B1

Alias:NYB
Strain:-
detected when:
where:
Classification:Master-boot record (HD) infector, DBR - infector , resident
Length:1C0B

Preconditions

Operating System(s):MS-DOS
Version/Release:All models
Computer model(s):PC's
Caroname:B1

Attributes

Easy identification:

Type of Infection:

Bootsector infection. Selfrec on disk: MBR[40h...80h] = 0Eh E8h ABh 00h 50h D1h E8h FEh ...

Infection Technique:
Infection Trigger:boot from an infected floppy disk, if residentread or write to track 0 on any floppy disk drive
Storage Media affected:Harddisks, Disketts
Interrupts hooked:13h
Stealth:
Tunneling/Selfprot:
Oligo/Polymorphism:-
Encoding Method:
Damage:Transient: moves head of actual drive permanently from 1st tolast track / cylinder Permanent: -
Damage Trigger:Transient: (w/0:046Dh && 178Fh) == 0 (BIOS Timer) Permanent: -
Particularities:The virus resides at the top of memory, reducing the BIOS memory size at 0000:0413.
Similarities:

Agents

Countermeasures:
Standard means:

Acknowledgements

Location:Virus Test Center, University Hamburg, FRG
Classification by:BSI (GISA) / V2, Hubert Schmitz
Documentation by:BSI (GISA) / V2, Hubert Schmitz
Date:1994-12-20
Information Source:Caroentry (autom.converter by S.Freitag)

(c) 1996 Virus-Test-Center, University of Hamburg