³¼SAFE HEX, FOR YOUR COMPUTER'S SAKE!¼³ ¹ Many Amiga owners often have problems with various disk errors or faults and viruses. Faults like: Error validating disk, guru meditation xxxx, the disk has a read write error, please insert system Lazarus, and so on. Many of these failures are often due to viruses and therefore you have to move step by step when you want to rescue one of these disks. You should always on the lookout when you get new disks with any of the above faults. These days just the thought of a virus can get some computer owners quaking with fear. Nothing in the world is as frustrating as insecurity and defencelessness, but why on earth give up? FIRST CHECK WITH AN ORDINARY VIRUS KILLER Here are 3 basic types of check: BOOT CHECK The majority of viruses have a menu where you can select "Check Boot" and thereby check the disk's bootblock for virus. This is chosen and, in most cases, you are able to read the text on the bootblock. This text can, in certain cases, give an indication of how the bootblock is working, i.e. whether there is a virus on the disk or not. Normally one must make do with just the virus killer messages where all the well known viruses are named by the virus killer if it finds the virus on the bootblock. If a virus is found, you install the bootblock, which means that the bootblock is overwritten by a standard bootblock and then the virus is overwritten too and thus removed permanently. All bootblocks where you get the message: "Not a standard boot" ought to be, as a principle, installed. In other words, you should overwrite it (and only this block). Some beginners often confuse this operation with formatting a disk, and then all of the disk's contents is erased. There are so many useful bootblocks these days, so it's probably a question of whether you should maybe leave the bootblock alone. If you have used a new version of one of our virus killers, then you will know that they kill around 98% of all possible viruses, so do not use the install function when you get the message "not a standard boot".-I never do. The chance of it being a new, unknown virus which your virus killer does not know is practically non-existent. Remember too, that there might be a special bootloader which you MUST not delete, otherwise the disk will be ruined. If you are a relatively inexperienced Amiga user, then it is ALWAYS important to take a copy of the disk and work with the copy. That applies both when you are trying to erase a virus and when you are trying to repair a faulty disk. FILE CHECK There are today other areas than the disk's boot which can be infected with a virus. The first viruses of all we got on the Amiga were exclusive- ly boot viruses, but now there are an increasing number of what are known as file viruses which necessitate further checking. The object of this check is that all the disk's files are scanned through and checked for virus. If you are new to computers this might not mean anything to you, but you can liken it to a book, where the bootblock can be likened to the front page and the individual pages are the pages of the disk's file. More recent virus killers like Kill Da Virus 5 by Mike Hansell (purchase program), for example, and Virus Checker by John Veldthuis (freeware) are examples of program where both file and boot check are taken in one. If only all viruses could be changed to this method in future. It would save a lot of time. MEMCHECK There is a particular virus killer which has been specially made to test your Amiga's memory. There are unfortunately not many of these virus killers which use this method. In my opinion that is a great shame. Of these Ram checkers, like VMK made by Chris Hames (freeware) you can find version 1.10 on Fred Fish no 451 or use the totally new FindEmAll 5.1 made by Koen Peetermans (freeware) which is used only indirectly to check your disks. That is to say, that you put those disks you wish to check into the machine, and let the programme on the disk "run" all the way in, so that one is in on the disk's menu or at the start of the programme. You reset the machine by pressing (Control A + A) at the same time and then put the next disk int eh disk drive and then go on with the next disk. If it is a totally new game you have got, you can of course play for a bit if your fingers ar itching. During the test it is specially IMPORTANT that you take a suitable number of disks at a time dependent on how many viruses you think may be on the disks. The idea depends on finding those disks which are virus free by an easy and secure method. If you take, for example, too many disks at once ad find virus on a portion of them, you can easily check them again with the help of the boo and file check methods we just mentioned, but then some of the idea behind it has got lost by the wayside. Some of the RAM checkers provide the name of the virus they find, but often the user gets merely some system addresses which are tested for virus. If any irregularities are found here, then there are good grounds for being alert. In a number of cases it can be the fault of rather harm- less programmers, for example, a RAM disk. Several of the new virus killers, eg VT version 2.37 and BootX version 4.40 have a built in Ram checker, which makes the RAM check at the start- up before the main program itself starts up.....A simple but good method! SIMPLE CHECK Yes, this is an expression which probably not many are familiar with. But, as the name indicates, this check for virus actually is carried out total- ly without use of a virus killer. Take a copy of your original workbench disk, note down on the disk how many bytes are full on the disk or avail- able and try to make sure that there is a standard boot block on the disk. Check the suitable portions of the disk as described in the section Mem- Check. If the bootblock or a number of the bytes have changed, you can be sure that there is a dirty rotten virus at play on one or more of the disks which you have just tested. If you are confused after you have read all this, then don't worry. Reality is actually more simple than theory. Before you start checking your disks for viruses jus just have to try and guess if there is possibly a virus on the disks before you start investigating them. If you reckon that there is probably a virus on the disks, then use the first two methods to check for viruses. If, on the other hand, you reckon that your disks are free of virus, use one of the two latter methods which are much quicker to control than with an ordinary virus killer. 100% SECURITY IS AN ILLUSION Unfortunately you cannot test all your disks and your harddisk and achieve 100% security, even if you use all the 4 above methods together. If you want greater security it requires that if the disk is "crunched" that you have to "unpack" all the files involved eg in the Machine's RAM store and carry out the virus control here. Remember especially when you check your harddisk, I know that there are a lot of people who forget but you do it as a matter of course..don't you? Actually, you can never be 100% safe. This is due to, amongst other things, the fact that there are special viruses which are called bombers. These bombers cannot infect and cannot exist in the machine (i.e. they cannot survive a reset). They are thereforeparticularly difficult to find, especially if a new, unknown type is involved. The explanation for this is that most virus killers make a check to find something which is actually resident in your machine and, when it involves a bomber, nothing will be found here. Actually you can find these bombers by analysing all program codes, or by using a program like SnoopDos (version 1.2 is found on Fred Fish no 451). SnoopDos is actually a fantastic program which continually orientates the user about all the Amiga's calls and operations during the development of a program. MODEM AND HARDDISK Packer programs, such as LZ and other very popular programs, are particu- larly vulnerable to infection by the Link virus. If you have a modem, then be particularly careful when a totally unexpected version comes on BBS, do not upload it and do not put it onto your harddisk. Wait a week or so to find out if it is still on the BBS. If it's been removed, then you will know why! Experience shows unfortunately that things can go gruesomely wrong if you don't take care and use your head. Important data ought always have a back -up (copy). WRITE PROTECT IS IMPORTANT You have of course, always write protected all your disks (when the move- able piece of plastic in a position where you can see through a small square window). The wide spread of computer viruses today is due primarily to the fact that people forget to write protect their disks. Unfortunately things don't look as though they are changing. Estimates today are that over 100 million disks are infected with viruses. Nobody can get away from it. Often I am phoned up by people who have found 3©400 of their disks infec- ted with a virus. The record must go to Sweden, where one young man told me that he had found 5 different viruses on one of his disks. NEVER swap programmes with people like that! I myself seldom use a normal virus killer but instead I use a combination of the latter mentioned methods (MemCheck, Simple Check and un-packing). You should try it too. This method is particularly good, and quick too. I can especially recommend the method as a double control after one has used an ordinary virus killer, if one wants maximum security. REWARD I have had reports from nuclear plants, military installations and hospi- tals where viruses can cause irreparable damage and, at worst, cause a total catastrophe. The law has also been tightened up a bit in recent years. One can today risk up to 5 years in prison in certain countries for making a computer virus. Our organisation Safe Hex International has collected a reward of 3000 US dollars, so as to get hold of some of the people responsible for making these dreadful viruses. ABOUT DISK FAILURE AND VIRUS Failure at disk start-up. If you get a failure message in the form of guru or the like within the first 2-3 seconds after you have put in a disk, then don't worry. The Amiga has gradually altered its operative system several times (1.0, 1.1, 1.2, 1.3, and now 2.0). This has meant that today there are a lot of disks in circulation where there are home made boot blocks or viruses. These worked without doubt on the old system, but not on the new systems: Kickstart 1.3, 2.0 or whatever it is you have. Install the disk, if it doesn't have a standard bootblock, then it will probably work again. Fault on the disk besides. If you start checking for viruses and get a fault message "Error validat- ing disk", "the disk has a read write error" or the like, then don't immediately throw out the disk. Press cancel a couple of times until the fault message disappears and continue. Now you can check the disk for virus or repair it. Several of our best virus killers have a scanning function which is parti- cularly useful in controlling "read/write errors" in the files. The faulty files which you find can be repaired either by replacing them, if they are standard files such as those which are found on the original workbench disk (it is absolutely the quickest), or you can attempt to use a disk repair program. For myself, I prefer the program Disksalv version 1.42 made by Dave Haynie. The program can be found on disk no 251 in Fred Fish's wonderful Public Domain series which I can recommend to every new computer user. Other good repair programs can of course be found. I often use Quarterback Tools, which is a bought program, but Disksalv is probably the best program for new users because you have to start it up and the whole thing runs automa- tically. Does this sound attractive? We could do with a lot more user friendly programmes like this. Always remember to scan your disks for disk faults when you have carried out a repair. My experience is that only about 50% of faulty disks can be rescued, so it is important to double check the repair afterwards. NOT DIFFICULT TO DO, JUST START NOW When you read all this you can rather easily get the impression that it is difficult to carry out all these tests and so on. This mustn't put you off carrying out virus control of your disks. Follow these methods and always use the LATEST virus killers,then you will have all the security you need. The risk of virus on a disk is maybe 1:10,000 and I think you can live with that! It's easier than you think When you have got started on this, you will soon find out the easy ways and after 10 hours' practice I believe that you will be able to cope with most problems. Remember always to read the documentation before you start to use a program, it always saves a lot of time in the long run. You can probably save up to 98% of your disks. It will soon become a sport and it is, in fact, a really exciting area to work in. Just get your disk box out now and then and get on with it! Regards Erik Lovendahl Sorensen