PAKISTANI BRAIN VIRUS
Origin: Lahore, Pakistan, January 1986 (Developed by two brothers as an experiment.)
Host: IBM PCs and Compatibles
Class: Boot Sector Infector
Description:
Replaces original boot sector with itself
Moves original boot sector to another location
Adds seven sectors that contain remainder of virus
Flags all modified sectors as unusable to protect itself
Replicates onto all inserted bootable floppies
How Spread:
Booting from unknown or shared disks
Infects through any access to an inserted disk, such as listing directories, executing programs, or rebooting.
Symptoms:
Copyright @BRAIN label displayed on infected disk
Reboot sequences slowed down
Excessive floppy disk activity for simple tasks
Program crashes for some versions of DOS
Interrupt vectors modified
Potential Damage:
System crash can cause loss of data
Spreads quickly to all bootable disks
Precautions:
Do not boot from unknown floppies
Boot only from the hard disk, if one exists
Write-protect all boot disks
Recovery:
Shut down infected systems
Reboot from a clean, write-protected original boot disk
List directories of all disks and look for @BRAIN label
If @BRAIN label found, destroy the disk, or:
o Run DOS SYS command to rewrite boot sector
o Recreate volume serial label using any available utility (Will still leave seven bad sectors with dead virus.)
NOTE: Will live through software reboot.
|