Name : L.A.D.S. Aliases : No Aliases Type/Size : Boot virus/ 1024 bytes Incidence : No Incidence Discovered : 10-06-91 Way to infect: See below Rating : Not very dangerous Kickstarts : 1.2/1.3 Damage : Overwrites bootblock Manifestation: DisplayAlert Removal : Install the virus bootblock Comments : The L.A.D.S virus pretend to trick you by giving a DisplayAlert as to be a virus hunter bootblock, but don't trust it. When you boot with a L.A.D.S infected disk you will get the following message (1): (1) "L.A:D:S Virus Hunter No virus in memory Press any mouse button" After infection and the 5.th resets your mouse moving will be affected and after the 8.th resets you will get the following DisplayAlert (2): (2) "AMIGA COMPUTING Presents: The GREMLIN Virus All Code (c) 1989 By Simon Rockman: Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LADS} of the L.A.D.S. virus. Push left mouse button to return. Name : L.A.D.S. Aliases : No Aliases Type/Size : Boot virus/ 1024 bytes Incidence : No Incidence Discovered : 10-06-91 Way to infect: See below Rating : Not very dangerous Kickstarts : 1.2/1.3 Damage : Overwrites bootblock Manifestation: DisplayAlert Removal : Install the virus bootblock Comments : The L.A.D.S virus pretend to trick you by giving a DisplayAlert as to be a virus hunter bootblock, but don't trust it. When you boot with a L.A.D.S infected disk you will get the following message (1): (1) "L.A:D:S Virus Hunter No virus in memory Press any mouse button" After infection and the 5.th resets your mouse moving will be affected and after the 8.th resets you will get the following DisplayAlert (2): (2) "AMIGA COMPUTING Presents: The GREMLIN Virus All Code (c) 1989 By Simon Rockman: Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LADS} of the L.A.D.S. virus. Push left mouse button to return. Name : Lame Blame Aliases : Taipan Lame Blanme Type/Size : Boot/1024 Clones : Cheater Hi Jacker Symptoms : No Symptoms Discovered : 17-07-91 Way to infect: Boot infection Rating : Harmless Kickstarts : 1.2/1.3/2.0 Damage : Overwrites boot. Removal : Install boot. Comments : The LameBlame virus allocates CHIP-Memory for it`s location. After Copying the virus into this AREA it patches the CoolCapture vector and the DoIO() to infect other disks. The whole virusbootblock will be crypted by an byte depending of $dff006 so you can`t read any texts in the bootblock. The virus isn`t dangerous for HD-Users because it tests for the trackdisk.device. After every 8th Alert the virus gives ount an ALERT: "LameBlame! by Tai-Pan - Nimber of Copys:0002" Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LameBlame} of the LameBlame virus. Push left mouse button to return. Name : LameGame Aliases : No Aliases Type/Size : Boot/1024 Original : TimeBomb V1.0 Symptoms : No Symptoms Discovered : ? Way to infect: No infection Rating : Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Overwrites Rootblock. Manifestation: - Removal : Install boot. Comments : This is another TimeBomb-Clones. For further information please read "TimeBomb"-Virus. Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LameGame} of the LameGame virus. Push left mouse button to return. Name : Lamer Bomb Aliases : Gotcha Lamer Clones : No Clones Type/Size : Trojan/2128 Symptoms : No Symptoms Discovered : 16-11-90 Way to Infect: No infection Rating : Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Fastformat of disk(s). Removal : Delete File. Comments : -> See Gotcha Lamer. Name : Lamer Exterminator 1 Aliases : No Aliases Type/Size : Boot/1024 Clones : Guardians Boot Aids Symptoms : No Symptoms Discovered : 05-01-90 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 1 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted. Name : Lamer Exterminator 2 Aliases : No Aliases Type/Size : Boot/1024 Clones : No Clones. Symptoms : No Symptoms Discovered : 16-03-90 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 2 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted. Name : Lamer Exterminator 3 Aliases : No Aliases Type/Size : Boot/2048 Clones : No Clones Symptoms : No Symptoms Discovered : 11-10-90 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks + Block 2, 3. Removal : Install boot. Comments : The Lamer Exterminator 3 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. This version of the virus saves the original bb in block 2 and 3. The Original Bootblock will be executed, too. Name : Lamer Exterminator 4 Aliases : No Aliases Type/Size : Boot/1024 Clones : Starcom Return Symptoms : No Symptoms Discovered : 17-02-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 4 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted ($DFF007). Memory-Address over StructMemList. Name : Lamer Exterminator 4 Aliases : No Aliases Type/Size : Boot/1024 Clones : Starcom Return Symptoms : No Symptoms Discovered : 17-02-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 4 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted ($DFF007). Memory-Address over StructMemList. Name : Lamer Exterminator 5 Aliases : No Aliases Type/Size : Boot/1024 Clones : No Clones Symptoms : No Symptoms Discovered : 07-05-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 5 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted ($DFF007). Memory-Address over SysStkLower. Name : Lamer Exterminator 6 Aliases : No Aliases Type/Size : Boot/1024 Clones : Starcom 4 Symptoms : No Symptoms Discovered : 29-05-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 6 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted ($DFF007). Memory-Address over SysStkLower. Some routines are new. CoolCapture-text etc... Name : Lamer Exterminator 6 Aliases : No Aliases Type/Size : Boot/1024 Clones : Starcom 4 Symptoms : No Symptoms Discovered : 29-05-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 6 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted ($DFF007). Memory-Address over SysStkLower. Some routines are new. CoolCapture-text etc... Name : Lamer Exterminator 7 Aliases : Selfwriter, Pseudo-self-writer Type/Size : Boot/1024 Clones : No Clones Symptoms : No Symptoms Discovered : 09-07-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Damages Blocks. Removal : Install boot. Comments : The Lamer Exterminator 7 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors to stay resident. Sometimes the virus fills up a calculated block ($DFF006) with the word "LAMER". No salvage possible. The whole Bootblock is crypted ($DFF007). Memory-Address over StructMemList and AllocABS. Name : Lamer Exterminator 8 Aliases : No Aliases Type/Size : Boot/1024 Clones : No CLones Symptoms : No Symptoms Discovered : 12-10-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Fastformat of disk(s). Removal : Install boot. Comments : The Lamer Exterminator 8 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus formats the disk. The whole Bootblock is crypted ($DFF006). Name : Lamer Exterminator 8 Aliases : No Aliases Type/Size : Boot/1024 Clones : No CLones Symptoms : No Symptoms Discovered : 12-10-91 Way to infect: Boot infection Rating : Dangerous Kickstarts : 1.2/1.3 Damage : Overwrites boot + Fastformat of disk(s). Removal : Install boot. Comments : The Lamer Exterminator 8 Virus is a very dangerous virus. It patches the BeginIO()-Vector from the trackdisk.device to infect other disks. The virus uses the KICK-Vectors + SumKickData to stay resident. Sometimes the virus formats the disk. The whole Bootblock is crypted ($DFF006). Name : Lamer Exterminator Endcli Aliases : No Aliases Type/Size : Trojan/2260 Clones : No Clones Symptoms : No Symptoms Discovered : Not known Way to infect: No infection Rating : Less Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Installes the Lamer Exterminator 1-Virus Removal : Delete File. Comments : If you are executing this file it executes the Lamer 1 virus and after that the Original EndCli. Name : Lamer Exterminator Loadwb Aliases : No Aliases Type/Size : Trojan/4172 Clones : No Clones Symptoms : No Symptoms Discovered : 02-08-89 Way to infect: No infection Rating : Less Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Installes the Lamer Exterminator 1-Virus Removal : Delete File. Comments : If you are executing this file it executes the Lamer 2 virus and after that the Original LoadWB. Name : Laureline Female Aliases : No Aliases Type/Size : Boot/1024 Clones : No Clones Symptoms : No Symptoms Discovered : 17-04-94 Way to infect: Boot infection Rating : Less Dangerous Kickstarts : 1.2/1.3/2.0/3.0 Damage : Overwrites boot. Removal : Install boot. Comments : If you are booting with an infected disk the virus copies itself (always) at the $6B500 chip-adress. After copying it changes the DoIO ()-Vector from the exec.library for infection. The virus is resident by using the CoolCapture-Vector. The virus just infects your disk if you are booting with it or if you`re showing the bootblock for example with a boot block utility. The virus checks your configuration and saves it. When the virus-copy-value is bigger than 77 the virus gives out an alert by pressing the right mousebutton. Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LaurelineFemale} of the Laureline Female virus alert. Push left mouse button to return. This text isn`t visible in the bootblock and varies. Name : Laureline Male Aliases : No Aliases Type/Size : Boot/1024 Clones : No Clones Symptoms : No Symptoms Discovered : 17-04-94 Way to infect: Boot infection Rating : Less Dangerous Kickstarts : 1.2/1.3/2.0/3.0 Damage : Overwrites boot. Removal : Install boot. Comments : If you are booting with an infected disk the virus copies itself (always) at the $6E800 chip-adress. After copying it changes the DoIO()-Vector from the exec.library for infection. The virus is resident by using the CoolCapture-Vector. The virus just infects your disk if you are booting with it or if you`re showing the bootblock for example with a boot block utility. The virus checks your configuration and saves it. When the virus-copy-value is bigger than 35 the virus gives out an alert by pressing the right mousebutton. Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LaurelineMale} of the Laureline Male virus alert. Push left mouse button to return. This text isn`t visible in the bootblock because it is crypted. Name : Leviathan Aliases : No Aliases Clone : No Clones Type/Size : Boot+File/1024 & 1056 (File) Symptoms : No Symptoms Discovered : 28-10-93 Way to Infect: Boot & Link infection Rating : Harmless Kickstarts : 1.2/1.3 -> Kick 2.0 guru at reset Damage : Overwrites boot Manifestation: In the boot & file you can read "-=- LEVIATHAN -=-" Removal : Delete file and/or install boot Comments : The virus Uses the coolcapture to be resident. There is a coded text in the Boot/File: "YOU ARE THE OWNER OF A NEW GENERATION OF VIRUS!" "IT FUCKS UP YOUR STARTUP-SEQUENCE!!" The virus uses the DoIO(EXEC)-Vector to infect the boot of the disks. The virus patches the OldOpenLib(EXEC)-Vector too. If this vector is used, the virus tries to create a file (s/$c0) and to modifiy the startup-sequence with the virusname. Name : Liberator v1.21 Aliases : Memcheck Type/Size : File/10936 Discovered : 18-10-92 Way to infect: .fastdir Rating : Dangerous Kickstarts : ? Damage : It looks for various virus killers and removes them The virus has a counter build in (.fastdir) when it reaches 15 the text is shown and the disk is destroyd Manifestation: The text: Congratulations your hard disk has been liberated of virus protection!! Hello from the Liberator virus v1.21. The anti-anti-virus is born! Lets play trash the hard disk and ram the disk heads. I`m outta here, kiss mine you lamer Remowal : Delete it General comments: Not resident Name : Liberator Virus V3.0 Aliases : Cv (Check Vectors rev 5.1) Type/Size : File/10712 Incidence : 18-07-92 Discovered : 18-10-92 Way to infect: .fastdir Rating : Dangeruos Kickstarts : KS2.04: 68030: Damage : Tries to hide its evil purpose by the following menu: Check Vectors rev 5.1 All Rights Reserved more TUPperware © by Mike Hansell Reset vectors ok, Nothing resident, Trackdisk.device not intercepted, DoIO ok, VBlank ok, dos.library not intercepted. System appears to be free of viruses and trojans! The real purpose is to place .fastdir files in ALL harddisk partitions. Length: 2/3 bytes. Startvalue on all Harddisks in .fastdir $310a = 1 Return. Note: .fastdir has after this 2 empty-signs ($20) in the name. Writes in the following: DH0: s/startup-sequence: cv >NIL: execute s:startup-sequence2 cv >NIL: ;fast to the end !!!! endcli >NIL: Manifestation: "Congratulations your hard disk has been liberated of virus protection!! Hello from the Liberator virus v3.0 - Digital Deviant The anti-anti-virus is here again! Lets play trash the hard disk and ram the disk heads Only hardcore belgian rave can truly liberate the mind! The liberator 15/01/92" Remowal : Remove the Liberator 3 virus, all .fastdir and s.-seq. Remember to change back the startup-sequence to good old original ones. General comments: Does NOT survive in the memory after changing of fastdir Name : Liberator Virus V5.01 Aliases : PV Type/Size : File/16924 Discovered : 18-10-92 Way to infect: Several files Rating : Dangerous Kickstarts : 1.2/1.3/2.0 Damage : A new update of Liberator V3.0 The real name is PV. Tries to hide its evil purpose by the following menu: "PV (Protect Vectors) v1.02 by Peter Stuer July 22, 1992 FREEWARE Reset vectors ok, Nothing resident, Trackdisk.device not intercepted, DoIO ok, VBlank ok, low interrupts ok, dos.library not intercepted. monitoring vectors... Fully Kickstartv2.xx compatible, stops all viruses, checks disk-validators, Use run to push this program into the background" The analyze tests is done at device df0: and df1: The viruses writing :c/run, :c/br (runback), :s/.info .info-length: 4 Bytes, .info-Startvalue: $00000064 The original s-startup : cls After infection: br c:pe cls Manifestation:The text: "Congratulations this disk has been liberated of virus protection!! Hello from the Liberator virus v5.01 - Random Disaster The anti-anti-virus is here again! Lets play trash the hard disk and ram the disk heads The piracy curse Liberator V - The future is near. Look out for Liberator VI - The final nightmare ... coming soon from a lame swapper near you! Respect to the virus masters Lamer Exterminator,crime & Contrast. And remember - be excellent to each other! The liberator 27/07/92 Virus Generation :" Remowal : Remove the Liberator 5 virus, .info and all .fastdir and s.-seq. Remember to change back the startup-sequence to good old original one. General comments: The virus changes its name like c/PV, /PE, /PB and so on, that means the last letter is always changed, maybe to hide itself Name : Little Sven Aliases : Cameleon Type/Size : Boot/2048 Clones : No Clones Symptoms : No Symptoms Discovered : 07-05-92 Way to infect: Boot infection Rating : Very Dangerous Kickstarts : 1.2/1.3 not properly with 2.0, but it works. Damage : Overwrites block 3 & 4 + crypts blocks. Removal : Use good Viruskiller. Comments : The Little Sven-Virus is a very dangerous one. The length of the virus is 2048 byte. The virus saves the original bootblock of every infected disk in block 2, 3 so this bootblock will executed even when the disk is infected. If you are starting a Little Sven infected disk the virus makes itself resident by changing the CoolCapture-Vector. After that the virus loads the OriginalBB from block 2 & 3 To infect other disks the virus uses the BeginIO() vector from the trackdisk.device. Additionally the virus patches the DisplayAlert()-Vector from the intuition.library and the Supervisor()-Vector from the exec.library. After initialising all this virus routines the originalBB will be executed. DisplayAlert-Patch: -This patch forbids all alerts. That means no alerts will be shown anymore. Supervisor-Patch: -This patch sets the CoolCapture to the virusvalue. BeginIO-Patch (Infections-Patch): Case 1: You are insetring a unprotected disk. 1) The virus checks if the disk is already infected If Yes: The virus checks if the bb-access was a read-access. -> Yes: the virus loads the OriginalBB from block 2, 3. That Means if you want to see the booblock of an infected disk the virus shows you always the original one. -> No: End. If No: The virus checks if this is the 3rd infection. -> Yes: The virus will execute a routine which writes data on your disk. -> DAMAGED!!! -> No: The virus loads the OriginalBB of the disk, copies it to block 2, 3 and infect the disk. Block 2, 3 are now damaged. No salvage possible. The Bootblock AND the original bootblock are crypted. (The virusbb is crypted depending of $DFF007) BeginIO()-Patch (Infections-Patch): Case 2: A block will be loaded from an unprotected disk. 1) The virus will check the actual block for a byte-mark ($ABCD). If Yes: The block was already crypted, so decrypt. If No: The virus checks for the value 8 in the 1st longword (= DATA) -> Yes: Inserts the byte-mark $ABCD and crypts the block. -> No: End. That means you can read such blocks just when the virus is active in memory. But now imagine you have an infected disk with crypted blocks on it. Now you copy a normal DOS-BB on this disk and you are booting with it. ----> YOU WILL GET A READ/WRITE ERROR or A CHECKSUM ERROR. So please use a good viruskiller which can also decrypt such blocks. E.G. VT or VirusWorkshop. In the end of the decrypted bootblock you can read: "The Curse of Little Sven!" -> See also Xcopy5.6-Trojan which installs this virus... Name : Logic bomb Aliases : Paradox 1 Type/Size : Boot/1024 Clones : No Clones Symptoms : No Symptoms Discovered : 08-04-9 Way to infect: Boot infection Rating : Harmless Kickstarts : 1.2/1.3/2.0 Damage : Overwrites boot. Removal : Install boot. Comments : -> See Paradox 1 @DATABASE "Virus Info Base" @NODE MAIN "LoopCombo" Name : Loop Combo Aliases : No Aliases Type/Size : Disk-Validator/1848 Clones : No Clones Symptoms : No Symptoms Discovered : 26-04-94 Way to infect: No infection Rating : Very Dangerous Kickstarts : 1.2/1.3 Damage : Fastformat !! Removal : Delete Disk-Validator. Comments : This is another Disk-Validator "virus". The only thing it does is to format your disk. Imagine you have a good disk with this Validator on it. Now it maybe will happen: Your diskstrukture gets an error. If you are now inserting the disk, the AmigaDOS tries to load the Disk-Validator. But this devil only formats your disk and show you an alert: Click on this gadget to see a @{" Demo " SYSTEM V-IFF:LoopCombo} of the Loop Combo virus alert. Push left mouse button to return. Name : Love Machine Aliases : No Aliases Type/Size : Boot/1024 Original : Warhawk Symptoms : No Symptoms Discovered : 11-08-94 Way to infect: Boot infection Rating : Less Dangerous Kickstarts : 1.2/1.3/2.0 Damage : Overwrites boot. Removal : Install boot. Comments : The Lovemachine-Virus is a Warhawk-Clone. -> See Warhawk. Name : Loverboy & the sex machine Aliases : 16 Bit Crew Clone Type/Size : BB/1024 Incidence : No Incidence Discovered : 28-08-91 Way to infect: Bootblock Rating : Less dangerous Kickstarts : 1.2/1.3/2.0 Damage : Bootblock Remowal : Install the disk General comments: -> See 16 Bit Crew for further information. Name : LSD Aliases : No Aliases Type/Size : Boot/1024 Original : SCA Symptoms : No Sypmtoms. Discovered : 24-11-89 Way to infect: Boot infection Rating : Harmless Kickstarts : 1.2/1.3/2.0 Damage : Overwrites Bootblock. Removal : Install Boot. Comments : A.G.A.I.N. a boring SCA-Clone. Name : Lummin Aliases : XaCa Origin : DISK-KILLER V1.0 Type/Size : Bomb/1368 Symptoms : A CLI-message appeares Discovered : No date found yet Way to Infect: No infection Rating : Very Dangerous Kickstarts : 1.2/1.3/2.0/3.0 Damage : Fastformat of your disks. Removal : Delete file Comments : If you start the virusfile and your disk in df0: isn`t write-protected then the virus start a fastformat routine. The disk-data will be irrevocable destroyed !!! After the fastformat a message in the CLI appeares: "Catch me if you can... etc." In fact this virus is a clone of the DISK-KILLER virus. (I haven`t got it.) Click on this gadget to see a @{" Demo " SYSTEM V-IFF:Lummin} of the Lummin virus. Push left mouse button to return. Name : Lupo Aliases : No Aliases Type/Size : File/1420 Original : Nano Symptoms : No Sypmtoms. Discovered : 21-05-93 Way to infect: File infection Rating : Harmeless Kickstarts : 1.2/1.3/2.0 Damage : No Damage. Removal : Install Boot. Comments : The LUPO-Virus is a NANO-clone. -> See NANO NOTE: THE INVISIBLE FILENAME OF THE NANO-VIRUS WAS CHANGED INTO SPACE-KEYS ($20) THAT MEANS THE LUPO VIRUS WON`T SPREAD. (DAMN LAMER FUCK YOU!) Name : LZ 2.01 Trojan Aliases : No aliases Type/Size : Trojan/37380 Byte Discovered : 21-09-91 Way to infect: None Rating : Less Dangerous Kickstarts : all Damage : Destroy the files you try to pack. Remowal : Delete it. Name : LZ Aliases : No Aliases Type/Size : Link/400 Clones : No Clones Symptoms : No Symptoms Discovered : 14-07-91 Way to infect: Link infection Rating : Less Dangerous Kickstarts : 1.3 Removal : Use good Viruskiller. Comments : The LZ-Virus patches the GlobVec6 (Write) vector from the dos.library. Now Imagine you`re saving a programm. (E.G. You are packing it and save it on DH0:). Now, the virus checks if the 1. CodeHunk is longer as 1000 bytes. If it is greater than 1000 bytes, the virus searches for RTS or JMP -XY(a6) and insert a BRA. That means (FOR NON-ASSEMBLERS!) the virus inserts a jump to make sure that the virus will be activated if you are starting the infected file. ( -> See FileGhost ). The virus doesn`t infect 2.0 systems or higher =:-) That`s because of the GlobalTabel-PATCH.