VirusX 3.1 (3.2 added by 17Bit, notes at end.) by Steve Tibbett Note: The version of VirusX on this disc is 3.2, unfortunatly we got hold of this without documentation so we had to 'edit' the 3.1 docs which I dnld'ed from Compunet. We didnt really want to do this but we still aint had a reply from Steve T and 3.2 is really much better! The Complete Virus Removal System VirusX - Fourth in a growing line of "X-Utilities". REMEMBER: STUFF NEW TO THE LATEST VERSION IS AT THE _END_ OF THIS FILE! Version Notes: -------------- Version Notes are now in the VirusX.C file, as is information on some of the viruses. Amiga Viruses have been following us around for some time now, and I think it's about time we got rid of it for good There are a number of CLI-based Virus Checkers out there, which do their job just fine, but if you're not into using CLI, what do you do? You use VirusX! Please, I encourage you to give this program to anybody who might have the virus. Including your local dealer - some of the dealers in this area have the virus all over their disks, which they allow customers to copy, and they don't do anything about it because they don't know how. VirusX makes it extremely simple. You can put VirusX in your Startup-Sequence.When run, it will open a small window so you know it's there (and it will display the occasional message in it).Whenever a disk is inserted into any of the 3.5" drives, that disk is automagically checked for the SCA virus, and also checked to see if it's boot sector is "Standard". If the disk has a nonstandard boot sector, it is either a new form of virus which I don't know about yet, or it is a commercial program which uses the boot block for something constructive (like bootingtheir game). If VirusX finds a boot block it is suspicious about, it will present the user with a requester either warning him that the disk has the SCA virus (or any other current virus), or telling him that the boot code is nonstandard. In either case he is given the option to either ignore it, or to Remove it. If the user selects Remove, after he says he's SURE he wants to rewrite the disk's boot sector (Remember: Never rewrite the boot sector of a commercial program unless you KNOW that program doesn't use it for something else. If the program gives you the AmigaDOS window before running, you know it is safe to repair that disk.). The boot code written back to the disk by VirusX is the same boot code that the AmigaDOS INSTALL command (and it's compatible counterpart on one of the fish disks) uses. If you click in the little "VirusX" window, and type a number from 0 to 3, (Corresponding to the drive # you would like to look at), VirusX will resize it's window to fit in the ASCII text of these two blocks, and allow you to view it. When you run across a "Nonstandard Boot Block", you can now check and see if the boot block is some sort of new Virus (Assuming that the author of the Virus left a string in it) as you will see something like "Revenge Virus 1.2G" or whatever string that identifies the virus. Note that not all viruses have text strings in them, so don't use this method alone to determine whether an unknown boot block is a virus or not. Also, you can check to see which strain of the SCA virus you have (VirusX will report "an SCA virus", but will not tell you if it is the "LSD" virus, or the "Zorro/Willow" virus or whatever new ones may appear). Generally, if boot code is capable of writing itself back to a different disk than the one it was loaded from, it is a virus. Keystrokes: 0, 1, 2, 3, will show you the boot block of whatever drive you select (0 would be DF0:, say), I will show you the Info window. C will cause VirusX to re-check all inserted disks. To use the keystrokes, click in the main VirusX window and type away. To move the initial position of the VirusX window, just put two numbers after the "VirusX" line in your command line. For instance, to put it at 50,30, just say VIRUSX 50 30. If you run across a strain of the virus, or any other virus that VirusX doesn't specifically warn of, PLEASE send me a copy of a disk with that virus on it! I want to keep VirusX current, and to do so, I need the viruses. I want feedback on this! Send me a letter! This program is Copyrighted, but is freely redistributable (It's NOT Shareware). Do what you want with it, but Please don't use it for evil purposes. That's what I'm trying to prevent. (If your conscience is compelling you to send me something, send me an original game you're bored with... It won't cost you anything, and it'll keep me busy for a few hours (or more...). My address: Steve Tibbett 2710 Saratoga Pl. #1108 Gloucester, Ontario K1T 1Z2 My BBS:  OMX BBS, 613-731-3419. I can be reached on BIX as "s.tibbett" and on People/Link as "SteveX". I'm also on Compuserve, but with their dumb numbering system, I can never remember who I am. --------------------------------------------------------- BYTE BANDIT VIRUS: What the Byte Bandit virus does is once it's in memory, it copies itself to just above the high memory pointer on the first hunk of RAM it can find (Which means it's not always in the same place), wedges itself into the Interrupt Server chain, into the Trackdisk.device's vectors,and creates itself a Resident structure so it can hang around after reboot. It watches EVERY disk inserted, and will write itself to ANY bootable disk that is inserted! This one can spread like wildfire - every disk you insert into your external drive during a session with this Virus loaded will result in all those disks being infected. Ouch. Also, if you Install a disk while this virus is going, it will just copy itself back to the disk - which is why it has to be wiped it from memory. When VirusX finds this virus on a disk, it will also display a "Copy Count" which is the number of disks that have been infected by that "Branch" on the "Tree" that the virus is on - If you infect a disk with your copy, and your copy is number 300, then that copy will be #301. If he infects somebody, that will be #302, but on YOUR copy, two infectations down the line, there will be another #302... Anyways, the copy count on MY Byte Bandit virus is #879... Note that VirusX will check RAM for this virus as well as the disk. This was necessary as you can tell from the description above. Special thanks must go here to Dave Hewett, who, 2 days after I gave him a copy of the virus, gave me a printed, commented disassembly of the virus with meaningful labels and everything I needed to stomp it - Thanks Dave! Thanks must also go to Bruce Dawson of CygnusSoft Software, who went to the trouble of being the First person to send me this Virus. (As of yet, he's also the ONLY person - Geez, folks, I need YOUR help to do this too, eh?) REVENGE VIRUS: What this virus does, is everything that the Byte Bandit virus does, PLUS, after infecting a disk, it will wait one minute after every reboot, and change your mouse pointer into an image of a certain part of the Male anatomy. 8-) I think the reason this virus is called the "Revenge" virus is because it looks specifically for the Byte Bandit and for the SCA Virus. If it finds either of these, it Rigs THAT virus so that it will CRASH the machine unless THIS virus is loaded first. Note that I might be wrong about this - that's the way it looks from the disassembly, but I don't have an SCA virus here to test it with. I tried it with the Byte Bandit and it didn't seem to do anything like this - but be warned, in case it pops up later or something. He stays in RAM via changing the CoolCapture vector to point to his own code. He then intercepts the DoIO() call and watches for any attempts to rewrite or to read the boot block and acts accordingly. He also has an interrupt around counting VBlanks until it's time to bring up his sicko pointer. To get this virus out of memory is Simple - Hold down the Joystick button (Plug a joystick into port 2, and hold down the button while you are rebooting), and the screen will briefly turn RED during the boot, and it's out of memory. (If you hold down Joystick button AND mouse button, it will half-remove himself from RAM and turn the screen Blue) VirusX will alert you if the virus is present in RAM and will render it helpless in RAM before telling you about it. It will also report it's presence on disk. I'd like to thank Lars Wilkund for being the first (And only so far) person to send me this virus on disk. Lasse is part of a Swedish users group with over 700 members! BYTE WARRIOR VIRUS: The Byte Warrior Virus is a lot like the Byte Bandit virus, except it is not designed to hurt anything - it will start an "Alarm" sound if it sees another virus (or at least I think it does - it hasn't for me), but other than that, it will write itself to any disk inserted. There is also a hidden message in it, asking us to spread it around and not to erase it. Ya, right. NORTH STAR VIRUS: It's a virus itself that alerts you to other ones - I think this sort of idea is stupid because it can do just as much damage as the rest of them. One new virus showed up for this version, the "Obelisk Softworks Crew" virus. It was sent to me by Jason Allen Smith. Thanks, Jason! Other changes this version - it's now a bunch smaller ( again!) thanks to a bit of a rewrite in assembler, and some reorganization. SCA Virus: This is the original. It just sits in RAM writing itself to any disk you boot off of. You can get it out of memory by either running VirusX, or holding down the left mouse button while you reboot the machine (The machine will flash the screen green once it's truly gone). 17BIT NOTES: (By the way I didnt like sabotaging Steves Docs but if people didnt distribute incomplete dnlds then it neednt happen and we HAD to include Version 3.2 rather than 3.1...) This version of VirusX checks for 16 (yes SIXTEEN) different types of virus! (No wonder we included it!) It works pretty much the same as VX3.1 but just has more virus's in its lists. Do yourself a favour and check all your discs straight away! Note: The virus counter doesnt seem to work, but I think this is just a small buggette in an early version, and the program still works fine - Ive been using it for ages now with no problems and to be honest don't like using my Amiga without it If you get a lot of 'HCS' virus then relax as it is the System Z bootblock - which is a virus killer, its better to kill it anyway as VirusX is much better. I'd like to thank Lasse Wilklund, Jason Allen Smith, Bruce Dawson,Robb Walton (sorry, Rob, I can't remember how your last name goes, I think that's it), Pete Foley, and all the others who have sent me disks whom I cannot remember. Sorry I don't answer mail as quickly or as often as I'd like, I have very little time these days. Mucho thanks also to Dan James, who's been helping me all along, and who did a lot of the finding out about the IRQ Virus. There are MORE viruses out there! Please, send them to me! ...Steve