticad (4) (Parasitic - resident)

          Length: 3012
          Pseudonyms: Plastique
          Infects: COM and EXE files

               Very similar to Anticad (1)

     Anticad (5) (Parasitic - resident)

          Length: 3004
          Pseudonyms: Plastique
          Infects: COM and EXE files

               Very similar to Anticad (1)

     Antipascal (1) (Parasitic - non-resident)

          Length: 605
          Pseudonyms: 
          Infects: COM files only

               A virus targetted at Pascal source programs.

     Antipascal (2) (Parasitic - non-resident)

          Length: 529
          Pseudonyms: 
          Infects: COM files only

               Very similar to Antipascal (1).

     Antipascal (3) (Parasitic - non-resident)

          Length: 480
          Pseudonyms: 
          Infects: COM files only

               Very similar to Antipascal (1).

     Antipascal (4) (Parasitic - non-resident)

          Length: 440
          Pseudonyms: 
          Infects: COM files only

               Very similar to Antipascal (1).

     Antipascal (5) (Parasitic - non-resident)

          Length: 400
          Pseudonyms: 
          Infects: COM files only

               Very similar to Antipascal (1).

     Azusa (Boot - master boot sector)

          Length:  1 sector on disk, 1K in memory
          Pseudonyms: 

               After the thirty-second boot from an infected disk,
               this virus disables the COM1 & PRT1 output addresses. 
               The master boot sector on a hard disk must be
               reconstructed rather than replaced, as the virus does
               not preserve it.

     Brain (1) (Boot - floppy only)

          Length:  6 sectors on disk, 7K in memory
          Pseudonyms: Pakistani Brain

               This virus consists of a boot sector and three
               clusters (6 sectors) marked as bad in the FAT.  The
               first of these sectors contains the original boot
               sector, and the rest contain the rest of the virus. 
               It only infects 360K floppies.  It creates a label on
               an infected disk of ' (c) Brain '.  It leaves room on
               the disk for the system files.

     Brain (2) (Boot - floppy only)

          Length:  6 sectors on disk, 7K in memory
          Pseudonyms: Ashar

               This virus consists of a boot sector and three
               clusters (6 sectors) marked as bad in the FAT.  The
               first of these sectors contains the original boot
               sector, and the rest contain the rest of the virus. 
               It only infects 360K floppies.  It creates a label on
               an infected disk of ' (c) ashar '.  Does not leave
               room for the system files.

     Brain (3) (Boot - floppy only)

          Length:  6 sectors on disk, 7K in memory
          Pseudonyms:

               This virus is very similar to Brain (1), but does not
               create a disk label.  Instead it wipes out the first
               121 sectors of the hard disk (including the partition
               table and the FAT) in such a way that this area of the
               disk will need to be reformatted.

     Burger (Parasitic - non-resident)

          Length: 
          Pseudonyms: Virdem
          Infects: COM files only

               A family of viruses springing from the demonstration
               virus Virdem, written by Ralf Burger.  Most of them
               will only infect on the A-drive (like Virdem itself).

     Cascade (1) (Parasitic - resident)

          Length: 1701
          Pseudonyms: Fall, Russian
          Infects: COM files only

               The virus occurs attached to the end of a COM file. 
               The first three bytes of the program are stored in the
               virus, and replaced by a branch to the beginning of
               the virus.  The virus is encrypted (apart from the
               first 35 bytes) using an algorithm that includes the
               length of the host program, so every sample looks
               different.  It becomes memory-resident when the first
               infected program is run, and it will then infect every
               COM file run (even if the file has an EXE extension). 
               If the system date is between October and December
               1988 the cascade display will be activated at random
               intervals.  Because recognition depends on the length
               of the virus, it will infect programs already infected
               by variants with different lengths.

     Cascade (2) (Parasitic - resident)

          Length: 1704
          Pseudonyms: Fall, Blackjack
          Infects: COM files only

               Same as Cascade (1), apart from difference in length.

     Cascade (3) (Parasitic - resident)

          Length: 1704
          Pseudonyms: 
          Infects: COM files only

               Same as Cascade (2), but has been modified, without
               recompiling, to format the hard disk.  The formatting
               routine from Datacrime (1) has been written over the
               cascade display, and the activation routine changed to
               1st October to 31st December, any year except 1993. 
               Formatting will be after a random interval, maximum 5
               minutes.

     Dark Avenger (1) (Parasitic - resident)

          Length: 1800
          Pseudonyms: Eddie
          Infects: COM and EXE files

               Infects when a file is opened, so an unsophisticated
               scan program will spread this virus to every program
               examined.

     Dark Avenger (2) (Parasitic - resident)

          Length: 2000
          Pseudonyms: 
          Infects: COM and EXE files

               Similar to Dark Avenger (1), but a directory listing
               will show the uninfected length.  Can bypass most
               forms of access control when reading from a disk.

     Dark Avenger (3) (Parasitic - resident)

          Length: 2100
          Pseudonyms: 
          Infects: COM and EXE files

               Similar to Dark Avenger (2), but slightly better at
               hiding itself.

     Datacrime (1) (Parasitic - non-resident)

          Length: 1280
          Pseudonyms: 
          Infects: COM files only

               The virus occurs attached to the end of a COM file. 
               The first three bytes of the program are stored in the
               virus, and replaced by a branch to the beginning of
               the virus.  The virus will search through full
               directory structure of the disks (in the order C, D,
               A, B) for a COM file other than COMMAND.COM.  It will
               also ignore any COM file if the 7th letter of the name
               is a D.  If the date is after 12 October (any year) it
               will display the message:

                   DATACRIME VIRUS
                   RELEASED: 1 MARCH 1989

               and do a low level format on track zero, all heads, of
               the hard disk.  The message is encrypted.  There is an
               error in the way the format table is addressed, and
               there are several mistakes in the code involving the
               critical error handler.

     Datacrime (2) (Parasitic - non-resident)

          Length: 1168
          Pseudonyms: 
          Infects: COM files only

               Same as Datacrime (1), apart from difference in
               length.

     Datacrime (3) (Parasitic - non-resident)

          Length: 1480
          Pseudonyms: Datacrime II
          Infects: COM and EXE files

               This version is much the same as Datacrime (1), but it
               will now infect EXE files as well.  The virus is
               encrypted except the first 42 bytes, and the message
               is separately encrypted.  The message is now:

                   DATACRIME II VIRUS

               It will ignore any file if the 2nd letter of the name
               is a B.  The addressing of the format table has been
               corrected.

     Datacrime (4) (Parasitic - non-resident)

          Length: 1514
          Pseudonyms: Datacrime II
          Infects: COM and EXE files

               This version is much the same as Datacrime (3).  The
               virus is encrypted except the first 56 bytes, but the
               message is no longer separately encrypted.  Code has
               been added to the encryption routine to prevent
               single-stepping.  The message is now:

                   * DATACRIME II VIRUS *

     Den Zuk (Boot - floppy only)

          Length:  9 sectors on disk, 7K in memory
          Pseudonyms: Search

               Main body of virus is kept on a specially formatted
               track 40, head zero, sectors 33 to 41.  Graphics
               display of 'DEN ZUK', together with what looks like
               the AT&T logo, slides in from the sides of the screen
               when Crtl-Alt-Del is pressed.  Display is not done if
               KEYBUK or KEYB is installed.

     Devil's Dance (Parasitic - resident)

          Length: 941
          Pseudonyms: 
          Infects: COM files only

               The virus infect every COM file in the current
               directory, then becomes memory-resident and infects
               every COM file executed.  It monitors the keyboard,
               and ten keystrokes after infection it starts changing
               the display attributes.  When Ctrl-Alt-Del is pressed,
               the following messages are displayed:

                   Have you ever danced with the devil under the weak
                   light of the moon?
                   Pray for your disk!
                   The_Joker...
                   Ha Ha Ha Ha Ha Ha Ha Ha Ha Ha 

               These messages will only be visible if you have an odd
               number of floppy disk drives (or an even number and an
               MDA display).  After the messages, the boot sector of
               the hard disk will be overwritten if the number of
               keystrokes since infection exceeds 5000.

     Disk Killer (Boot - DOS boot sector)

          Length:  5 sectors on disk, 8K in memory
          Pseudonyms: Ogre

     EDV (Boot - master boot sector)

          Length:  1 sector on disk
          Pseudonyms:

               Similar to Yale, but infects hard disks as if they
               were floppies.  Stores the original boot sector at
               track 39, head one, sector eight.  This overwrites
               data on a hard disk.  A read to the boot sector is
               diverted to this location by the virus.  An infected
               hard disk will be inaccessible unless the virus is
               resident in memory.  Does not alter the apparent size
               of memory.

     Form (Boot - DOS boot sector)

          Length:  2 sectors on disk, 2K in memory
          Pseudonyms:

               Very similar to Italian (1), but no display.  Beeps
               every time a key is pressed if the date is the 24th of
               the month.

     Green Caterpillar (Parasitic - resident)

          Length: 1575
          Pseudonyms: 
          Infects: COM & EXE files

               The display is only performed if the file infecting
               the system was infected three months or more
               previously.  A Green Caterpillar moves along each line
               of the screen and transfers anything already there
               back by ten columns, changing the attributes to yellow
               on black.

     Hacker (1) (Parasitic - resident)

          Length: 1154
          Pseudonyms: 
          Infects: COM & EXE files

     Hacker (2) (Parasitic - resident)

          Length: 1158
          Pseudonyms: 
          Infects: COM & EXE files

     Hacker (3) (Parasitic - resident)

          Length: 1610
          Pseudonyms: 
          Infects: COM & EXE files

     Hacker (4) (Parasitic - resident)

          Length: 1776
          Pseudonyms: 
          Infects: COM & EXE files

     Hacker (5) (Parasitic - resident)

          Length: 1576
          Pseudonyms: 
          Infects: COM & EXE files

     Hacker (6) (Parasitic - resident)

          Length: 1594
          Pseudonyms: 
          Infects: COM & EXE files

     Hacker (7) (Parasitic - resident)

          Length: 1154
          Pseudonyms: 
          Infects: COM & EXE files

     Hidden (1) (Parasitic - resident)

          Length: 4096
          Pseudonyms: 4K, IDF, Century, Frodo
          Infects: COM & EXE files

               Virus hides the fact that programs are infected by
               intercepting DOS service calls.  The length and the
               contents of infected files will be apparently
               unchanged and pass any test such as check-summing.

     Hidden (2) (Parasitic - resident)

          Length: 3584
          Pseudonyms: Fish 6
          Infects: COM & EXE files

               Similar in effect to Hidden (1).  On any date after
               the start of 1991 it will display the message:

                   FISH VIRUS #6 - EACH DIFF - BONN 2/90 '~knzyvo}'

               whenever a program requests the system date from DOS. 
               After the message a halt is issued.  The virus is
               encrypted, and it is encrypted in a different way in
               memory.

     Horse (Boot - master boot sector)

          Length:  1 sector on disk, 1K in memory
          Pseudonyms: 

               Cross between New Zealand and Yale.  The original boot
               sector is held at track thirty-nine head one sector
               nine on a floppy, and track zero head zero sector
               seven on a hard disk.

     Icelandic (1) (Parasitic - resident)

          Length: 656
          Pseudonyms: 
          Infects: EXE files only

               The virus occurs attached to the end of an EXE file. 
               One in ten EXE files will be infected when executed. 
               When a program is infected the disk is examined.  If
               it is a hard disk of more than 20 meg one cluster is
               marked as bad in the first copy of the FAT.  This
               cluster will be the last free entry.  Unused space on
               the last cluster of the FAT will be assumed to be
               valid entries.  Signature is hex string 18H, 44H, 19H,
               5FH in last four bytes of virus.  Virus will not
               infect system unless INT 13H segment is 0700H or
               0F000H.

     Icelandic (2) (Parasitic - resident)

          Length: 642
          Pseudonyms: Saratoga
          Infects: EXE files only

               Saratoga variant.  One in two EXE programs loaded are
               infected.  Signature is now 'PooT'.  Check on INT 13H
               system has been removed.

     Icelandic (3) (Parasitic - resident)

          Length: 632
          Pseudonyms: 
          Infects: EXE files only

               As for Icelandic (1) except:  Check on INT 13H system
               has been removed, as has FAT processing.  Virus finds
               entry point of INT 21H, all DOS service calls are by
               far calls instead of interrupts.

     Icelandic (4) (Parasitic - resident)

          Length: 1618
          Pseudonyms: Mix1
          Infects: EXE files only

     Icelandic (5) (Parasitic - resident)

          Length: 848
          Pseudonyms: December 24th
          Infects: EXE files only

               Prevents programs from executing on December 24 -
               instead it displays a message saying "Merry Christmas"
               (in Icelandic).

     Italian (1) (Boot - DOS boot sector)

          Length:  2 sectors on disk, 2K in memory
          Pseudonyms: Ping Pong

               This virus consists of a boot sector and 1 cluster (2
               sectors used) marked as bad in the first copy of the
               FAT.  The first of these sectors contains the rest of
               the virus, and the second contains the original boot
               sector.  It infects all disks which have at least two
               sectors per cluster, and it occupies 2K of memory.  It
               displays a single character 'bouncing ball' which
               interacts with some characters on the screen.  It will
               not run on an 80286 or an 80386 machine.

     Italian (2) (Boot - DOS boot sector)

          Length:  2 sectors on disk, 2K in memory
          Pseudonyms: Mistake, Typo, Swap

               Very similar to Italian (1), but instead of the
               bouncing ball routine it monitors output to the
               printer.  Every 50th character, it will start checking
               for one of the characters on its list, and change this
               for the alternate (eg "C" for "K" or "G" for "J" and
               vice versa).  Escape sequences are allowed to pass
               unchanged (provided they are no more than six
               characters).


     Italian (3) (Boot - floppy only)

          Length:  2 sectors on disk, 2K in memory
          Pseudonyms: Ghostballs

               This is not really a virus because it does not infect. 
               It has the has activation routine and display as
               Italian (1), but infection is only performed by the
               Vienna (3) virus.

     Italian (4) (Boot - DOS boot sector)

          Length:  2 sectors on disk, 2K in memory
          Pseudonyms: Big Italian

               Very similar to Italian (1), but will infect 80286 &
               80386 machines.

     Jerusalem (S1) (Parasitic - resident)

          Length: 897
          Pseudonyms: April 1st
          Infects: COM files only

               The virus is written to the beginning of the file. 
               Date is checked on infection.  If date is 1st April,
               virus produces the message:

                   APRIL 1ST HA HA HA YOU HAVE A VIRUS

               and the machine locks.  If date is after 1st April
               1988, virus produces the message:

                   YOU HAVE A VIRUS !!!

               but no machine locking occurs.  Identifying string is
               'sURIV 1.01'.

     Jerusalem (S2) (Parasitic - resident)

          Length: 1488
          Pseudonyms: April 1st
          Infects: EXE files only

               Similar to Jerusalem (S1).  The virus is written to
               the beginning of the file after the relocation table. 
               If date is 1st April, virus produces the message:

                   APRIL 1ST HA HA HA YOU HAVE A VIRUS

               and the machine locks.  Additionally, machine locks
               one hour after infection if default year of 1980 is
               used, or day is Wednesday after 1st April 1988. 
               Identifying string is 'sURIV 2.01'.

                                   
     Jerusalem (S3) (Parasitic - resident)

          Length: 1808
          Pseudonyms: 
          Infects: COM and EXE files

               This is almost the same as the later Jerusalem (1). 
               Differences are: The string 'sUMsDos' in the type
               version is 'sURIV 3.00' in this version, the 30 minute
               delay is here 30 seconds, and there is a bug in the
               program delete.  'sURIV' is written to the end of
               infected COM files.

     Jerusalem (1) (Parasitic - resident)

          Length: 1808
          Pseudonyms: Israeli, PLO, Friday the 13th, Black Hole
          Infects: COM and EXE files

               The virus occurs attached to the beginning of a COM
               file, or the end of an EXE file.  A COM file also has
               the five-byte 'marker' attached to the end.  This
               marker is usually (but not always) 'MsDos', and is
               preceded in the virus by 'sU'.  COM files increase in
               length by 1813 bytes.  EXE files usually increase by
               1808 bytes, but the displacement at which to write the
               virus is taken from the length in the EXE header and
               not the actual length.  This means that part or all of
               this 1808 bytes may be overwritten on the end of the
               host program.  It becomes memory-resident when the
               first infected program is run, and it will then infect
               every program run except COMMAND.COM.  COM files are
               infected once only, EXE files are re-infected each
               time they are run. After the system has been infected
               for thirty minutes an area of the screen from row 5
               column 5 to row 16 column 16 is scrolled up two lines
               creating a black two line 'window'.  From this point a
               time-wasting loop is executed with each timer
               interrupt.  If the system was infected with a system
               date of Friday the thirteenth, every program run will
               be deleted instead.  This will continue irrespective
               of the system date until the machine is rebooted.  The
               end of the virus, from offset 0600H, is rubbish and
               will vary from sample to sample.  There is a minor
               version called Anarkia which does not display the
               black window.

     Jerusalem (2) (Parasitic - resident)

          Length: 2080
          Pseudonyms: Fu Manchu
          Infects: COM and EXE files

               The virus occurs attached to the beginning of a COM
               file, or the end of an EXE file.  It is a rewritten
               version of the Jerusalem (1) virus.  The marker is now
               'rEMHOr' (six bytes), and the preceding 'sU' is now
               'sAX' (Sax Rohmer - creator of Fu Manchu).  COM files
               increase in length by 2086 bytes & EXE files 2080
               bytes.  EXE files are only infected once.  One in
               sixteen times on infection a timer is installed which
               runs for a random number of half-hours (maximum 7.5
               hours).  At the end of this time the message:

                   The world will hear from me again!

               is displayed in the centre of the screen and the
               machine reboots.  This message is also displayed every
               time Ctrl-Alt-Del is pressed on an infected machine,
               but the virus does not survive the reboot.  There is
               further code which activates on or after the first of
               August 1989.  This monitors the keyboard buffer, and
               makes derogatory additions to the names of politicians
               (Thatcher, Reagan, Botha & Waldheim), censors out two
               four-letter words, and to 'Fu Manchu ' adds 'virus
               3/10/88 - latest in the new fun line!'  All these
               additions go into the keyboard buffer, so their effect
               is not restricted to the VDU.  All messages are
               encrypted.

     Jerusalem (3) (Parasitic - resident)

          Length: 1631
          Pseudonyms: Sunday
          Infects: COM and EXE files

               This is also a variation of Jerusalem (1).  The
               five-byte marker is attached to the end of both COM
               and EXE files.  The timer routine is only installed if
               the day is Sunday.  Instead of the black 'window' and
               the machine slowing down, the following message is
               displayed:

                   Today is SunDay! Why do you work so hard?
                   All  work and no play make you a dull boy!
                   Come on ! Let's go out and have some fun!

               Any programs run on a Sunday are deleted.

     Jerusalem (4) (Parasitic - resident)

          Length: 1808
          Pseudonyms: Anarkia 2
          Infects: COM and EXE files

               This is a minor variation of Jerusalem (1).  Program
               deletion is on Tuesday the 13th, and both the black
               window and the program deletion will be disabled
               during 1992.

     Jerusalem (5) (Parasitic - resident)

          Length: 1715
          Pseudonyms: PSQR
          Infects: COM and EXE files

               Another variation of Jerusalem (1).  The five-byte
               marker is attached to the end of both COM and EXE
               files.  There is no timer routine.  Any programs run
               on the 13th of ANY month are deleted, and the first
               track of the hard disk is over-written.  The string
               'COMMAND.COM' (used to exclude that file from
               infection) is encrypted.

     Jerusalem (6) (Parasitic - resident)

          Length: 1808
          Pseudonyms: Frere Jacques
          Infects: COM and EXE files

               Similar to Jerusalem (1), but without the black window
               display and the program deletion.  Instead the program
               plays a peculiarly discordant version of Frere Jacques
               every twelve and a half minutes on Friday the
               thirteenth.

     Jerusalem (7) (Parasitic - resident)

          Length: 1716
          Pseudonyms: Slow
          Infects: COM and EXE files

               Similar to Jerusalem (1), but without the black window
               display and the program deletion.  The virus is
               encrypted and the main data area is encrypted
               separately.  On any Friday from 1991 onwards, the
               virus will set the time to zero of half the files
               examined or created.

     Jerusalem (8) (Parasitic - resident)

          Length: 1487
          Pseudonyms: Subliminal
          Infects: COM files only

               Similar to Jerusalem (1), but will only infected
               genuine COM files with a COM extension.  The signature
               is nine bytes.  Displays 'LOVE, REMEMBER?' on the
               screen, and removes it again too quickly for it to be
               seen on most machines.  It contains three unreferenced
               encrypted strings which decrypt to:

                   SUBLIMINAL V1.10
                   ^HYSTERIA!
                   02OCT89

     Jerusalem (9) (Parasitic - resident)

          Length: 1991
          Pseudonyms: Solano, Dyslexia
          Infects: COM files only

               Very similar to Jerusalem (8).  After a delay of four
               minutes, it will check a random screen location
               approximately every half minute for two consecutive
               numbers.  If found they will be transposed.  The
               encrypted strings now decrypt to:

                   DYSLEXIA V2.01
                   ^HYSTERIA!
                   08FEB90

     Jerusalem (10) (Parasitic - resident)

          Length: 1600
          Pseudonyms: Solomon, Antiscan
          Infects: COM and EXE files

               Similar to Jerusalem (1), but without the black window
               display and the program deletion.  This virus is
               targeted at one of the programs in the S&S Toolkit
               (TRYOUT.EXE) - if this program is run while the virus
               is active, any writes to the A-drive are redirected to
               the first hard disk.  The five-byte marker is the old
               S&S phone number in packed decimal format.

     Jerusalem (11) (Parasitic - resident)

          Length: 1558 (1840 on COM)
          Pseudonyms: IPX
          Infects: COM and EXE files

               Similar to Jerusalem (1), but without the black window
               display and the program deletion.  Will only infect if
               Novell Netware appears to be installed.  Attempts to
               send details of successful logons to its own socket
               number, but the code contains too many mistakes for
               this to be successful.  One peculiarity is that the
               virus length includes a stack area when infecting COM
               files but not EXE files.

     Jerusalem (12) (Parasitic - resident)

          Length: 1899
          Pseudonyms: PcVrsDs, Irish
          Infects: COM and EXE files

               Similar to Jerusalem (1), but without the black window
               display and the program deletion.  Virus is encrypted. 
               Formats first thirty-two tracks of the hard disk if
               date is Monday the twenty-third (any month, any year
               except 1990).

     Joshi (Boot - master boot sector)

          Length:  8 sector on disk, 6K in memory
          Pseudonyms: 

               If the date is 5th of January this virus forces the
               user to type "Happy birthday Joshi" every time the
               system allocates or releases memory, or check or
               changes the date or time.                             

     June 16th (Parasitic - non-resident)

          Length: 879
          Pseudonyms: 
          Infects: COM files

               Infects every COM file on the current disk.  Virus
               goes in front of the file.  If the file is shorter
               than the virus, it increases the length of the file to
               that of the virus before infection.  On June 16th the
               name of every entry in the root directory (including
               deleted files) is changed to "ZAPPED     ".

     Kennedy (Parasitic - non-resident)

          Length: 333
          Pseudonyms: 
          Infects: Only COM files which start with a jump

               On 6 June, 18 November & 22 November it displays the
               message:

                   Kennedy er dod - lange leve "The Dead Kennedys"

               Otherwise it infects one COM file in the current
               directory.

     Keypress (Parasitic - resident)

          Length: 1216
          Pseudonyms: 
          Infects: COM & EXE files

               For DOS version 3 or later this virus infects when a
               program is executed, but for earlier versions it
               infects when a program file is opened.  Generates
               keyboard interrupts for two seconds every ten minutes. 
               If a key is pressed during this period it will be
               repeated.

     Lehigh (Parasitic - resident)

          Length: 555
          Pseudonyms: 
          Infects: COMMAND.COM only

               Infects only COMMAND.COM, where it overwrites the
               stack space.  No check is made to see if memory is
               already infected.  Identifying string is hex 65 A9 as
               last two bytes of file.  If a disk which contains an
               uninfected copy of COMMAND.COM in the root directory
               is accessed, that copy is also infected.  A count of
               infections is kept within each copy of the virus, and
               when this count reaches 4 the current disk is trashed
               each time a disk is infected.

               If the current disk is either the A-drive or the
               B-drive, then, to be trashed:

               a.  The disk just infected must be either the A-drive
                   or the B-drive.

               b.  The disk just infected must not be the current
                   drive.  

               This trashing is done by overwriting the first
               thirty-two sectors following (but not including) the
               boot sector with part of the BIOS, and is accompanied
               by a display of another part of the BIOS.  Infection
               changes the date and time of the infected file.  If a
               floppy with an uninfected COMMAND.COM is
               write-protected, there will be a 'WRITE PROTECT ERROR'
               message from DOS.

     New York (1) (Parasitic - part resident)

          Length: 867
          Pseudonyms: Typo RMG
          Infects: COM files only

               This is the only known virus which has a
               memory-resident routine without the whole virus
               becoming memory-resident.  Typed characters are
               occasionally changed to the character to the right of
               them on the keyboard.  This only happens if they are
               removed from the keyboard buffer at faster than nine
               per second.

     New York (2) (Parasitic - resident)

          Length: 1864
          Pseudonyms: Dbase
          Infects: COM files only

               Any file with a DBF extension which is opened has each
               pair of bytes throughout the file reversed.  The files
               full pathname is added to the file BUG.DAT, which is
               created in the root directory.  Any read from a DBF
               file is restored to its normal condition in the
               buffer.  The hard disk is trashed if the creation
               month of the BUG.DAT file is three months or more
               different from the current one - no allowance is made
               for the end of year.

     New Zealand (1) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: 

               This virus consists of a boot sector only.  The
               original boot sector is held in track zero, head one,
               sector three on a floppy disk, and track zero head
               zero, sector two on a hard disk.  The boot sector
               contains two character strings:

                   Your PC is now Stoned!
                   LEGALISE MARIJUANA!

               The first of these is only displayed one in eight
               times when booting from an infected floppy, the second
               is unreferenced.

     New Zealand (2) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Stoned, Marihuana

               Very similar to New Zealand (1).  Much of the code has
               been reorganised.  The only significant change is that
               the original boot sector is stored at track zero, head
               zero, sector seven on a hard disk.  There are now
               minor variants with different messages.

     New Zealand (3) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Korean

               This may be the original New Zealand virus.  There is
               no message.  The original boot sector is held in track
               zero, head one, sector three on all disks.  On a
               standard hard disk this will overwrite the second
               sector in the first copy of the FAT.

     New Zealand (4) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Sex Revolution

               Very similar to New Zealand (2).  The original boot
               sector is stored at track zero, head zero, sector
               eight on a hard disk.  Boot message is:

                   'EXPORT OF SEX REVOLUTION ver. 2.0'

     New Zealand (5) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Rostov

               Very similar to New Zealand (2).  No boot message.

     New Zealand (6) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Zapper

               Very similar to New Zealand (2).  Boot message is:

                   'I ZAPPED YOU!'

     New Zealand (7) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Swedish Disaster

               Very similar to New Zealand (2).  Boot message is:

                   'The Swedish Disaster'

     New Zealand (8) (Boot - master boot sector)

          Length:  1 sector on disk, 2K in memory
          Pseudonyms: Michaelangelo, Gibraltar Revenge               

               Very similar to New Zealand (2).  No boot message,
               instead it overwrites the boot disk on March 6th (any
               year).  Original boot sector is kept at track zero,
               sector three, head one on a 360K floppy, but at sector
               fourteen on all other floppies.  This is impossible on
               a low density disk, so 720K 3.5" disks will not boot
               after infection.

     Nomenklatura (Parasitic - resident)

          Length: 1024
          Pseudonyms: 
          Infects: COM and EXE files

     Nothing (Parasitic - resident)

          Length: 476
          Pseudonyms: Do Nothing, Stupid
          Infects: COM files only

               Infects the first COM file in the current directory,
               even if it was infected already.  Prevents programs
               from receiving the DOS error flag for system services
               - a side effect of this is that an attempt to delete a
               file from the DOS prompt will delete every file in
               that directory.

     Omicron (1) (Parasitic - resident)

          Length: 2343
          Pseudonyms: Flip
          Infects: COM & EXE files

               Occasionally inverts the display, then halts the
               computer.  The order of the rows and columns in the
               display are reversed, the individual characters are
               unaffected.

     Omicron (2) (Parasitic - resident)

          Length: 2153
          Pseudonyms: Flip
          Infects: COM & EXE files

               Very similar to Omicron (1).

     Oropax (Parasitic - resident)

          Length: 2756
          Pseudonyms: Music virus
          Infects: COM files only

               Infects on the DOS directory functions, not on load
               and execute.  Plays three different tunes, after a
               five minute delay, with seven minute intervals between
               tunes.  The tunes are:

                   Stars and Stripes
                   Blue Danube
                   Mozart's Symphony No 40

               Ohropax is the proprietary name of a German brand of
               earplugs.

     Pentagon (Boot - floppy only)

          Length:  4 sectors on disk, 5K in memory
          Pseudonyms: 

               Virus is possibly an honourary term, at least for this
               sample, as all attempts to run it have so far failed. 
               The following describes what would happen if it did
               work (as future samples might).

               This virus consists of a boot sector and two files. 
               The boot sector is a normal PCDOS 3.20 boot sector
               with three changes:

               1.  The OEM name 'IBM' has been changed to 'HAL'.
               2.  The first part of the virus code overwrites 036H
                   to 0C5H.
               3.  100H-122H has been overwritten by a character
                   string.

               The name of the first file is the hex character 0F9H. 
               This file contains the rest of the virus code followed
               by the original boot sector.  The name of the second
               file is PENTAGON.TXT.  This file does not appear to be
               used in any way or contain any meaningful data.  Both
               files are created without the aid of DOS, and the
               first file is accessed by its stored absolute
               location.

               Four different sections of the virus are separately
               encrypted:

               1.  004AH - 004BH, key 0ABCDH - load decryption key
               2.  0059H - 00C4H, key 0FCH - rest of virus code in
                   boot sector.
               3.  0791H - 07DFH, key 0AAH - the file name and
                   copyright message.
               4.  0800H - 09FFH, key 0FCH - the original boot
                   sector.

               The virus will survive a warm boot (Ctrl-Alt-Del).  It
               only infects 360K floppies, and it will look for and
               remove Brain from any disk that it infects.  It
               occupies 5K in memory.

     Perfume (Parasitic - resident)

          Length: 765
          Pseudonyms: 
          Infects: COM files

     Pixel (1) (Parasitic - non-resident)

          Length: 847
          Pseudonyms: Amstrad
          Infects: COM files only

               Infects all COM files in the current directory.  The
               date and time of the file are changed on infection. 
               After the fifth generation, alternate infections end
               with a message and the host program is not executed. 
               The message varies - the original is:

                   Program sick error:Call doctor or buy PIXEL for
                   cure description

     Pixel (2) (Parasitic - non-resident)

          Length: 345
          Pseudonyms:
          Infects: COM files only

               Similar to Pixel (1).

     Pixel (3) (Parasitic - non-resident)

          Length: 299
          Pseudonyms:
          Infects: COM files only

               Similar to Pixel (1), but does not change file date
               and time.

     Pixel (4) (Parasitic - non-resident)

          Length: 277
          Pseudonyms:
          Infects: COM files only

               Similar to Pixel (1), but instead of a message there
               is a routine which hangs the machine.

     Saturday 14th (Parasitic - resident)

          Length: 669
          Pseudonyms:
          Infects: COM and EXE files

               On Saturday the 14th this virus overwrites the first
               hundred sectors of the current partition with rubbish.

     Shake (Parasitic - resident)

          Length: 476
          Pseudonyms: 
          Infects: COM files

               Occasionally displays the message:

                   Shake well before use !

               instead of executing a program, but never more than
               once per session. 

     Sylvia (Parasitic - non-resident)

          Length: 1301
          Pseudonyms: 
          Infects: COM files

               The virus occurs attached to the beginning of a COM
               file. 

     Syslock (1) (Parasitic - non-resident)

          Length: 3551
          Pseudonyms: 
          Infects: COM and EXE files

               The virus occurs attached to the end of a COM or EXE
               file.  Infected files increase in length by 3551
               bytes.  Virus will not infect if environment contains
               the string 'SYSLOCK=@'.  Searches disk for references
               to 'MICROSOFT' and changes them to 'MACROSOFT'.  There
               is a minor variant which changes these references to
               'MACHOSOFT', and this variant is disabled by the
               environment string 'VIRUS=OFF'.

     Syslock (2) (Parasitic - non-resident)

          Length: 2764
          Pseudonyms: Advent
          Infects: COM and EXE files

               This is much the same as Syslock (1) and is disabled
               by the environment string 'VIRUS=OFF'.  During Advent
               (the four weeks before Christmas), instead of
               infecting a file it will sometimes display four
               candles and the legend:
                        'M E R R Y  C H R I S T M A S  !'
               while playing the tune Tannenbaum.  This is only done
               if running under DOS version 2X or if the virus
               generation number is two.

     Telefon (Boot - master boot sector)

          Length:  2 sectors on disk, 1K in memory
          Pseudonyms: 

               Similar to New Zealand.  The second half of the virus
               and the original boot sector occupy the last two
               sectors of the root directory.  The virus maintains a
               count of the number of bootups, and when this reaches
               500 the disk is overwritten and the message:

                   'Campaa Anti-TELEFONICA (Barcelona)'

               is displayed.

     Tequila (Dimorphic)

          Length:  2468, 5 sectors on disk, 3K in memory
          Pseudonyms: 
          Infects: EXE files only

               This virus is dimorphic, which means that it functions
               as both a Boot and a Parasitic virus.

               The Parasitic form is non-resident and only infects
               the first hard disk as a Boot virus.  

               The Boot form becomes memory-resident and only infects
               EXE files parasitically.  Reads or writes to the boot
               sector of the first hard disk are diverted to the
               stored copy of the original boot sector.  It infects
               on execution or when a file is closed, but will not
               infect any file whose name includes a 'V' or an 'SC'. 
               When resident it will subtract its own length from any
               file which appears to be infected.  

     Tiny (1) (Parasitic - resident)

          Length: 198
          Pseudonyms:
          Infects: COM files only

     Tiny (2) (Parasitic - resident)

          Length: 167
          Pseudonyms:
          Infects: COM files only

     Tiny (3) (Parasitic - resident)

          Length: 160
          Pseudonyms:
          Infects: COM files only

     Tiny (4) (Parasitic - resident)

          Length: 159
          Pseudonyms:
          Infects: COM files only

     Tiny (5) (Parasitic - resident)

          Length: 158
          Pseudonyms:
          Infects: COM files only

     Traceback (1) (Parasitic - resident)

          Length: 2930
          Pseudonyms: Spanish
          Infects: COM and EXE files

               If date is 5 December 1988 or later, the virus looks
               for, and infects, one COM or EXE file - either in the
               current directory or the first one found on the disk
               starting from the root directory.  Search is
               terminated if an infected file is found.  If date is
               28 December 1988 or later a display similar to the
               Cascade virus is produced one hour after infection. 
               Keyboard input is used to apparently 'push' the
               characters back to their original positions, one
               screen pass per character (repeated characters
               ignored).  If nothing is typed, the screen restores
               itself after one minute.  After the screen is
               restored, the keyboard returns to normal.  Any
               characters typed in during the actual falling
               character display will lock the machine.  Display will
               repeat every hour.

     Traceback (2) (Parasitic - resident)

          Length: 3066
          Pseudonyms: 
          Infects: COM and EXE files

               Same as Traceback (1), apart from difference in
               length.

     V512 (1) (Parasitic - resident)

          Length: 512
          Pseudonyms: Number of the Beast
          Infects: COM files only

               Infects by overwriting the first 512 bytes of a COM
               file.  The original start of the file is placed in the
               unused portion of the last file cluster.  This means
               that an infected file will not function if it is
               copied, as the virus will replace the beginning of the
               file with whatever rubbish exists after the end of the
               file in the new location.  The virus locates itself in
               a DOS disk buffer.

     V512 (2) (Parasitic - resident)

          Length: 512
          Pseudonyms:
          Infects: COM files only

               Very similar to V512 (1).

     V512 (3) (Parasitic - resident)

          Length: 512
          Pseudonyms:
          Infects: COM files only

               Very similar to V512 (1).

     V512 (4) (Parasitic - resident)

          Length: 512
          Pseudonyms:
          Infects: COM files only

               Very similar to V512 (1).

     Vacsina (4) (Parasitic - resident)

          Length: 1212
          Pseudonyms: 
          Infects: COM files, and small EXE files

               The virus beeps as it infects a file.  Only infects
               COM files which start with a jump instruction.  Small
               EXE files (less than 64K) are converted to COM files
               and, although not infected, become eligible for     
               infection next time.  If the system is already
               infected with an earlier version, it will be
               re-infected with this version.  Puts an infection
               marker (which includes the version number) in the
               unused portion of the INT 31H vector.

     Vacsina (5) (Parasitic - resident)

          Length: 1206
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Functionally identical to previous version.

     Vacsina (6) (Parasitic - resident)

          Length: 1269
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Similar to Vacsina (4), but does not beep when
               infecting.  If COMMAND.COM is infected, it displays
               the message "Az sum vasta lelja" as the system is
               loaded.

     Vacsina (16) (Parasitic - resident)

          Length: 1339
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Similar to Vacsina (6) without the message.  Infects
               all COM files.

     Vacsina (23) (Parasitic - resident)

          Length: 1753
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Similar to Vacsina (16), but infects EXE files in one
               pass.  If a program is infected with an earlier
               version, this is replaced by the current version. 
               Plays the tune "Yankee Doodle Dandee" when the machine
               is rebooted by pressing Ctrl-Alt-Del.  Contains a
               number of routines to determine the version number
               from an external program when memory-resident, and
               instruct the virus to masquerade as the previous or
               the subsequent version.

     Vacsina (24) (Parasitic - resident)

          Length: 1760
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Similar to Vacsina (23), but only plays the tune if
               the generation count is ten or more.

     Vacsina (25) (Parasitic - resident)

          Length: 1805
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Very similar to Vacsina (24).

     Vacsina (33) (Parasitic - resident)

          Length: 2680
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Similar to Vacsina (23), but now plays the tune at
               17.00 hours.  Code has been added to restore minor
               changes and prevent accidental mutation.

     Vacsina (34) (Parasitic - resident)

          Length: 2568
          Pseudonyms: 
          Infects: COM files, and small EXE files

               Very similar to Vacsina (33).

     Vacsina (38) (Parasitic - resident)

          Length: 2752
          Pseudonyms: 
          Infects: COM and EXE files

               Very similar to Vacsina (33).

     Vacsina (39) (Parasitic - resident)

          Length: 2772
          Pseudonyms: 
          Infects: COM and EXE files

               Very similar to Vacsina (33).

     Vacsina (41) (Parasitic - resident)

          Length: 2928
          Pseudonyms: 
          Infects: COM and EXE files

               Very similar to Vacsina (33).

     Vacsina (42) (Parasitic - resident)

          Length: 2992
          Pseudonyms: 
          Infects: COM and EXE files

               Very similar to Vacsina (33).

     Vacsina (44) (Parasitic - resident)

          Length: 2880
          Pseudonyms: 
          Infects: COM and EXE files

               Similar to Vacsina (33), but only plays the tune if
               the infection count is divisible by eight.

     Vacsina (45) (Parasitic - resident)

          Length: 2896
          Pseudonyms: 
          Infects: COM and EXE files

               Very similar to Vacsina (44).

     Vacsina (46) (Parasitic - resident)

          Length: 2976
          Pseudonyms: 
          Infects: COM and EXE files

               Very similar to Vacsina (44).

     Valert (Parasitic - resident)

          Length: 1554
          Pseudonyms: Ten byte
          Infects: COM and EXE files

               From 1st September onwards (any year), it changes the
               buffer address in any write to a file by ten bytes.

     Vcomm (Parasitic - part-resident)

          Length: 637
          Pseudonyms: Poland
          Infects: EXE files

               Infects another EXE file in the current directory. 
               Attempts to install an Int 13H routine in the high end
               of video RAM, without checking that any memory exists
               there.  If successful, it will convert any writes to
               the disk into reads - otherwise the machine will hang.

     Victor (Parasitic - resident)

          Length: 2442
          Pseudonyms: 
          Infects: COM and EXE files

               Sometimes deletes files on a Wednesday if the hour is
               9, 11, 13 or 15. 

     Vienna (1) (Parasitic - non-resident)

          Length: 648
          Pseudonyms: Austrian, Unesco, DOS62
          Infects: COM files only

               The virus occurs attached to the end of a COM file. 
               COM files increase in length by 648 bytes.  The first
               three bytes of the program are stored in the virus,
               and replaced by a branch to the beginning of the
               virus.  The virus looks for, and infects, one COM file
               - either in the current directory or in one of the
               directories on the PATH.  One in eight files
               'infected' does not get a copy of the virus.  Instead
               the first five bytes of the program are replaced by a
               far jump to the BIOS initialization routine.

     Vienna (2) (Parasitic - non-resident)

          Length: 648
          Pseudonyms: 
          Infects: COM files only

               This is the version published in Ralf Burger's book
               'Computer Viruses: A High-Tech Disease'.  An error has
               been introduced which disables the virus's ability to
               search through the PATH, and the far jump has been
               replaced by five spaces.

     Vienna (3) (Parasitic - non-resident)

          Length: 2351
          Pseudonyms: Ghostballs
          Infects: COM files only

               Based on Vienna (2) without the overwrite. Infects one
               COM file in current directory and also writes a
               non-infective version of Italian virus (Italian (3))
               to the disk in the A-drive.

     Vienna (4) (Parasitic - non-resident)

          Length: 507
          Pseudonyms: Polish
          Infects: COM files only

               Based on Vienna (2) without the overwrite.  Infection
               is indicated by changing the creation month to 13.

     Vienna (6) (Parasitic - non-resident)

          Length: 534
          Pseudonyms: Polish
          Infects: COM files only

               Very similar to Vienna (4).

     Vienna (7) (Parasitic - non-resident)

          Length: 627
          Pseudonyms: 
          Infects: COM files only

               Very similar to Vienna (1)

     Vienna-Camouflage (Parasitic - non-resident)

          Length: 1260
          Pseudonyms: Camouflage
          Infects: COM files only

               This family of viruses is based on Vienna (2) without
               the overwrite.  The virus is encrypted and the
               encryption routine (which is the same as for Cascade)
               is randomized.  No simple identification string is
               possible.

     Yale (Boot - floppy only)

          Length:  1 sector on disk, 1K in memory
          Pseudonyms: Alameda, Merritt

               This virus consists of a boot sector only.  It infects
               floppies in the A-drive only and it occupies 1K of
               memory.  The original boot sector is held at track
               thirty-nine, head zero, sector eight.  It hooks into
               INT 9, and only infects when Ctrl-Alt-Del is pressed. 
               It will not run on an 80286 or an 80386 machine,
               although it will infect on such a machine.  It has
               been assembled using A86.  It contains code to format
               track thirty-nine, head zero, but this has been
               disabled.  Will not infect if KEYBUK or KEYB is
               installed.

     Zerobug (Parasitic - resident)

          Length: 1536
          Pseudonyms: 
          Infects: COM files only

    9.3  Pseudonyms.

     Advent                  -    Syslock (2)
     Alameda                 -    Yale 
     Amstrad                 -    Pixel (1)
     Anarkia                 -    Jerusalem (1H)
     Anarkia 2               -    Jerusalem (4)
     Antiscan                -    Jerusalem (10)
     April 1st               -    Jerusalem (S1),
                                  Jerusalem (S2) 
     Ashar                   -    Brain (2) 
     Austrian                -    Vienna (1) 
     Big Italian             -    Italian (4)
     Black Hole              -    Jerusalem (1) 
     Blackjack               -    Cascade (2) 
     Camouflage              -    Vienna-Camouflage
     Century                 -    Hidden (1)
     Datacrime II            -    Datacrime (3),
                                  Datacrime (4) 
     Dbase                   -    New York (2)
     December 24th           -    Icelandic (5)
     Do Nothing              -    Nothing
     DOS62                   -    Vienna (1) 
     Dyslexia                -    Jerusalem (9)
     Eddie                   -    Dark Avenger
     Fall                    -    Cascade family
     Fish 6                  -    Hidden (2)
     Flip                    -    Omicron
     Frere Jacques           -    Jerusalem (6)
     Friday the 13th         -    Jerusalem (1)
     Frodo                   -    Hidden (1) 
     Fu Manchu               -    Jerusalem (2) 
     Ghostballs              -    Italian (3),
                                  Vienna (3)
     Gibraltar Revenge       -    New Zealand (8)
     Horse                   -    Hacker
     IDF                     -    Hidden (1)
     Invader                 -    Anticad (3)
     IPX                     -    Jerusalem (11)
     Irish                   -    Jerusalem (12)
     Israeli                 -    Jerusalem family
     Korean                  -    New Zealand (3)
     Machosoft               -    Syslock (1B)
     Marihuana               -    New Zealand (2) 
     Merritt                 -    Yale 
     Michaelangelo           -    New Zealand (8)                    
     Mistake                 -    Italian (2) 
     Mix1                    -    Icelandic (4)
     Music                   -    Oropax
     Number of the Beast     -    V512 (1)
     Ogre                    -    Disk Killer 
     Pakistani Brain         -    Brain (1) 
     PcVrsDs                 -    Jerusalem (12)
     Ping Pong               -    Italian (1) 
     Plastique               -    Anticad family
     PLO                     -    Jerusalem (1) 
     Poland                  -    Vcomm
     Polish                  -    Vienna (4),
                                  Vienna (6)
     PSQR                    -    Jerusalem (5)
     Rostov                  -    New Zealand (5)
     Russian                 -    Cascade (1) 
     Saratoga                -    Icelandic (2) 
     Search                  -    Den Zuk
     Sex Revolution          -    New Zealand (2H)
                                  New Zealand (4)
     Solano                  -    Jerusalem (9)
     Solomon                 -    Jerusalem (10)
     Spanish                 -    Traceback (1) 
     Stoned                  -    New Zealand (2) 
     Subliminal              -    Jerusalem (9)
     Sunday                  -    Jerusalem (3) 
     Swap                    -    Italian (2) 
     Swedish Disaster        -    New Zealand (7)
     Ten byte                -    Valert
     Typo                    -    Italian (2)
     Typo RMG                -    New York (1)
     Unesco                  -    Vienna (1)
     Yankee Doodle           -    Vacsina
     Zapper                  -    New Zealand (6)
  9.4  Lengths of Parasitic viruses.

        The infective length of a Parasitic virus is the length by
        which an infected program will increase.  This is usually,
        but not always, the same as the length of the virus.

        There are a number of traps for the unwary in the infective
        lengths of viruses.

        Some viruses have a signature which is added to the program
        after the virus (e.g. the Jerusalem family).

        The length of EXE files must be divisible by sixteen before a
        virus is added to the end because of the way the processor
        addresses memory.  For this reason a virus will usually round
        up any such file before infecting, and the increase in length
        will include these rounding bytes. Some viruses also round up
        COM files before infecting them.

        The length of an EXE file is not always the same as the
        length which DOS loads.  If the load length is different it
        will, of course, be shorter than the file length.  When such
        a file is infected, the virus will normally be added after
        the end of the load portion, overwriting the rest of the
        file.  The increase in length will thus be less than the
        length of the virus, and occasionally there will be no
        increase in length.


        Some viruses also have special handler routines which are
        written in addition to the virus to EXE files (eg the earlier
        Vacsina series), to COM files (eg Nothing) or both (Valert).

        The following list is given for reference, but also to show
        how ridiculous it is to name viruses by their lengths.

           158          -    Tiny (5)
           159          -    Tiny (4)
           160          -    Tiny (3)
           167          -    Tiny (2)
           198          -    Tiny (1)
           277          -    Pixel (4)
           299          -    Pixel (3)
           333          -    Kennedy
           345          -    Pixel (2)
           400          -    Antipascal (5)
           405          -    405
           440          -    Antipascal (4)
           476          -    Shake,
                             Nothing
           480          -    Antipascal (3)
           507          -    Vienna (4)
           512          -    V512
           529          -    Antipascal (2)
           534          -    Vienna (6)
           555          -    Lehigh
           605          -    Antipascal (1)
           627          -    Vienna (7)
           632          -    Icelandic (3)
           637          -    Vcomm
           642          -    Icelandic (2)
           648          -    Vienna (1),
                             Vienna (2)
           656          -    Icelandic (1)
           669          -    Saturday 14th
           765          -    Perfume
           847          -    Pixel(1)
           848          -    Icelandic (5)
           867          -    New York (1)
           879          -    June 16th
           897          -    Jerusalem (S1)
          1024          -    Nomenklatura
          1154          -    Hacker (1),
                             Hacker (7)
          1158          -    Hacker (2)
          1168          -    Datacrime (2)
          1206          -    Vacsina (5)
          1212          -    Vacsina (4)
          1216          -    Keypress
          1260          -    Vienna-Camouflage
          1269          -    Vacsina (6)
          1280          -    Datacrime (1)
          1301          -    Sylvia
          1339          -    Vacsina (16)
          1408          -    Alabama
          1480          -    Datacrime (3)
          1487          -    Jerusalem (8)
          1488          -    Jerusalem (S2)
          1496          -    Jerusalem (8) with signature
          1514          -    Datacrime (4)
          1536          -    Zerobug
          1554          -    Valert
          1558          -    Jerusalem (11)
          1575          -    Green Caterpillar
          1576          -    Hacker (5)
          1594          -    Hacker (6)
          1600          -    Jerusalem (10)
          1605          -    Jerusalem (10) with signature
          1610          -    Hacker (3)
          1618          -    Icelandic (4)
          1631          -    Jerusalem (3)
          1636          -    Jerusalem (3) with signature
          1701          -    Cascade (1)
          1704          -    Cascade (2),
                             Cascade (3)
          1715          -    Jerusalem (5)
          1720          -    Jerusalem (5) with signature
          1753          -    Vacsina (23)
          1760          -    Vacsina (24)
          1776          -    Hacker (4)
          1800          -    Dark Avenger (1)
          1805          -    Vacsina (25)
          1808          -    Jerusalem (1), (4), (6), (S3)
          1813          -    Jerusalem (1), (4), (6) or (S3) with
                             signature
          1845          -    Jerusalem (11) with signature (COM file)
          1864          -    New York (2)
          1899          -    Jerusalem (12)
          1904          -    Jerusalem (12) with signature
          1991          -    Jerusalem (9)
          2000          -    Dark Avenger (2)
                             Jerusalem (9) with signature
          2080          -    Jerusalem (2)
          2086          -    Jerusalem (2) with signature
          2100          -    Dark Avenger (3)
          2153          -    Omicron (2)
          2343          -    Omicron (1)
          2351          -    Vienna (3)
          2442          -    Victor
          2468          -    Tequila
          2568          -    Vacsina (34)
          2680          -    Vacsina (33)
          2752          -    Vacsina (38)
          2756          -    Oropax
                             Vacsina (38) with signature
          2764          -    Syslock (2)
          2772          -    Vacsina (39)
          2880          -    Vacsina (44)
          2885          -    Vacsina (44) with signature
          2896          -    Vacsina (45)
          2900          -    Anticad (1)
          2901          -    Vacsina (45) with signature
          2928          -    Vacsina (41)
          2930          -    Traceback (1)
          2932          -    Vacsina (41) with signature
          2976          -    Vacsina (46)
          2981          -    Vacsina (46) with signature
          2992          -    Vacsina (42)
          2996          -    Vacsina (42) with signature
          3004          -    Anticad (5)
          3012          -    Anticad (4)
          3066          -    Traceback (2)
          3551          -    Syslock (1)
          3584          -    Hidden (2)
          4096          -    Anticad (2)
                             Anticad (3)
                             Hidden (1)

