Ping-Pong virus

From Wikipedia, the free encyclopedia

The Ping-Pong virus (also called Boot, Bouncing Ball, Bouncing Dot, Italian, Italian-A or VeraCruz) is a boot sector virus discovered on March 1, 1988 at the University of Turin in Italy. It was likely the most common and best known boot sector virus until outnumbered by the Stoned virus.

[edit] Replication method

Computers could be contaminated by it via infected diskette, showing up as a 1 KB bad cluster (the first one on the disk — the boot sector) to most disk checking programs. Due to being labelled as bad cluster, MS-DOS will avoid using it to boot up. It infects disks on every active drive and will even infect non-bootable partitions on the hard disk. Upon infection, the virus becomes memory resident.

[edit] Effect

The virus would become active if a disk access is made exactly on the half hour and start to show a small "ball" bouncing around the screen in both text mode (the ASCII diamond character "◊") and graphical mode. No serious damage is occurred by the virus except on '286 machines (and also V20, '386 and '486), which would sometimes crash during the ball's appearance on the screen. The cause of this crash is the "MOV CS,AX" instruction, which only exists on '88 and '86 processors. For this reason, users of machines at risk were advised to save their work and reboot, since this is the only way to temporarily get rid of the virus.

The original Ping Pong virus (Ping-Pong.A) only infects floppy disks. Later variants of this virus such as Ping-Pong.B and Ping-Pong.C also infect the hard disk boot sector as well. Whilst the virus is active, one cannot replace the boot sector — it either prevents writing to it or it immediately re-infects it.

Ping-Pong.A is extinct but the hard-disk variants can still appear.

[edit] References

Languages