EMF (404)

Alias:
Strain:-
detected when:
where:
Classification:COM-infector
Length:406 (INCLUDING 3 GARBAGE BYTES AT THE END, SEE COMMENTS: )

Preconditions

Operating System(s):MS-DOS
Version/Release:DOS >= 3
Computer model(s):PC's
Caroname:EMF.404

Attributes

Easy identification:

Type of Infection:

The virus appends itself to the files Selfrec on disk: Filetime_seconds == 60

Infection Technique:
Infection Trigger:Search current directory (including system/hidden)
Storage Media affected:
Interrupts hooked:24
Stealth:
Tunneling/Selfprot:
Oligo/Polymorphism:-
Encoding Method:
Damage:Transient: - Permanent: -
Damage Trigger:Transient: - Permanent: -
Particularities:The virus is not memory resident. Interrupt port 21h bit 1 is not cleared if the virus exitsbecause of DOS < 3. Not displayed text: "Screaming Fist (c)1" The last 3 bytes of the original virus are now missing, thoughthe encryption routine still decrypts and encrypts them. It is thelast 3 bytes of MSG_NOT_DISPLAYED:
Similarities:

Agents

Countermeasures:
Standard means:

Acknowledgements

Location:Virus Test Center, University Hamburg, FRG
Classification by:Adam David, Frisk Software International
Documentation by:Adam David, Frisk Software International
Date:28.7.93
Information Source:Caroentry (autom.converter by S.Freitag)

(c) 1996 Virus-Test-Center, University of Hamburg