Blot Virus

Alias:---
Strain:---
detected when:May 1988
where:Amherst (USA)
Classification:Boot sector virus
Length:681 Bytes

Preconditions

Operating System(s):Atari TOS
Version/Release:ROM TOS from 02.06.1986; in other versions, no action is per
Computer model(s):All Atari ST
Caroname:Blot

Attributes

Easy identification:In memory at Phystop +34 and in the boot sector at the same offset, the following bytes can be found: $0206198600FC0018

Type of Infection:

Boot sector of drive A.

Infection Technique:
Infection Trigger:Usage of drive A.
Storage Media affected:Drive A.
Interrupts hooked:200 Hz interrupt , Bios Parameter Vector. Critical Error Handler at infection time. Phystop is decremented by 1 KByte.
Stealth:
Tunneling/Selfprot:
Oligo/Polymorphism:
Encoding Method:
Damage:The screen is blacked out from bottom to middle and from top to middle at same time.
Damage Trigger:Virus is about 3 hours in Ram. (Depends on value of 200 Hz timer).
Particularities:Only boot sectors that aren't executable are in- fected.
Similarities:The general concept of the virus is similar to the 'Screen'-Virus

Agents

Countermeasures:Make sure that the virus is not in memory. Search bootsector for the string mentioned above. Modify last byte in boot sector to another value.
Standard means:Clear all bytes in bootsector (sector 0) beginning at offset 30 (dec) and clear all bytes in sector 5.

Acknowledgements

Location:Virus Test Center, University of Hamburg FRG
Classification by:
Documentation by:Ralf Stegen
Date:5-June-1990
Information Source:George R. Woodside

(c) 1996 Virus-Test-Center, University of Hamburg