Dismember

Alias:
Strain:-
detected when:
where:
Classification:COM-infector
Length:NONE

Preconditions

Operating System(s):MS-DOS
Version/Release:All models
Computer model(s):PC's
Caroname:Dismember

Attributes

Easy identification:

Type of Infection:

The virus appends itself to the files Selfrec on disk: File_Seconds == 62

Infection Technique:
Infection Trigger:1000h <= Filesize <= 0FE00h
Storage Media affected:
Interrupts hooked:
Stealth:
Tunneling/Selfprot:
Oligo/Polymorphism:-
Encoding Method:
Damage:Transient: - Permanent: -
Damage Trigger:Transient: - Permanent: -
Particularities:The virus is not memory resident. The file analysed appeared to be the original launch virus. Init are some text strings describing the virus, which are not passedon by infection. Before the virus is the text:The Dismember Virus 1.00 (288 Bytes Version)and after the virus is the text:Self-Encrypting Non-Resident Parasitic .COM infectorCoded 1992 by Annihilator, Sweden(c) Copyright FPCP 1992
Similarities:

Agents

Countermeasures:
Standard means:

Acknowledgements

Location:Virus Test Center, University Hamburg, FRG
Classification by:Adam David, Frisk Software International
Documentation by:Adam David, Frisk Software International
Date:20.6.93
Information Source:Caroentry (autom.converter by S.Freitag)

(c) 1996 Virus-Test-Center, University of Hamburg