Name : G-Zus-Packer Aliases : NO Aliases Type/Size : Trojan/15016 bytes Incidence : Delete all the files you try to pack Discovered : By Flavio Stanchina, Italy 05-11-93 Way to infect : No Spreading Rating : Not dangerous. Only the first attemt! Kickstarts : 1.2/1.3/2.04 Damage : See below Manifestiation : Pretend to be a packer program Removal : Delete this trojan General comments: This trojan is found at BBS with the following name: "g-zus001.lha" 12.252 bytes. The G-Zus Trojan pretend to be a packer/unpacker. But... don't trust it! Actually it delete your original file, keep the original file name and write a new file only 30 bytes. In this file you can read: "This Is Magic!". If you start the G-Zus-Packer trojan you will get the following message on the screen: "G-Zus The Final Compressor/Decompressor. Anything else is futile... ...you will be assimilated" IN THE DOC YOU CAN READ: The G-Zus compactor/decompactor: v0.01 -------------------------------------- Author: Jean-Christophe Clement Public release: May 9, 1993. This trojan is proably NOT written by the above mentioned man, because in the doc you can find the address of the man too. How silly can people be? ....Proably this trojan is done like a revenge or malice of the mentioned man. Name : Gadaffi Aliases : No Aliases Type/Size : Boot/1024 Clones : MAD, Boomer Symptoms : No Symptoms Discovered : 03-04-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : Only Kickstart 1.2 Damage : Overwrites boot/"Floppymusic!" Removal : Install boot. Comments : The virus uses the coolcapture and the kick vectores to stay resident in memory. The Gadaffi virus has a counter which after the 7.th reset abuses the drive engine through stepping, and this can scratch the diskette so it is then unusable. Some generates some noice on the speakers,- this is much more like the behavior of Byte Bandit, but mostly it steps the drive because of wrong access to trackdisk.device by inserting another disk in drive. It`s very simple coded. Depending of infections the virus starts a "Floppymusic-routine". This routine is very dangerous and even can cause DRIVE-ERRORS!! (NO JOKE!). This routine is also used in the well-known "A.I.S.F. or InterLamer" Virus. Please be careful. In the bootblock you can read: GADAFFI VIRUS! Spreading strictly forbitten !!!(c)88 JG For UpdateSevice call: 0222/1597 Have FUN... (The phone number of the austrian lotto association) Name : Gadaffi-MadII Aliases : Gadaffi Type/Size : Bootblock, 1024 bytes ( two blocks, 0,1 ) Symptoms : Head step-instructions after 7.th reboot Discovered : 08-04-91 Way to infect: See Gadaffi Rating : Dangerous Kickstarts : 1.2 only Damage : Nothing in itself Removal : Reinstall the diskette Comments : As Gadaffi except the step-instructions after the 7.th reboot, which results in a black screen. A little annoying, especially while inserting and removing the diskette, which can scratch the surface. Name : Gandalf Aliases : No Aliases Type/Size : Boot/1024 Clones : No Clones Symptoms : No Symptoms Discovered : 29-12-91 Way to infect: Boot infection Rating : Less Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot. Removal : Install boot. Comments : Some copies pops up a requester while others makes a display beep. Sometimes Gandalf virus will format the disk when counter is incremented to 7. DisplayAlert or nothing before disk is running ihibited. The Gandalf-Virus uses the coolcapturevector to stay resident in memory. The PutMsg-Vecto r is used to infect other disks. Additionally the ExitIntr()-Vector is used to set the coolcapture and the DoIO()-Vector always to the virusvalue. In the decoded bootblock (eor-loop) you can read: Gandalf`s Rache 1.5.90 - Ser.Nr. B00128 - Hi Butonic & Angel! Name : GCA Aliases : No Aliases Type/Size : Boot/1024 Original : Forpib Symptoms : No Symptoms Discovered : - Way to infect: Boot infection Rating : Less Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot. Removal : Install boot. Comments : The GCA virus is a Forpib clone. -> See Forpib. Name : Genestealer Aliases : No Aliases Type/Size : Boot/1024 Clones : No Clones Symptoms : Like it is a KS 1.3 with NTSC specifications? Discovered : 23-04-92 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Overwrites boot + Rootblock. Removal : Install boot. Comments : Infects every none write-protected disk inserted in any drive. Can probably DAMAGE harddisks. The virus tests the frequency on the El-net. In this way the Amiga system distinguishes between American and European (NTSC/PAL) systems and if it isn't American the Rootblock can probably be damaged. Sometimes the Amiga can't detect either it works in Europe or in the US under Sys-1.3. It will then open its initial screen in NTSC in Europe. Most likely the virus will behave that way, too, and that's no good. The Genestealer-Virus copies itself always to the same memory-address => $7EC00. It uses the CoolCapture to stay resident in memory . For infection the virus patches the DoIO()-Vector from the exec.library. When the virus is active it pretends to be a normal DOS-Bootblock. The virus checks for a value in the Vertikal-Blank-Int. If this value isn`t 50 the virus destroys the rootblock (Only DD-Disks!). If you are pressing the left mouse-button while you are booting the virus executes an endless-loop by showing a green screen. In the end of the Bootblock you can read: "GENESTEALER VIRUS!!! by someone..." Name : Genetic Protector 2.0 Aliases : No Aliases Type/Size : Boot/1024 Original : Dotty Symptoms : No Symptoms Discovered : 14-03-92 Way to infect: Boot infection Rating : Less Dangerous but can probably infect harddisks. Kickstarts : 1.2/1.3/2.0 Damage : Overwrites boot. Removal : Install boot. Comments : The Genetic Protector virus is a Dotty virus clone. -> See Dotty. Name : Germany Aliases : No Aliases Type/Size : Boot/1024 Original : Forpib Symptoms : No Sypmtoms. Discovered : 17-10-92 Way to infect: Boot infection Rating : Harmeless Kickstarts : 1.2/1.3 Damage : Overwrites Boot. Removal : Install Boot. Comments : The Germany-Virus is another Forpib clone. -> See Forbip. Name : Glasnost Aliases : No Aliases Type/Size : Boot/2048 Clones : No Clones Symptoms : No Symptoms Discovered : 23-06-92 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Overwrites boot + block 2 & 3. Removal : Install boot. Comments : If you are booting with a Glasnost-infected disk the virus copies itself to $7F000 and changes the KICK- Vectors to stay resident. On the next reset the virus patches the DoIO()-Vector to infect other disks. Now imagine you are inserting an unprotected disk with e.g. the X-Copy Bootblock. Now, the virus does the following: 1) Check for Write-Protection 2) Not protected: loads the bootblock form the current disk (X-Copy-Boot). 3) Saves 44 bytes from the original-bb in the own viruscode and insert in this place a virus-loader routine. 4) The virus saves 2048 bytes. (Virus+OrgBB) Block 2,3 are now DAMAGED !! NO salvage possible. If you are now booting with the infected disk the virus- loader routine copies the virus from the block 2,3 in $7F000 and jumpes at $7F000. Then the virus inserts the original code of the BB and executes it. Additionally the virus installs a new patch in the ZERO-PAGE ($6C) and will damages a block on every infection: First, the virus caclulates a block with the $DFF006 register. In this block the virus inserts the following longwords from $100: $11111111; $22222222; $44444444; $88888888 The ZERO-PAGE (see above) routine does the following: 1) Checks if a value reaches 45000 if this was true the virus blockades the system. 2) If the value becomes 60000 the virus shows some colors on the screen and make an endless loop. (You need a reset to escape from this routine!!) In block 3 you can read: "Glasnost VIRUS by Gorba!! First release" Name : Golden Rider Aliases : No Alises Clones : No Clones Type/Size : Link/868 Symptoms : No Symptoms Discovered : 22-11-92 Way to Infect: Link infection Rating : Less Dangerous Kickstarts : 1.2/1.3 Damage : No Damage Removal : Use a good viruskiller or delete infected programms. Comments : When it patches the DOS.library it infects via copying itself to the first hunk in an executable file. Activated this way it will stay resident in memory. When it is "ramdom" which file it inflicts you can have the virus for a very long time without remarking it. Furthermore, if it is a very rarely used function in the main program it has patched, it will never be activated anymore. It adds to the file its own lengt and modify the functions return until after it has laid itself resident. This way executed it will patch every new executed file during the same session. ( Same boot period ). An early Golden Rider version only inflected files less than 100.000 bytes under KickStart1.2. The newer ones seems not to have these limits. The virus copies itself to $7C000 and changes the CoolCapture to stay resident. For infection the virus patches the Open()-Vector from the dos.lib. For write-protection check the virus additionally patches the DoIO()-Vector. Imagine you are inserting a disk: Now, the virus checks with the help on DoIO() if the disk is write-protected. The virus now "remebers" if the disk was protected or not. Now you are opening a program (e.g. with an ASCII-Editor). The virus checks the write-protection value. If the disk wasn`t write-protected the virus checks for this signs & numbers in the program-name: "/", ":", "0", "1" or all letters greater than $40. If any of these letters/signs are in the file name the infection will be canceled. If not the virus links itself behind the 1. Hunk by searching a RTS. (Like Crime & File Ghost). The virus just infects files which are: - executeable - smaller than 100000 bytes In the file you can read: ">>> Golden Rider <<< by ABT" REMOVAL: There is no guarantee that viruskillers can reestablish the files, so use at first a copy. Else the file - sizes with your original software copies. Is it to say that it is no guarantee to compare with your backup set? Name : Gotcha Lamer Aliases : Lamer Bomb Clones : No Clones Type/Size : Trojan/2128 needs the program: Minidemo.Exe 773 bytes Symptoms : No Symptoms Discovered : 16-11-90 Way to Infect: No infection Rating : Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Fastformat of disk(s). Removal : Delete the infected file(s). Comments : Gotcha Lamerinfects only the programmes in c/dir: Dir Execute, Run, and CD. When Minidemo.Exe has been runned the above-mentioned files will be increased with 372 bytes in length. (Never the less, some increased with only 336 bytes). By following execution of these programmes Diskdrive heads start to step and if the disk isn`t write- protected thevirus executes a fastformat-routine. Then you get an Alert: "HAHAHE... Gotcha LAMER!!!" pops up and the machine is crashed. Apparantly a variant "mini-demo.exe" should be able to destroy all files at none writeprotected devices when it detects a bootable disk and the virus is active in memory but it is a little blurred. The Gotcha Lamer-Virus consists of the DIR-Command and the virus itself. If you are starting the file the virus will allocate 1000 bytes and copies a DoIO()- Patch-Routine into this memory. After copying the virus patches the DoIO()-Vector by seting the DoIO()-Jump-Address to the allocated memory. Then the virus executes the DIR-Command. On the next bootblock-access the virus checks for write- protection. If the disk isn`t write-protected the virus executes a fastformat-routine. Then you get an Alert: "HAHAHE... Gotcha LAMER!!!" REPAIR: Some viruskillers will search for the name of the program, else they detect its presence in the memory. Copy your original files from the c: