Sorry, but I had no time to finish this analyse before
due to my studies and so on...

Entry...............: Penetrator
Alias(es)...........: Penetrator-2001
Virus Strain........: Smeg-1
Virus detected when.: June 2001
              where.: Poland (?)
Classification......: Linkvirus,memory-resident, not reset-resident
Length of Virus.....: 1. Length on storage medium:         6796 Bytes
                      2. Length in RAM:                  100KB< Bytes

--------------------- Preconditions ------------------------------------

Operating System(s).: AMIGA-DOS Version/Release.....: 2.04+
Computer model(s)...: all models/processors (MC68000-MC68060)
                      The virus is totally not aware of processor caches
                      and crashes even on 030 machines!

--------------------- Attributes ---------------------------------------

Easy Identification.: System crash, various alerts and requesters...

Type of infection...: Self-identification method in files:

                      - via unused bits of protection flags

                      Self-identification method in memory:

                      - checks special offset from the Task pointers
                        (equal to Smeg 1)

                      System infection:

                      - Several tasks and processes will be created.
                        The names are random beside support process
                        called 'help'...

                      - The packets will be redirected to processes
                        of virus to handle separately each device
                        LOCATE_OBJECT and EXAMINE_NEXT packets will
                        be used for infection
                        (equal to Smeg 1)

                      Infection preconditions:

                       - HUNK_CODE is found
                       - device is validated
                       - at least 10 free blocks
                       - $4eae call is found in the range of BSR.W

Infection Trigger...: The infection is based on the packet handling of
                      AMIGA OS. Every started or listed file can be
                      infected.
                      Support process performs some additional actions
                      like:
                      - direct infection LIBS:diskfont.library
                      - making new C:MakeDir (in my opinion this part
                        shows how lame the virus author is)

Storage media affected:
                      all DOS-devices

Interrupts hooked...: None

Damage..............: Permanent damage:
                      - Deletes files, shows alerts, reboots machine
                      Transient damage:
                      - Crashes the system (any Amiga with data cache)

Damage Trigger......: Permanent damage:
                      - some PC characteristic files are found
                        during checking of the devices, DateStamp check
                      Transient damage:
                      - Code is several times encrypted without
                        flushing of the caches...

Particularities.....: This virus is very lame coded and it's author
                      has broken several rules. Seems this is the lamest
                      virus I have seen during my AV activity...
                      There were added several encryptions, but only
                      the first decryptor (from the original SMEG) is
                      followed by CacheClearU...
                      The virus contains time routine and displays loads
                      of text in alerts and intuition requesters.
                      Also textfile can be generated. Author says that
                      Amiga rules but in my opinion he has nothing but
                      the UAE (which he hits with this virus) and has
                      never seen Amiga with processor better than 68020.

                      The virus is aware of the following task names:

                      'Viru'  'VIRU'  'viru'  'VT2.'  'VT3.'

                      'VT4.'  'VT5.'  'Xtru'  'BLVC'  'Bers'

                      'Nuke'  'Chec'  'Prot'  'Boo'

                      And the most funny thing - the virus holds whole
                      MakeDir command which is written to disk and
                      then infected...

Similarities........: Whole intelligent code is taken from SMEG-1
                      which source code was made public. No comments.

Stealth.............: None.

Armouring...........: I have noticed six encryption routines.
                      I must admit the second enryption is little bit
                      tricky due to somekind of EPO, but we've already
                      seen this trick in some bootblock viruses
                      (eg. DATACRIME)
                      No (slow-)polymorphism or any intelligent code
                      was found.
                      Somekind of armour were the bugs in the virus,
                      however if it managed to infect files the repair
                      was easily possible like with any other typical
                      hunk increasing viruses.

Comments............: Now will follow some ascii texts I have ran into
                      during reassembly:


Visible in requesters displayed by the virus:

 NuUWAGA WIRUS !!  ednak najwiëksze  oblem z pozyskan
 !..POWYÛSZA INFO   zagroûenie jaki  iem potrzebnego.
 RMACJA MA NA CEL  e niesie.ze sobâ  ci oprogramowani
 U ZAZNAJOMIENIE.   ten BAKCYL jest  a,CHËTNIE SÎUÛË 
       I OSTRZEÛE  :..* TOTALNA DES  POMOCÂ..Posiadam
 NIE CIË PRZED NI  TRUKCJA WSZYSTKI   ôwietny program
 EZWYKLE.          CH PARTYCJI NA H   ANTYWIRUSOWY,kt
    NIEBEZPIECZNY  D *..Majâc BOLES  óry.rozpoznaje p
 M WIRUSEM !!!.*   NE doôwiadczenie  onad 600 róûnych
 OSTRZEÛENIE !!!    z WIRUSEM,który   odnian wirusów.
 *.WYKRYÎEM WIRUS   tak mi.skopaî T  ..Wystarczy ûe p
 A W PAMIËCI !!!.  wardy Dysk ûe pr  odrzucisz mi kop
 PENETRATOR 2001   zez dwa tygodnie  ertë zwrotnâ.z n
 jest nowym polsk   nie potrafiîem.  aklejonym znaczk
 im wirusem linko  zmusiê AMIGI do   iem + dysk do na
 wym..* WIRUS ÎAT  boot'u z twardzi  grania.i 10 zî z
 A WEKTORY (FUNKC  ela.(2GB szlak t  a program ANTYWI
 JE) dos.library   rafiî).Postanowi  RUSOWY...Na Adre
 *.LOCK(),WRITE()  îem napisaê prog  s:.AMIGA SHAREWA
 ,READ(),EXAMINE(  ram rezydentny k  RE (dopisz).Korn
 ),EXECUTE()..POB  tóry miaî.za zad  atka 100.32-410 
 IEÛNY OPIS BAKCY  anie WYKRYÊ WIRU  Dobczyce..WAÛNE:
 LA:.-kodujâc sië  SA i ostrzec pot  (doîâcz na dysku
 ,uûywa techniki   encjalne ofiary.   zainfekowany pl
 polimorficznej.-  przed skutkami d  ik,w celu.ustale
 korzystajâc z ze  ziaîania tego HU  nia czy nie nast
 gara moûe przery  JOSTWA !!!..* JA  âpiîa MUTACJA TE
 waê Twojâ pracë,  K ZABIÊ ROBALA ?  GO SYFA).* KONIE
 .wyôwietlajâc gî   *.ABY WYKRYÊ I   C POMOCY *.ª....
 upie komunikaty   ZLIKWIDOWAÊ BAKC
 odautorskie.-dod  YLA NIEZBËDNY.JE
 atkowo zanim usa  ST DOBRY PROGRAM
 dowi sië na dobr   ANTYWIRUSOWY.ST
 e,testuje.system  ARAJ SIË.NIEZWÎO
  na obecnoôê pro  CZNIE ZDOBYÊ JAK
 gramów antywirus   NAJÔWIEÛSZE WER
 owych.-moûe spow  SJE.PROGRAMÓW.!!
 odowaê uszkodzen  !(VirusZ,VirusWo
 ie,lub utratë da  rkshop,XTruder).
 nych.UWAGA !!! J  ..Jeûeli masz pr


Visible as alerts:

 .¦Lß..Nu...- W I
  R U S -...´#» P
  E N E T R A T O
  R   2 0 0 1 «..
 æ.IDZIE,IDZIE LA
 TO Z DALA.....SÎ
 OÏCE Z GÓRY NAPI
 ERDALA...æ.ÛABA 
 CIPKE W WODZIE M
 OCZY....(KURWA J
 AKI ÔWIAT UROCZY
  !!!.......æ.ÎAP
  ZA CYCE ZAKONNI
 CE !!!..Cú.rB.<.


Visible in decoded virus:

 8øNu.ÀNu..ê`....
 C/MakeDir.S:Star
 tup-Sequence.Lib
 s/diskfont.libra
 ry.SYS:C/.SYS:S/
 .DF0:.DF1:.WIN.C
 OM.COMMAND.COM.P
 C Z£OM.%ld.AMIGA
  FOREVER !!!  in
 tel OUTSIDE !!!.


I don't know what author wanted to show with this virus, but he shown
that he is complete lamer. I will not bother to translate the texts
- should be enough if I say that 'ROTFL' is good to explain my mood
when I have read it for the first time...

--------------------- Acknowledgement ----------------------------------

Location............: Pawlowice, Poland
Classification by...: Zbigniew Trzcionkowski
Documentation by....: Zbigniew Trzcionkowski
Date................: December 2001
Information Source..: virus disassembly, SMEG1 source code
Copyright...........: This document is public domain.

===================== End of PENETRATOR Virus ==========================
