Jerusalem (computer virus)
||This article may be too technical for most readers to understand. (September 2014)|
||This article needs attention from an expert in Computer security. (September 2013)|
|This article needs additional citations for verification. (September 2013)|
|Point of Origin||Israel|
|Operating system(s) affected||DOS|
Jerusalem is a DOS virus first detected in Jerusalem, in October 1987. On infection, the Jerusalem virus becomes memory resident (using 2kb of memory), and then infects every executable file run, except for COMMAND.COM. COM files grow by 1,813 bytes when infected by Jerusalem and are not re-infected. .EXE files grow by 1,808 to 1,823 bytes each time they are infected. The virus re-infects .EXE files each time the files are loaded until they are too large to load into memory. Some .EXE files are infected but do not grow because several overlays follow the genuine .EXE file in the same file. Sometimes .EXE files are incorrectly infected, causing the program to fail to run as soon as it is executed.
The virus code itself hooks into interrupt processing and other low level DOS services. For example, code in the virus suppresses the printing of console messages if, for example, the virus is not able to infect a file on a read-only device such as a floppy disk. One of the clues that a computer is infected is the mis-capitalization of the well-known message "Bad command or file name" as "Bad Command or file name".
The program contains one destructive payload that is set to go off on Friday the 13th, all years but 1987. On that date, the virus deletes every program file that was executed. Jerusalem is also known as BlackBox because of a black box it displays during the payload sequence. If the system is in text mode, Jerusalem creates a small black rectangle from row 5, column 5 to row 16, column 16. The rectangle is scrolled up by two lines.
As a result of the virus hooking into the low-level timer interrupt, PC-XT systems slow down to one fifth of their normal speeds 30 minutes after the virus has installed itself. The slowdown is less noticeable on faster machines. The virus contains code that enters a processing loop each time the processor's timer tick is activated.
Symptoms also include spontaneous disconnection of workstations from networks and creation of large printer spooling files. Disconnections occur since Jerusalem uses the 'interrupt 21h' low-level DOS functions that Novell Netware and other networking implementations required to hook into the file system.
Jerusalem was initially very common (for a virus of the day) and spawned a large number of variants. However, since the advent of Windows, these DOS interrupts are no longer used, so Jerusalem and its variants have become obsolete.
- 1 Aliases
- 2 Variants
- 2.1 Get Password 1 (GP1)
- 2.2 Suriv viruses
- 2.3 Sunday (Jeru-Sunday)
- 2.4 Anarkia
- 2.5 PQSR
- 2.6 Jeruspain (Jeru-Spanish)
- 2.7 Frère
- 2.8 Westwood (Jerusalem-Westwood)
- 2.9 Jerusalem-113
- 2.10 Jerusalem-Apocalypse
- 2.11 Jerusalem-T1
- 2.12 Jerusalem-T13
- 2.13 Jerusalem-Sat13
- 2.14 Jerusalem-Czech
- 2.15 Jerusalem-Frère.2
- 2.16 Jerusalem-Nemesis
- 2.17 Jerusalem-Captain Trip
- 2.18 Jerusalem-J
- 2.19 Jerusalem-Yellow
- 2.20 Jerusalem-Jan25
- 2.21 Friday-15th (Skism)
- 2.22 Carfield (Jeru-Carfield)
- 2.23 Mendoza (Jerusalem Mendoza)
- 2.24 Other variants
- 3 See also
- 4 References
- 5 External links
- Friday13th (Note: The name can also refer to two viruses that are unrelated to Jerusalem: Friday-13th-440/Omega and Virus-B)
Get Password 1 (GP1)
Discovered in 1991 this Novell NetWare-specific virus attempts to gather passwords from the NetWare DOS shell in memory upon user login, which it then broadcasts to a specific socket number on the network where a companion program can recover them.
The Suriv viruses are earlier, more primitive versions of Jerusalem. Suriv 1 and 2 triggers on April 1 while Suriv 3 triggers on Friday 13, switching off the computer on the 13th.
Files infected by Sunday grow by 1,636 bytes.
On each Sunday the virus displays one of the following messages during 30 minute intervals.
- Today is SunDay! Why do you work so hard?
- All work and no play make you a dull boy!
- Come on ! Let's go out and have some fun!
The variant is intended to delete every program as it is run. Software bugs prevent this from happening.
Sunday has several variants.
- Sunday.a - The version described above.
- Sunday.b - A version of Sunday which has a working program-deleting function.
- Sunday.1.b - Like Sunday.b, except that a bug regarding the Critical Error Handler, which causes problems on write-protected disks, has been fixed.
- Sunday.1.d - Like Sunday.1.a, except the same bug is fixed in a different way.
- Sunday.1.Tenseconds - Like Sunday.a, except the delay for the messages is now 10 seconds. In addition, the test for Sunday is correctly set for day 0 (zero) instead of 7 (seven).
- Sunday.2 - Like Sunday.1.a, except files grow by 1,733 bytes.
Anarkia is almost identical to the original Jerusalem. It uses the self-recognition code "Anarkia".
PQSR causes infected files to grow by 1,720 bytes. On the 13th of any month, the virus deletes any program run on the PC. Garbage is written to the master boot record and the nine sectors after the MBR. The virus uses "PQSR" as its self-recognition code.
If the virus is memory-resident, Jeruspain will delete any program run on the 26th of any month.
Frère plays Frère Jacques if the day is Friday or the 13th of any month.
Westwood causes files to grow by 1,829 bytes. If the virus is memory-resident, Westwood deletes any file run during Friday the 13th.
Programs will not run during Saturdays. The virus avoids PHENOME.COM instead of COMMAND.COM, and therefore infects COMMAND.COM.
Jerusalem-Apocalypse contains the text "Apocalypse!!". If the virus is memory-resident, it will delete any file on Friday the 13th.
If the virus is memory-resident, it will delete any file run on Tuesday the 1st.
The virus causes .COM and .EXE files to grow by 1,812 bytes. If the virus is memory-resident, it will delete any program run on Tuesday the 13th.
If the virus is memory-resident, it will delete any program run on Saturday the 13th.
If the virus is memory-resident, it will delete any program run on Friday the 13th. Jerusalem-Czech has a self-recognition code and a code placement that differ from the original Jerusalem.
Jerusalem-Frère plays Frère Jacques once per minute. A variant called Two Tigers plays the same tune.
The virus avoids NEMESIS.COM instead of COMMAND.COM, and therefore infects COMMAND.COM. Jerusalem-Nemesis contains the string "NEMESIS.COM".
Jerusalem-Captain Trip contains the strings "Captain Trips" and "SPITFIRE". Captain Trips is the name of the apocalyptic plague described in Stephen King's novel The Stand.
If the year is any year other than 1990 and the day is a Friday on or after the 15th, if a program is run, Jerusalem-Captain Trip creates an empty file with the same name as the program. On several other dates it installs a routine in the timer tick that activates when 15 minutes pass. On the 16th Jerusalem-Captain Trip re-programs the video controller. Jerusalem-Captain Trip has several errors.
The variant causes .COM files to grow by 1,237 bytes. .EXE files grow by about 1,232 bytes. The virus has no "Jerusalem effects."
Jerusalem-Yellow does not infect .EXE files. All files infected grow by 1,363 bytes apiece.
After the virus is loaded into memory, when 45 minutes pass or when 4,096 keystrokes are entered, Jerusalem-Yellow creates a large yellow box with a shadow in the middle of the screen and the computer hangs.
If the virus is memory-resident, it will delete any program run on January the 25th.
Friday-15th causes infected files to grow by 1,813 bytes. If the virus is memory-resident and a program is run on Friday the 15th, the virus will create a new file with the same name as the program.
The virus causes infected files to grow by 1,508 bytes.
If the virus is memory-resident and the day is Monday, the computer will display the string "Carfield!" every 42 seconds.
Mendoza (Jerusalem Mendoza)
The virus does nothing if the year is 1980 or 1989.
For all other years a flag is set if the virus is memory resident and if the floppy disk motor count is 25. The flag will be set if a program is run from a floppy disk.
If the flag is set, every program which runs is deleted.
If the flag is not set and 30 minutes passes, the cursor is changed to a block. After one hour, Caps Lock, Nums Lock, and Scroll Lock are switched to "Off".
- Lee Morton's Lover
- Slow 
- "Jerusalem". F-Secure. Retrieved 9 February 2013.
- "Jerusalem". ESET. Retrieved 9 February 2013.