
                                         Jim Bates

     Pitch -  A  new  Virus  High  Note

     In spite of the increasing complexity of viruses arriving on
     my desk these days, there is still the occasional trivial and
     primitive specimen which makes me grit my teeth at the
     sheer irresponsibility of the originator. This cause of this
     month's ire is a 593  byte virus which infect s COM files in
     various directories on the host machine.

     Although the whole of the virus code does become memory-
     resident, the infection cycle is a one-shot mechanism  which
     is only invoked when an infected file is executed. The virus
     contains the usual crop of mistakes and under certain
     circumstances will irreparably damage infected files.
     However, the trigger routine is not intentionally destructive,
     as it simply causes a high-pitched whine to be emitted from
     the computer' s speaker.


     Installation

     When an infected file is executed, the virus code is run first
     and begins by allocating two memory blocks for its own use 
     Processing then passes to a routine which attempts to find
     files with a COM extension in the current directory of the
     active drive.

     Once a suitable file is found, it is infected and a counter is
     decremented. When the counter reaches zero or there are no
     more matching files available, processing returns to the
     calling routine. The starting value of this counter is not
    initialised at this stage and it is therefore not possible to
     predict how  many files will be infected.

     A secondary infection routine is then called which attempts
    to get to the root directory of drive C. If this is successful the
     find and infect routine is called again (without resetting the
    infection counter).

     Once the requisite number of *.COM files in the root
     directory (including COMMAND.COM if it is there) have
     been infected, the routine shifts its attention to the first
     subdirectory and infects any COM  files there. In this case the
     counter is set to 3 before the infection search begins and a
     check is made to ensure that at least one file is infected
     before the routine is exited.

     If this check fails (i.e. no suitable files were found), then the
     next subdirectory off the root is tried, and so on. Once all
     available files in the root and primary subdirectories of the
      C: drive are infected, the machine will hang. Subsequent
      attempts to execute an infected COM  file will also have the
      same effect.

      Once these infection routines have completed, an 'Are you
      there?' call is issued to determine whether the virus is
      memory-resident. If it is, processing passes to the host repair
      routine which replaces the original block of 593 bytes at the
      head of the file and passes control to it.

      If the virus code is not resident, an additional 42 bytes of
      memory are allocated from system resources and the two
      interrupt interception routines are copied into it. The ad-
      dresses for these routines are then hooked into the system
      and processing finally passes to the host repair routine and
      thence to the host program.


      Resident Operation

      The first interception routine simply installs an INT 47h
      routine which serves to answer the virus' 'Are you there?'
      call. INT 47h is not used by DOS and on most systems will
      remain unallocated; however there is at least one application
      package which uses it (a network oriented database engine
      from  Gupta Technologies), and machines running this
      package will malfunction in an unpredictable manner in the
      presence of this virus.
      The second interception routine takes over the timer tick
      routine at INT 1Ch. As in the previous case, this interrupt is
      not used by DOS but again there are several packages which
      use it on an occasional basis and malfunctions will certainly
      occur in these cases.

      The interception maintains a counter which is initialised to a
      value that represents a time delay of approximately ten
      minutes. Once this delay has elapsed, the routine accesses
      the sound control ports and causes the speaker to emit an
      annoying high-pitched note (slightly above the highest note
      on a piano). This will then continue until the machine is
      switched off.
                                            
      Neither of the interception routines attempts to maintain
      connection with any previous routines at the specified
      interrupt locations.


      Infection Processing

      This virus only infects COM  files and makes no check of
      their size or the content of the header. A block of 593 bytes is
      copied from  the beginning of the file and appended to the
      end. The virus code is then written over this initial block so
      that it executes first. Repairing the host file is a reversal of
      this process. COM  files greater than 64,942 bytes will be
      irreparably damaged.
                                                      


     Once infected, the seconds field of the time stamp of the
     infected file is set to the ubiquitous 62 seconds. The virus
     has no stealth capability and infected files will appear 593
     bytes larger than their original size (except in the case of
     large files mentioned above).


     Conclusions

     The mismanagement of memory  resources by this virus
     makes it unlikely to spread very far. Unpredictable system
     crashes will occur at random intervals depending upon any
     other memory management software that may be operative.
     In addition, its rather obvious trigger further limits the likely
     spread of the sample.

     This is just another poor attempt at virus programming. The
     range of mistakes in the code suggests that the author has
     very little experience in assembly language. Fortunately
     this misbegotten creation will cause no problems for
     existing anti-virus software and is best consigned to the
     dustbin of history.
                                                                                                 :


                                                  
      Aliases:  593

      Type:  Resident Parasitic COM infector
                 (including  COMMAND.COM).

      Infection:  All  COM files.

      Self-Recognition:

      Files      Time stamp is 62 seconds.

      System     88h in AL, INT 47h returns 44h in AL
                 shows virus is resident.

      Hex Pattern :
                 8916 1403 8B16 1803 81C2 0001
                 0316 1403 8916 1A03 B43F 8B0E

      Intercepts:  INT 1Ch for trigger routine.
                   INT 47h for 'Are you there?' call.
  
      Trigger:  Ten minutes after system infection
                occurs, speaker emits a continuous
                high pitched tone.

      Removal:  specific disinfection is possible in
                most cases. Under clean system
                conditions, identify and replace
                infected files.
                                             

                                    
    

