Additional Details
Byway is an extremely fast infector of COM and EXE files. It uses similar
methods with spreading as the old DIR-II virus family, but it employs a
novel technique. When the user executes an infected program in a clean
machine, the virus creates a hidden file called CHKLISTx.MSx in the root
directory (where "x" is ASCII-255, a fake space). When it infects a file
it changes the directory entries and crosslinks all executable files to
point to the CHKLISTx.MSx file, which in turn contains the virus code.
Microsoft Anti-Virus uses almost the same name for its checksum file,
apparently the virus author wanted to make the user believe that the
new file is the MSAV's file.
Byway exhibits both polymorphic and full stealth behavior. When the user
runs an infected program for the first time, the virus executes instead,
reserving 3216 bytes for itself. From this time on, all disk operations
are rerouted to the original files, resulting in their correct execution
and functioning. This way the virus hides quite successful from detection.
Byway employs an improved tunneling technique in order to bypass most
antivirus programs and integrity checkers. In fact it is able to defeat
most antivirus programs that use their "own file system" to scan files
and in turn, it infects the home directory of all scanned executable
files. This way the virus spreads very quickly through exposed machines.
The Byway.A variant contains the following encrypted texts:
The-HndV
by:Wai-Chan,Aug94,UCV
In Byway.B variant, the second text is a bit different:
-By:W.Chan-
Byway activates on several dates after year 1996. The activation depends
on a parity check of a "generation counter" and a date triggered event:
(day of the month) = (((month's number)*2)+2)
For example 4th of January, 6th of February and 26th of December, so there
is a trigger date every month. When activated it displays a running text:
TRABAJEMOS TODOS POR VENEZUELA !!!
In english, this means "Let's all work for Venezuela". The text is
displayed on 3:00, 6:00, 9:00, 12:00, 15:00, 18:00 and 21:00 o'clock.
The virus also tries to play a tune through a sound card.
Byway is reported to be in the wild internationally, especially
in Venezuela, Mexico, Bulgaria, UK and USA.