Ontario.2048

Ontario.2048
Ontario.2048
Common name Ontario.2048
Technical name Ontario.2048
Aliases Bootache.2048, Ontario III
Family Ontario
Classification Virus
Type DOS
Subtype DOS file infector
Isolation September 1992
Point of isolation Ontario, Canada
Point of Origin Ontario, Canada
Author(s) Death Angel

Ontario.2048 is a computer virus, discovered in September 1992. It is the third and final known variant of the Ontario family, both chronologically and in complexity. Because of its rather extreme differences from the original virus, some vendors identify it as a member of a separate family - hence the alias Bootache.2048.

Contents

Infection

Ontario.2048 is an encrypting, polymorphic, stealth DOS file infector. Upon the execution of an infected .COM, .EXE, .OVL, or .SYS file, Ontario.2048 goes memory resident and infects files of these times upon being opened. COMMAND.COM is infected using a special routine, and will not increase in file size. Infected files will increase in size by 2,048 bytes. However, when Ontario.2048 is in memory, no increase in file size will be observed due to the virus' stealthing.

When the DOS DEBUG program is in memory, Ontario.2048 will detect it and disinfect programs in memory to avoid being analysed. Ontario.2048 also features an extremely complex encryption system; a given sample of Ontario.2048 may only share two bytes in common with another.

Symptoms

Ontario.2048 can result in the following symptoms:

  • An increase in size of infected files by 2,048 bytes.
  • A decrease in available system memory of 5,120 bytes.
  • File size being changed after executables (infected ones) are executed, to display original file size.
  • Occasional printer-related problems have been observed in the Ontario.1024 variant of this family; it is unknown whether this carries over to Ontario.2048.

The first three symptoms are good indications that a virus is present, but are not necessarily specific to Ontario.1024.

Ontario.2048 also contains text, which is invisible because Ontario.2048 is encrypted. The following text strings are present:

COMSPEC=\COMMAND.COM COMEXEOVLSYS
MSDOS5.0
YAM
Your PC has a bootache! - Get some medicine!
Ontario-3 by Death Angel

The first line is a reference to the method used to find COMMAND.COM to infect, as well as file types that the virus infects. The second line refers to the version of MSDOS that Ontario.2048 was written on. The third is a reference to the Youngsters Against McAfee virus group, which the author had joined by this point.

A number of descriptions note multipartite function in Ontario.2048. This is incorrect. Ontario.2048 does contain a boot sector within it with a boot virus. If inserted into the boot sector, it would be a functioning boot virus (although it would not spread the file infection portion of Ontario.2048). However, Ontario.2048 never performs the injection; the code is functionally useless. Based on the virus author's documentation for the virus[1], this appears to be intentional (reasons unknown).

Prevalence

The WildList[2], an organisation tracking computer viruses, has never listed Ontario.2048 as being in the field. However, Ontario.1024 was included for a period of time.

Like all DOS file infectors, the advent of Windows significantly hindered the spread of Ontario.2048. Trend Micro statistics report only two infections since November 6, 2006[3], which indicates that the virus is now obsolete.

External links


Wikimedia Foundation. 2010.

Игры ⚽ Нужна курсовая?

Look at other dictionaries:

  • Ontario.2048 (computer virus) — Computer virus | Fullname = Ontario.2048 Common name = Ontario.2048 Technical name = Ontario.2048 Family = Ontario Aliases = Bootache.2048, Ontario III Classification = Virus Type = DOS Subtype = DOS file infector IsolationDate = September 1992… …   Wikipedia

  • Ontario (computer virus) — Ontario.512 Common name Ontario.512 Technical name Ontario.512 Aliases SBC Family Ontario Classification Virus Type DOS …   Wikipedia

  • Ontario (disambiguation) — Ontario is the most populous province in Canada. Ontario may also refer to: Contents 1 Places 2 Lakes 3 Computer viruses …   Wikipedia

  • Ontario.1024 (computer virus) — Ontario.1024 Common name Ontario.1024 Technical name Ontario.1024 Aliases 1024 SBC Family Ontario Classification Virus Type DOS …   Wikipedia

  • List of computer viruses (L–R) — This list is incomplete; you can help by expanding it. Name Alias(es) Type Subtype Isolation Date Isolation Origin Author Notes L1 …   Wikipedia

  • Comparison of AMD graphics processing units — For information on Nvidia graphics processing units, see Comparison of Nvidia graphics processing units. This page contains general information about the GPUs and video cards by Advanced Micro Devices (AMD), including those by ATI Technologies… …   Wikipedia

  • Pesticide — A cropduster spraying pesticide on a field Pesticides are substances or mixture of substances intended for preventing, destroying, repelling or mitigating any pest.[1] A pesticide may be a chemical unicycle, biological agent (such as a virus or… …   Wikipedia

  • Super Outbreak — Trajectoires des 148 tornades Type Tornades multiples Formée 3 et 4 avril  …   Wikipédia en Français

  • December 2010 lunar eclipse — Total lunar eclipse 2010/12/21 [1] Saros (member) 125 (48) Recent <S <T < > T> S> …   Wikipedia

  • Liste der Sonnenfinsternisse des 21. Jahrhunderts — Verlauf der Sonnenfinsternis vom 1. August 2008 im Abstand von jeweils drei Minuten fotografiert, aufgenommen in Nowosibirsk Diese Liste der Sonnenfinsternisse des 21. Jahrhunderts enthält alle Sonnenfinsternisse, die in diesem Jahrhundert von… …   Deutsch Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”