The boot sector of an infected floppy |
Brain is the industry standard name for a computer virus that was released in its first form in January 1986[1], and is considered to be the first computer virus for MS-DOS. It infects the boot sector of storage media formatted with the DOS File Allocation Table (FAT) file system.
Contents |
Brain affects the IBM PC computer by replacing the boot sector of a floppy disk with a copy of the virus. The real boot sector is moved to another sector and marked as bad. Infected disks usually have five kilobytes of bad sectors. The disk label is changed to ©Brain, and the following text can be seen in infected boot sectors:
There are many minor and major variations to that version of the text. The virus slows down the floppy disk drive and makes seven kilobytes of memory unavailable to DOS. Brain was written by two brothers, Basit and Amjad Iqbal, who at the time lived in Chahmiran, near Lahore Railway Station, in Lahore, Pakistan. The brothers told TIME magazine they had written it to protect their medical software from piracy, and it was supposed to target copyright infringers only.[2] The cryptic message "Welcome to the Dungeon", a safeguard and reference to an early programming forum on Dungeon BBS, appeared after a year because the brothers licensed a beta version of the code. The brothers could not be contacted to receive the final release of this version of the program. (see Author Response)
Brain lacks code for dealing with hard disk partitioning, and avoids infecting hard disks by checking the most significant bit of the BIOS drive number being accessed. Brain does not infect the disk if the bit is clear, unlike other viruses at the time, which paid no attention to disk partitioning and consequentially destroyed data stored on hard disks by treating them in the same way as floppy disks. Brain often went undetected, partially due to this deliberate non-destructiveness, especially when the user paid little to no attention to the slow speed of floppy disk access.
The virus came complete with the brothers' address and three phone numbers, and a message that told the user that their machine was infected and to call them for inoculation:
This program was originally used to track a heart monitoring program for the IBM PC, and pirates were distributing bad copies of the disks. This tracking program was supposed to stop and track illegal copies of the disk. Unfortunately, the program also sometimes used the last 5k on an apple floppy, making additional saves to the disk by other programs impossible.
When the brothers began to receive a large number of phone calls from people in United States, United Kingdom and elsewhere, demanding them to disinfect their machines, they were stunned and tried to explain to the outraged callers that their motivation had not been malicious. Their phone lines were over loaded. The brothers are still in business in Pakistan as Brain NET Internet service providers with a company called Brain Telecommunication Limited.
In 2011, 25 years after Brain was released, Mikko Hyppönen of F-Secure travelled to Pakistan to interview Basit and Amjad for a documentary.[3][4] Being inspired by this documentary and its widespread, a group of Pakistani bloggers interviewed Amjad, under the banner of Bloggerine.[5]
Ashar is an older version of Brain. There are six variants each with a different message.