Virus-Interceptor 1.14 ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ Copyright İ 1992,1993 Johan Eliasson Member of Safe Hex International All Rights Reserved Released the 30th of August 1993 FREEWARE Kickstart 2.0 or higher only.  Introduction   Disclaimer, Copyright, Distribution etc   About Safe Hex International   System requirements   Using Virus-Interceptor   CLI options   What if I find a virus?   Detection of unknown viruses   List of known crunchers   List of known viruses   History   Addresses etc   Thanks to...  ____ ______________ (__ | / _____________) | | / / _ ___ _ _ ___ | |/ / / )/ ) / )/ )/ __) | / / // '/ / (/ /(__ ) ______ |__/ (_/(_/_)(____/(____/ (__ __) / / __ _ ____ ___ ___ ___ ___ ___ ____ ___ ___ / / / | )(_ _)/ __) / ) / __) / __) / , )(_ _)/ )/ ) __/ (_ / | / / / / __) / '/ / (_ / __) / __/ / / / / // '/ (______)(_/|_/ (_/ (____)(_/_)(____)(____)(_/ (_/ (___/(_/_) _________________________________________________________________________ (#########################################################################) ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ Virus-Interceptor is an utility designed to protect you against file- viruses. The program is designed to be small, safe, and easy to use. When Virus-Interceptor is installed in memory, it will constantly check programs that are run for virus-infection. If a virus is detected in the code, the program will be aborted before it had a chance to start! Virus-Interceptor will also check the memory at regular intervals. If a virus is detected in memory it will be removed in a safe way. Virus-Interceptor has an unique feature: It will detect any new, previously unknown link-viruses in a program that was crunched with any of the known crunchers! Virus-Interceptor requires an absolute minimum of user-interaction. You just start it up, and then you can go on doing whatever it is you usually do with your computer. Virus-Interceptor will only disturb you if it finds a virus. Virus-Interceptor will communicate to you via DisplayAlert's, ie. those wellknown black screens with a yellow flashing border. Virus-Intercepor 1.13 knows 85 viruses, not counting clones. Virus-Interceptor is FreeWare. You may distribute Virus-Interceptor freely as long as you charge only a nominal fee (max $6) for copying and postage. The docs and the other files of the Virus-Interceptor package must always accompany the executable. You may not add, delete, crunch or modify the contents of the Virus- Interceptor directory in any way, archiving excluded. This software is provided "AS IS" without warranty of any kind, either expressed or implied. By using Virus-Interceptor, you agree to accept the entire risk as to the quality and performance of the program. Special permission is granted to Safe Hex International to modify the Virus-Interceptor package to suit their VirusKiller disk. If you know a virus programmer you can get a reward of $ 1000 for supplying his name and address. The fact is that the law punishes data crime very severely. (5 years in jail in most countries). We are an international group with more than 250 members who have started trying to stop the spread of virus. Let me give you some example: 1. Our motto is: "Safe Hex", who dares do anything else today?". 2. A virus bank containing all well known virus killer programmes. 3. We help people to get money back lost by virus infection. 4. We write articles about virus problems for 8 magazines. 5. We release the newest and the best virus killers around. 6. We have more than 20 "Virus Centers" worldwide where you can get free virus help by phoning our "Hotline", and the newest killers translated in your own language at very little cost.  List of Wanted Viruses  For more information contact: SAFE HEX INTERNATIONAL (Please send a "Coupon-Response Erik Loevendahl Soerensen International" and a self addres- Snaphanevej 10 sed envelope, if you want infor- DK-4720 Praestoe mation about SHI by letter). Denmark Phone: + 45 55 99 25 12 Fax : + 45 55 99 34 98 2.0 VIRUSES WANTED ------------------- IF you find new viruses , please send them TO DAY..........! I am currently searching for the following viruses : A.H.C.virus.BB Aibon (776) Infiltrate or damage BBS Aibon2 (784) Infiltrate or damage BBS Aibon-ACP.ctrl Amida.BB AmiPatch virus 1.0a (8288) Infiltrate or damage BBS Angel.BB Anti-Knacken.BB.(Sca clone) Antichrist.Link.(Jeff.clone) Australian.Paradise-BB BB-Prot.BB Beethoven.(2608) Bestial-Devastation Link (7876) BGS-9.III.(File.2608) Black.Knight.BB Blockchain.Virus Boot-Aids.BB Cascade.BB Charlie.Brown.(Hireling).BB Check.Filevirus.(18644)File Christmas.Violator.(1060).Link Clock.1.1.(setmap.&.S.Install) Clockvirus.(Back-running) Clockvirus.(Fast running) Commodore.BB CompuPhagozyte 7 File CopyLock-Virus.BB block 0-3 Cracker Exterminator.BB Creeping-EEL.BB Dailer.BBS.v2.8g.(33908) Infiltrate or damage BBS Detlef.BB Devil.11.B.Door.(3 files, 23452, 2342, 17884) Infiltrate or damage BBS Devil.V8.B.Door-Swiftware-(44224) Infiltrate or damage BBS Dialer.2.8g.(33908) Infiltrate or damage BBS Disgust.BB Disgust.BB Disk-killer.v1.0.(File1368) DiskRepair V.1.2 (49336) Infiltrate or damage BBS DiskRepair V.2.6 (37740) Disk.Speed.Check.1.01 (DSC101) Disktest virus (1368) Disktroyer v2 (812) DOpus.(6408).File Infiltrate or damage BBS DwEdit v1.6 (43700) Infiltrate or damage BBS Excrement-Installer Executors.BB Fuck.device.virus.BB Gandalf.BB GCA.BB.(Forpip.clone) Genetic.Protector.2.0 BB.(Dotty clone) Guardian.DMS Infiltrate or damage BBS Guardians Boot Aids.BB Hackers.Etic Happy.New.Year.BB Hardex.Saddam.Clone.(1848) Hill.BB HNA.Virus.BB Hunk-Lab.link Indiana.Jones.BB Infector.BB Influenza.BB Ingo's.Return.BB Jeff-Butonic.3.10(2916)File Jeff-Butonic.3.20.(2900)File Kefrens.I.BB Kefrens.II.BB Killed.virus.BB Kobold.II Lame.Saddam.Clone.(1848) Laurin.Saddam.Clone.(1848) Leviathan.BB Leviathan file (1056) Lupo (1484) MAD.IIa.BB MegaMon.PP-Bomb (26856) Infiltrate or damage BBS ModemCheck 1.1 Monkey-Killer.BB Mount.Virus.(1072) Mutilator.BB MVK.(1052)File Ninja.file.virus Noname.2.BB Nano2 Ohio.BB Overkill.BB.(block.1-3) P-Cracks.BB PayDay.BB Phatasmic.Force PowerTeam.BB PStats.(19784)File Infiltrate or damage BBS Rimednac.BB Saddam clone Lame (1848) Saddam clone Hard (1848) Saddam clone Laurin (1848) Saddam clone Animal (1848) Saddam clone Kick (1848) Saddam clone Nato (1848) Saddam clone Affe (1848) Saddam clone Iran (1848) Saddam clone Gral (1848) Saksen.no.2.BB Sao.Paulo.BB Satan.BB Schwartznegger SCSI-Virus (1560) file Sepultura. (1876) file Sentinel.BB Shit.Virus.(Nuked.007).BB SMBX-Mount.Installer.(64488) Suicide.BB Sysinfo 1.1 (5680) Infiltrate or damage BBS Sysinfo 2.2 (5656) Infiltrate or damage BBS Suntron.BB T.ET.E BB.Zombi.Clone T.ET.E-BB.Zombi.Clone Telecom.(756).File TimeDate TimeDate.Setmap Timer.virus.setmap(1712) Infiltrate or damage BBS Topdog.1.0 / TopUtil (2260) Infiltrate or damage BBS Tristar.Viruskiller-1.0.Virus.BB Trojan.Killer Infiltrate or damage BBS TTK.virus.BB UCA.BB UcAIDS.BB UInfo (13048) Infiltrate or damage BBS Umyj.Dupe.virus BB VirConSet virus 1 BB VirconSet virus 2 BB Virkill.2.BB Virus.II Virus Construktion Set File virus Virus.Terminator.6.0 (Trojan 1880) Virusmaker.1 Wahnfried.BB Warhawk 2 BB Witebox v 8.0 Trojan (34896) Infiltrate or damage BBS XaCa virus (1368) XLink.3.0 XprSpeed.3.2 (9556) Infiltrate or damage BBS X-Copy2.BB X-Ripper 1.1 (41360) Infiltrate or damage BBS Zenker.BB Zorro/Willow.BB ZSpeed (9556) Infiltrate or damage BBS Zviruskiller.1.5.BB And......infected disks with "French Kiss virus" and "ABC virus" containing the whole viruses (Block 0-3- or 4). I ONLY..have the first 1024 bytes!!!!! And of course any NEW.... virus you might find ! Please..mark the disk "Attention Virus"(please take care of my hard disk) Remember to state your address and phone number if you want a reply, but isn't necessary if you want to be anonymous, only the VIRUS counts. (I don't care, what "KIND" of disk you send me). After the disk is analyzed the disk is formatted and your name, will be 100 % arcivated in my trashcan. I.... ALWAYS keep my promise!!, (no more questions then!) A very EASY.......way is to send the viruses to your regional center, who will then send them along to me. THANK YOU VERY, VERY.. MUCH FOR YOUR HELP Virus-Interceptor will work on any Amiga with OS 2.0, OS 2.1 or OS 3.0. Virus-Interceptor has been successfully tested with 030 and 040 processors. There are a number of ways to start Virus-Interceptor. First of all you can click at the VI icon. It will use the program IconX to run Virus-Interceptor. IconX can be found in the c: drawer of your Workbench disk. The second way is to start up CLI, and then 'cd' to the directory where you keep Virus-Interceptor, and then type: 1> Virus-Interceptor Virus-Interceptor will then install itself, and that's it! It will auto-detach completely from the CLI, so you can close the CLI window. From now on Virus-Interceptor will communicate via alerts. The ideal thing is to put Virus-Interceptor in your startup- sequence, thus making it start up automatically every time you reboot. Load the file S:User-Startup into your favourite editor and insert "C:Virus-Interceptor >NIL:" at the beginning of the file, that is, if Virus-Interceptor is in the C: directory. >NIL: will get rid of the startup message. Virus-Interceptor patches the DOS-routines LoadSeg(), NewLoadSeg() and InternalLoadSeg(). The patching and the patch-removing is done as system-friendly as possible. You may wish to exit Virus-Interceptor, in out-of-memory situations for example. Just run Virus-Interceptor again, and it will exit in a second. VI will tell you it's leaving by flashing the screen and/or beeping (depending on your Sound preferences). You will also be told if a problem occurs, like if an other program is preventing VI from exiting.  CLI options  Go to CLI and type: 1> Virus-Interceptor ? You will be presented with a list of options, like this: P=PRIORITY/N,I=INTERVAL/N,S=STACK/N,M=NOMEMCHECK/S,L=NOLOADSEGCHECK/S: It isn't really necessary to use any of these options. If it seems complicated, just don't bother about them! PRIORITY sets the priority of the memory-checking routine. The default is 0. Higher priority means that the memory-checking will take precedence of other programs if the computer is busy. INTERVAL sets the interval in seconds for the memory-checking. The default is 5 seconds. STACK sets the stack memory. Default is 4096 bytes. Normally there's no reason to change that, but if you're short on memory you can try setting the stack to 2000 bytes. VI will probably manage. NOMEMCHECK will switch off the memory checking completely. NOLOADSEGCHECK will switch off the executable file checking completely. You can also use the redirection command > to redirect the output to NIL: Example 1> Virus-Interceptor PRIORITY 1 INTERVAL 10 Runs Virus-Interceptor at priority 1, and it will check the memory once every 10 seconds. Example 2> Virus-Interceptor NOMEMCHECK >NIL: Runs Virus-Interceptor without the memory checking. You won't be bothered with the startup message. If a virus is detected in an executable program or in the memory, you will be presented with an alert, telling you about it. It will look something like this: ********************************************************************** * * * Virus-Interceptor Alert: * * * * The file c:Strange is * * really the VeryBad file virus! * * * * Execution aborted. * * * ********************************************************************** Click a mouse-button and the flashing screen will be gone. The virus has been stopped in its tracks... But the virus will still be (in) that file c:Strange. Now you have to remove it from the disk. There are several excellent, intuitionized virus- killers that will do that for you. The most wellknown are BootX, VirusZ, and Virus_Checker. If you haven't got any of them, contact your regional SHI Centre and they will help you. If Virus-Interceptor said that the virus was 'unknown', there's one more thing you'll have to do: Send it to me! 8-) It might be a completely new virus, not yet recognized by any virus- killer. If you send the infected file to me on a disk, I will analyze it and include it in the next release of Virus-Interceptor! Thanks! Virus-Interceptor will detect unknown link-viruses if the infected file was previously crunched with any of the known crunchers. See list below. A link-virus works by attaching itself to a real program. Virus-Interceptor will then know that something's there, where nothing should be... Unknown file-viruses and trojan horses can not be detected... Yet... VI 1.08 uses a new technique for identifying crunched programs, and so the old list is now void. I have removed several crunchers, and I have yet to add some others, so this list will soon be extended. Imploder 1.0 - 3.1 Imploder 4.0 Imploder 4.0 Overlay PowerPacker 2.1/2.3 PowerPacker 3.0 PowerPacker 4.0 PowerPacker 4.0 password Name: Other names: Amiga Knights BBS-Link DiskRepair BGS-9 (and a bunch of clones, TTV1 inluding NoVi and NaSt) BGS-9 2 TTV1, Terrorists Bret Hawnes Butonic 1 HV 3.0, JEFF Butonic 2 HV 1.31, JEFF Byte Parasite (I,II,III) CCCP Centurions (I,II) Smily Cancer Challenger Chaos-Master 0.5 Commodore CompuPhagoZyte (1,2,3,3b,4,4a,IV) Crime Crime++ Crime'92 DAG Creator Darth Vader 1.1 Descriptor 3.0 Disaster-Master 2 Disk Speed Check Disktroyer 1.0 DM-Trash DStructure (I,II,III) EmWurm Excreminator 1.0 Freedom Golden Rider Gotcha Lamer Infiltrator Installer of 'Bluebox' Installer of 'Crime' Installer of 'D&A bootvirus' Installer of 'Gotcha Lamer' Installer of 'Lamer Exterminator' Installer of 'Little Sven' Chameleon Installer of 'Turk bootvirus' Installer of 'TFC Revenge bootvirus' IRQ-Team 41.0 Lamer Exterminator Lamer VirusX Liberator 1.21 Liberator 3.0 Liberator 5.01 LZ link Menem's Revenge Message ModemChecker FUCK ModemChecker LoadWB NANO PowerPacker trojan QRDL 1.1 Red October 1.7 Return of the Lamer! Disk-Validator virus Revenge of the Lamer (I,II) Saddam (and a bunch of clones) Disk-Validator virus Saron Message Show SysOp SnoopDos 1.6 TDB Message Trabbi Hochofen Travelling Jack (I,II,III,IV) TimeBomb 0.9 Timer virus Timer (setmap) Trojan 3.0 Virus Blaster 2.3 Virus Install 1.2 Virus Test 936 Xeno 1 XLink 3.0 FVDR 1.0 beta: A simple beta-release. Only a few has seen this one, which is just as well, it was very bug-ridden indeed. Version 1.0 : Public release! (21.10.92) Changed name from FVDR to Virus-Interceptor, which is a more accurate description of the program. Added Erik Loevendahl- Soerensen's collection of viruses. Thanks Erik! Changed the 'memorycheck after every program-start' to memorycheck once every second. And a hundred other changes that I have since long forgotten... The source-code is now 23 KB's big and consists of 1036 lines. Version 1.01 : Added the Saron link virus, (Thanks to Martin Lauridsen for (28.10.92) sending it to me!) The Saron virus is not a virus in the traditional sense, it's just a routine for showing some BBS greetings, but it works like a virus, and it can be just as menacing. You can't unpack the 'infected' file, and it can hide real viruses. So begone, ye! Show your credits in a textfile like everybody else! Version 1.02 : The Golden Rider and the Crime virus weren't recognized (08.11.92) correctly. Now they are. Also added loadseg-recognition for the Crime++ virus. Version 1.03 : Added some viruses: LZ link virus, Amiga Knights, (21.11.92) DStructure 1, 2 (and a clone: 3), Commodore filevirus, CompuPhagoZyte 3, 3b, 4, 4a, Liberator 3.0, Liberator 5.01, Timer virus, Trojan 3.0, Disk Speed Check file virus, SnoopDos 1.6 trojan, BGS-9 clones NoVi and NaSt. QRDL 1.1 linkvirus, Crime'92 linkvirus. Now you can use > to redirect the startup-text to NIL: if you wish. A side-effect is that Virus-Interceptor no longer is directly clickable from Workbench, but VI is better placed in the startup-sequence anyway! 8-) Version 1.04 : Added the CLI options PRIORITY, INTERVAL and STACK. (09.12.92) Requested by Magnus Holmgren and Tommy Hallgren! Bug fix: Occasionally the screen/mouse pointer would flicker, and a guru could pop up. Thanks to Tommy Hallgren and Jesper Ekhall for reporting, and especially to Tommy for helping me find the problem! Bug fix: If a virus was detected, the program that was run next could be accused of being infected as well! Bug fix: Virus-Interceptor thought that any PowerPacker 3.0 file was infected with the 'Crime' virus! Version 1.05 : Added the CLI switches NOMEMCHECK and NOLOADSEGCHECK. (10.12.92) Version 1.06 : Bug fix: The above mentioned flicker-bug wasn't removed (25.12.92) correctly. Bug fix: VI would guru if you had the Kickstart in RAM: Version 1.07 : Added a warning text that will appear if you try to run (08.01.93) VI on a computer with OS 1.3 or lower...just in case... Minimized the risk of false alarms about the Crime'92 virus. Added the Timer virus offspring: the fake setmap command. Version 1.08 : Changed the default stack to 4096 bytes. Vi will probably (23.02.93) survive with a stack of 2000 bytes, but no guarantees! Changed the default checking interval to 5 secs. 1 second was perhaps a bit unnecessary... I rewrote the documentation completely into the amigaguide format! (You should have noticed by now...) You should take the time to read it all thru again. It's not the same doc it was before. No more delays when quitting Virus-Interceptor. VI will now always exit in a second, unless some other task is keeping the processor busy! Thanks to Magnus Holmgren for letting me use his excellent timer-routines! When VI exits it will tell you about it with a screenflash and/or a beep, instead of with an alert as before. A DisplayBeep is nicer... I have optimized the memory-checking. It's now considerably faster, and kinder to the system. Virus-Interceptor will now only cause two Enforcer hits per memory-check. I was told that an earlier version caused 30-40 or so... 8-/ I'm afraid I can't do anything about these last two hits. It's the only way to detect some viruses! Virus-Interceptor performs a small security-check at startup. Nothing fancy, but it will keep most NewZappers away... I re-included the icon for you to click at... But you need the IconX program in the c: drawer for it to work. I greatly enhanced the 'unknown link virus' checking. VI will now also detect viruses using the End Of Hunk- infection method as well as the Infiltrator-method, which means that VI will now detect ANY unknown link-virus, if the infected file was previously crunched with any of the known crunchers (see above; updated list!) But of course: Viruses get 'better' all the time. Future viruses may use a method of infection that this version of VI does not recognize. A side effect from these new routines is that the risk of false 'unknown' alarms is almost non-existant. Version 1.09 : Bug fix: A generic printer driver was wrongly believed to be (15.03.93) the PowerPacker trojan horse. Thanks to Peter Binderup and Brian Hansen for sending the file to me! Also I improved my routines for future use. That's why the size of Virus-Interceptor has increased with 400 bytes... With these new routines I hope to be able to greatly reduce the risk of false file-virus alarms. We'll see... Version 1.10 : Bug fix: The programs Replex and HardTrack was mistaken for (23.03.93) the "Menem's Revenge" virus. Also Virus_Checker made the same mistake... And VirusZ 3.06 mistakes Menem's Revenge for Replex... 8-/ Thanks to Christian Carlsson for reporting and giving me the files! Version 1.11 : Sorry about the delay, but I've been very busy lately with my (12.05.93) studies etc... The PowerPacker-bug reared it's ugly head again. To my horror anaother innocent file was accused of being the PowerPacker trojan virus. Now the problem is definitely gone for good. VI is now 100% compatible with OS 3.0! Hooray! Thanks to beta-tester Jim Maciorowski! Version 1.12 : Added viruses : NANO, CompuPhagoZyte IV, Chaos-Master 0.5, (06.06.93) Travelling Jack 4, Show SysOp, DM-Trash, DAG-Creator. Also the TDB Message virus, thanks to Torben Danĝ for sending it to me! Virus-Interceptor no longer disables multi-tasking while checking certain things in memory, (it doesn't need to anymore). Also it's somewhat faster. Version 1.13 : Added viruses : ModemChecker file virus (also known as FUCK (06.08.93) virus), the LoadWB file virus that ModemChecker produces, and Descriptor 3.0 (same as 4.0). XLink 3.0 link virus, thanks to Martin Lauridsen for sending it to me! BBS-Link virus and another Message virus, thanks to Richard Hansen for sending them to me! I added a list of Wanted Viruses from SHI. Please read it! And if you have got any viruses that we don't, please send them to us!  List of Wanted Viruses  Version 1.14 : Bugfix in the recognition of the old EmWurm-virus. (30.08.93) A cracked and crunched version of PCTask was falsely identified as the EmWurm virus. The file seemed to be crunched with PowerPacker 3.0 yet my version of PowerPacker did not recognize it... Thanks to Jim Maciorowski for sending it to me! As AmigaGuide now is officially released I have dropped the ordinary Virus-Interceptor.doc, as it was a drag having to update both the doc and the guide for every new version. If you still don't have the AmigaGuide there are several utilities that removes the AmigaGuide codes from the guide and makes it readable as a docfile. My address: Johan Eliasson Phone: +46 11 169138 Bäckgatan 6 60358 Norrköping SWEDEN If you live in Sweden you can reach me at the following BBS:... GAZ BBS: 013-164345 Christian Carlsson at SHI Sweden for translating this doc into Swedish. Tomas Andersson, Magnus Holmgren, Tommy Hallgren, Mikael Nordell for helping me with my C problems. Tommy Hallgren and Jim Maciorowski for beta-testing. Erik Loevendahl Soerensen at SHI for support with viruses, info etc. Eddy Carroll for the SnoopDos-source. Koen Peetermans for his FindEmAllVectors-program. Peter Stuer for his utilities, especially the LVD program that inspired me in the first place! Jorrit Tyberghein for PowerVisor Brian Hansen, Jim Maciarowski and Richard Hansen for support My Amiga for having the best OS ever invented. My cat for keeping my monitor warm, or vice versa. Listed in no specific order. I have probably forgotten to include someone in the list. Sorry! END OF DOC.