Threat Description

Fax Free

Details

Aliases: Fax Free, Mosquito
Category: Malware
Type: Virus
Platform: W32

Summary



Fax Free is a resident file virus, which infects EXE files which are either opened or executed. The virus is 1024 bytes long, of which 787 bytes are encrypted starting at offset 73. After every encryption or decryption virus compares one byte of its code with its unencrypted value. If this byte is wrong when expected right or right when expected wrong, the crypt loop is repeated (paranoid programming). Infected files contain the date when infection has happened.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details



Virus doesn't infect any files executed from floppy disk. Also, if the file begins with 'AN' or 'LD', it will not be infected. Before infecting any files, the virus calculates two bytes from the file code - if they add up to 255, virus considers the file is already infected and doesn't infect it. Virus infects files only if they're smaller than 512 kB.

Virus checks the system date when an infected file is executed. If the date equals to 25th or 26th of the month, the machine is crashed. Crashing the machine is done by filling 10 bytes of memory at 0000:0522 with 60h.

Virus contains two text messages. The first one is encrypted but the another one, 'Mosquito', is visible in infected files. The encrypted text says

 Hello this is the core Rev 3 26/4/91 P 0.98c
         P. 0.98 Rev 4 24IX89 bye bye


Variant:Topo,Pisello

Two variants, 1536 and 1024 bytes, which have not been analyzed yet.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More