5lo

5lo

Computer virus
Fullname = 5lo
Common name = 5lo
Technical name = 5lo
Family = N/A
Aliases =
Classification = Virus
Type = DOS
Subtype = Resident EXE
IsolationDate = October 1992
Isolation = Unknown
Origin = Unknown
Author = Unknown

5lo is a computer virus that increases file size and does little more than replicate. Size: 1,032 bytes

Infection

5lo infects resident .EXE files only. When it infects a file, it increases the file size by about 1000-1100 bytes (though a typical value is 1032 bytes. [ [http://www.f-secure.com/v-descs/5lo.shtml F-Secure Computer Virus Information Pages: 5lo ] ] ) At the file's direct end, this message can be found (resulting in the virus's name):

92.05.24.5lo.2.23MZ

Other strings can be found in the virus's code:

????????.EXE and *.EXE

5lo stays resident. Whenever a .EXE file is run, 5lo will infect it (and another .EXE file). The virus also changes the file's timestamp to the date and time of infection. After these infections, a counter within the virus starts. However, this counter is never checked, so the virus doesn't activate. 5lo appends its code into infected files. It also changes the field 0Ch in the .EXE file's header to FFAAh. The virus identifies itself from memory by using the interrupt INT 21, AX=3521h which it has hooked. All the checks work correctly and the virus won't infect files multiple times and it installs itself to memory only once.

When 5lo is running in memory, it isn't discoverable by typing in MEM /C. This is because when the virus installs, it ties itself to the operating system. Free memory decreases by about 2 KB.

References


*cite web|url=http://www.f-secure.com/v-descs/5lo.shtml|title=F-Secure page on 5lo|author=|accessdate=

Links

* [http://www.symantec.com/security_response/writeup.jsp?docid=2000-122015-2957-99&tabid=2 Symantec's page on 5lo]


Wikimedia Foundation. 2010.

Игры ⚽ Нужно решить контрольную?

Look at other dictionaries:

  • P-38 Lightning survivors — Lockheed P 38 Survivors highlights the history of many well known flying and static displayed P 38 Lightnings in the United States. A list is also provided of other P 38s on display around the world; including location, model and serial numbers,… …   Wikipedia

  • P-80 Shooting Star — infobox Aircraft name = P 80 (F 80) Shooting Star type = Fighter national origin = United States manufacturer =Lockheed caption = P 80A 5LO 44 85747 designer = Clarence Kelly Johnson first flight = 8 January avyear|1944 introduction = avyear|1945 …   Wikipedia

  • Red Bull GmbH — Infobox Company company name = Red Bull GmbH picture of product = company company type = Private slogan = Red Bull Gives You Wiiings. No Red Bull. No Wings. foundation = 1984 founder = Dietrich Mateschitz Chaleo Yoovidhya location = Fuschl am See …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”