
                            The TP Viruses
                            --------------

        I know personally the author of these viruses.  Let call him
T.  P.  I gave also the name TP (the first letters of the virus
author's name) to the whole range of his viruses.

        Please, don't ask me if he was prosecuted.  He was not.  And
he won't be.  His viruses do not destroy anything and even if they did
--- there is not a law against the virus writers in our country.  And
of course you know, that it is very difficult to state one.  If a
program destroys something, the one who will be considered guilty will
be those who executed the program in the harmful way --- not those who
created the program.  (If I wipe out my boss' hard disk using the
Norton Utilities package, guess who will get fired --- I or Peter
Norton?!) And even if we vote such a law against the virus writers,
those who wrote viruses before the law was voted won't be prosecuted
--- at least this is the way the laws work in our country.  (Excuse me
if you cannot understand this, but I have difficulties to pick the
right words.  My legal English is much worse than my technical
English.)

        But let's return to our viruses.

        When T.  P.  first learned about the idea of computer virus,
he was fascinated (just like me, in fact).  Then he decided to create
his own virus (unlike me) and ...  he succeeded.  After that he began
to work on a virus prevention scheme.  Then he designed a virus which
was able to circumvent this scheme.  Then he improved the virus
protection program.  And then the virus.  And so on...  The virus
prevention program became more and more complex.  And so did the
virus.

        As far as I know, his virus is now at version 50 or above.
The virus' version (as a hex number) is placed in the before last byte
of the infected file.  I suppose that the virus known as VACSINA is in
fact version 16 (decimal) and the Yankee Doodle virus is version 38
(decimal) or something about that.

        Where comes the string "VACSINA" from?  Well, when my friend
created his virus protection program, he designed it as a device
driver.  His later viruses are able to communicate with this driver,
so they have to figure out if the later is already installed.  They do
this using the conventional way --- by trying to open a file with the
logical name of the device driver, which turns out to be "VACSINA".
This is the Bulgarian word for "vaccine" --- an appropriate name for a
virus prevention program.  The name is not spelled in cyrillic for
obvious reasons.

        All versions of the virus maintain upward compatibility. A
higher version can infect a file infected with the lower version by
removing the later. The opposite is never true. You can use this to
prove that VACSINA and Yankee Doodle are different versions of one and
the same virus. Just try to infect a file with both viruses. It
doesn't matter in which way you will proceed --- you will got a file,
infected with only one virus --- the Yankee Doodle one (which turns
out to be a higher version of the TP virus). For instance, if you
first infect the file with the VACSINA virus and then with Yankee
Doodle, the later will remove the former (leaving possibly a small
part of it, which is not able to infect other files). If you try the
opposite, you will first infect the file with the Yankee Doodle virus,
but VACSINA will recognize the higher version and will never attach
itself to that file.

        All versions of the virus remain *STRICTLY* non-destructive.
By saying strictly I know what I mean.  After this virus, my friend
created a completely different one --- and much more clever.  It would
be able to hide in the PC-DOS I/O buffers, to place itself in the
unused space of the .EXE-file headers and so on.  But he did not
spread this virus.  He did not even accept to give me a sample copy
--- and I am his friend and a well known antivirus researcher.  The
only reason was that sometimes --- in very rare occasions --- when
both viruses (older versions of TP and the new one) infect a single
file and one tries to remove the first of them, this operation *may*
cause damage to the file.  Furthermore the higher versions of the TP
virus can circumvent *any* memory resident program that monitors INT
13h.  However, the programs which are monitoring INT 21h will still
detect the virus.  It was very easy to circumvent them also, by using
the same technique.  However, this *might* cause damage (for instance,
if you disable some disk cache program).  This was the only reason the
virus leaves the INT 21h monitors.

        By the way, my friend did not spread the virus himself.  He
just left his creature lurking freely on the computer he was working
on.  There are not so much computers in Bulgaria and often one PC is
shared between 3-4 persons.  Of course, T.  P.  warned them for the
presence of a virus, but he did not insisted on his warning.  The
later was taken as a joke and no one paid any serious attention.  That
is how the virus spread.

        Let's now discuss a bit the different versions of the virus.
Some of them are quite similar, and I do not have a full collection of
all the versions.  In fact even T.  P.  himself does not saved copies
of all the versions he has created.  All of them are memory resident.
However there is a difference about the way the virus becomes
resident and the place in memory where it installs itself.  All
versions are able to infect both .COM- and .EXE-files. However the
methods of .EXE-file infection differ significantly.

        I am giving here a table of the versions I have a copy of. In
the table are shown the virus' version, its length and the minimal
size of the infectable files (i.e., files less than this size won't be
infected).

        |===============================================|
        | Virus   | To be infected, files  | Virus size |
        | version | have to be bigger than |  (bytes)   |
        |---------+------------------------+------------|
        |    4    |        1213 bytes      |   1215     |
        |    5    |        1207   "        |   1215     |
        |    6    |        1270   "        |   1279     |
        |   16    |        1340   "        |   1343     |
        |   23    |          64   "        |   1753     |
        |   24    |          64   "        |   1760     |
        |   25    |          64   "        |   1805     |
        |   33    |          64   "        |   2680     |
        |   34    |          64   "        |   2568     |
        |   38    |          64   "        |   2756     |
        |   41    |          64   "        |   2932     |
        |   42    |          64   "        |   2997     |
        |   44    |          64   "        |   2885     |
        |   45    |          64   "        |   2901     |
        |   46    |          64   "        |   2981     |
        |===============================================|

        Now I shall discuss some of the more interesting versions of
the virus.

        TP04.  One of the first successful versions.  It is very
widely spread in Bulgaria (the other "successful" versions are 16 and
44).  This virus has simple sound effect --- the infected files emit a
short beep (ASCII 7) when they are run.  The .EXE-files are infected
in a rather strange way.  In fact PC-DOS recognizes these files not by
their extension but by their first two bytes.  These bytes have to be
`MZ' for the .EXE-files.  For instance the 1701/1704 viruses use the
same way to distinguish the .COM-files.  (In fact, PC-DOS checks also
if the identifier is `ZM' --- so do the TP viruses.  I have not
encountered yet an .EXE-file with such identifier, but if they really
exists, this virus will handle them correctly.) At the time when the
versions 1--37 were created, the virus' author did not knew how to
infect an .EXE- file.  So he used a clever trick --- the virus
overrides the `MZ' identifier with a jump to the virus code.  Now
PC-DOS will consider the infected file as a .COM- one.  When the virus
receives control, it uses a small loader program which extracts the
appropriate information from the file's EXE-header and does the needed
patching.  Of course, this means that only .EXE-files with size less
then 64 K can be infected --- since this is the limit for the
.COM-files and PC-DOS will treat the .EXE-file infected if such way as
a .COM- one.  Unfortunately, this has an unwanted side effect.  These
.EXE-files are now infectable by some .COM-file viruses --- the
1701/1704 viruses for example.  And most of the programs which are
designed to cure against these viruses, generally do not touch the
.EXE-files --- since they *know* that the virus will not infect them!

        TP05. This is almost the same as the one above, but the
infected files do not beep when run.

        TP25.  This one is a bit different from the formers.  There is
no "VACSINA" string in it --- the author has dropped his device driver
based protection scheme.  It has also a much more elaborated sound
effect.  Now it plays the Yankee Doodle melody when one tries to
reboot the computer via the Alt-Ctrl-Del sequence (of course, the
machine is rebooted after the melody finishes).  Why this melody is so
popular between the Bulgarian viruses?  Simply at that time the source
of the Yankee virus was already spread.  And in it one can find the
melody --- nicely tabulated to pitches and durations together with a
playing subroutine.  This version of the TP virus has another
peculiarity.  It installs a new function call to PC-DOS (INT 21h,
function 0C5h).  Using this function, the virus is able to do a lot of
things --- to install itself in memory, to check if it is already
installed there, to switch on and off its infection capability and
even to remove itself from the memory or from the infected files.  The
last function is needed when a higher version of the virus wants to
infect a file, which is already infected by a lower version --- the
later has first to be removed.  However soon people started to use
this function to get rid of the virus (and even to vaccinate the
system against it).  So with the next versions, the function call was
moved to 0C6h.

        TP33.  At that time I pointed to the author that even a non-
destructive virus can be dangerous.  For instance, someone may change
the virus code and to add destructive functions.  Therefore, my friend
included a special routine, which is able to detect if the virus has
been patched --- and even to correct the errors.  Up to 16 bytes of
the virus code can be changed deliberately and the virus will still be
able to reconstruct itself during loading.  The routine uses Hamming
self correcting code (I'm not sure about the spelling of the name).
Of course, you may change more bytes or just patch the self correcting
procedure itself.  However in this case the virus will hang the
system.  I do not mean that the virus is *impossible* to be changed, I
just mean that this is a rather difficult task.  In fact the routine
described above was first designed to deactivate some debuggers which
are placing breakpoints (i.e., INT3) in the code being debugged and
thus are changing it.  When speaking about debuggers, this version
contains also some common tricks (mainly used in the copy protected
programs) to disable the debuggers --- e.g., destroys the contents of
INT3 and INT 1 vectors and so on.  The sound effect was also changed.
Now the virus plays his favorite melody at 5 pm., not when one presses
Alt-Ctrl-Del.

        TP38. This version is significantly improved. In fact, it (and
the higher versions) looks like a different virus. The main difference
is that the .EXE-files are now infected correctly. They are no more
converted to .COM- format and files of arbitrary size can be infected.
The other main change was the introduction of a clever method by which
*every* memory resident program which monitors some "dangerous"
interrupts can be disabled (or, more exactly circumvented). The
"antidebugging" part was also changed. Now if the virus is already in
memory and you try to load it for debugging or disassembling via INT
21h, function 4Bh, subfunction 00; the virus will detect the function
call and will remove itself from the infected file. So you will get a
"clean" file with your debugger and will see nothing. But if you
succeed to load the infected file (e.g., if the virus is not in
memory, or by using a "primitive" debugger like DEBUG.COM or AFD.COM),
you will be able to execute only the first few instructions of the
virus. Immediately after that, your debugger will be disconnected and
the rest of the virus will execute (i.e., install in memory, hook the
interrupt vectors, etc.). When the debugger receives control again,
it will be at the first instruction of the original file.

        TP42. This version has all the properties of the previous
ones, but is able to "fight" the Italian (Bouncing Ball, Turin) virus.
It changes the later in such way that after 255 reboots it will kill
itself and the only thing which will rest on the disk will be the
"dead body" (is there a single English word which means this?) of the
virus (i.e., the cluster marked as bad). There are different
conceptions about how to design the antivirus programs. I prefer the
"UNIX" approach --- a lot of programs, each one can handle a single
virus, with unified interface (i.e., options, errorlevel, etc.), which
can be easily combined into a larger program (in a .BAT-file). Some
people prefer the "put everything into one" approach --- a large
program, which can handle every virus they have heard about. Well, my
friend prefers another approach. According to him, the average user is
so stupid, that he is not able to start an antivirus program himself.
Therefore, the antivirus program has to spread by its own means and to
execute without the intervention of the user. I.e., it has to be a
virus itself.

        TP44. This version plays Yankee Doodle at 5 pm. with
probability of 1/8. This reduces the chances to discover the virus.

        TP46. Acts like the previous versions, but is able to fight
the 1701 (Cascade, Autumn, Falling letters) virus also (however is not
able to handle the 1704 one, as far as I know).

        One of the newest versions of the virus (somewhere about 50)
is able even to detect if it runs on an 80286/80386 system and to use
on of the instructions designed for protected mode usage, just to
circumvent the memory resident interrupt monitors. Unfortunately I
have no copy of this version.

