Fandom

Malware Wiki

V-Sign

1,335pages on
this wiki
Add New Page
Comment1 Share


V-Sign also known as Cansu and Sigalit is a boot sector virus from 1992. It is slightly polymorphic and displays an image after infecting 64 diskettes.

Behavior

When the system is booted from an infected diskette, V-Sign becomes memory resident, taking up 2,048 bytes. It installs itself in high memory, just below the DOS 640k boundary. The virus infects the hard disk as soon as the user accesses it.

V-Sign saves 38 bytes of the master boot record in its own code as it overwrites Side 0, Cylinder 0, Sector 1. Its code takes up two more sectors, so it places the rest of itself on Side 0, Cylinder 0, Sectors 4 and 5.

Diskettes are infected as they are accessed. It works the same way as when it infects a hard disk, except on the floppy, it stores its two other sectors on the last sectors of that disk's root directory (sectors 10 and 11 on 360k 5.25 inch floppies for example).

Payload

When the virus has infected 64 diskettes, it will display an ASCII "V" sign, and the system is hanged.

Name and Origin

V-Sign most likely comes from Turkey, but India has also been considered a possible home country of this virus. It was first reported in Canada. V-Sign takes its name from the image it displays. Its other name, Sigalit is Hebrew for the violet plant. Cansu is a Turkish female name.

References

McAfee Antivirus, V-Sign. 1992.06.15

F-Secure Antivirus. F-Secure Virus Descriptions : V-Sign.

Learn Hebrew Names. Sigalit - סִיגָלִית.

Videos

PC Virus V-Sign00:13

PC Virus V-Sign

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.