---------------------------------------------------------------------------- Translated (as much as possible) from German to English by Marco 'Topic' van den Hout, June 22nd 1991 With thanks to ASM-One for its great replace option! Updated from German to English, August 5th 1991 by : Mikkel Bille Stegmann Rekkendevej 43 ALIAS : T H E C O C O U N 4720 Præstø ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Denmark +45 53 796164 ---------------------------------------------------------------------------- C H A N G E S S I N C E T H E L A S T V E R S I O N VIRUSES : KNOWN KILLERS: OTHER BOOTS: DAMAGE PRG : ============ ============== ============= ============ Amigaknights Monkey-Killer Bavarian ByteWarCreator ByteParasite Bootgen V3.4 Disk.Info Dosspeed Bootintro V1.2 LHWarp V1.40 Dotty UTILITIES : Bootleg V2.1 LZ2.0 Freedom ============== Copylock 91 Virusmaker Future Disaster Countach V1 X-Ripper V1.1 Gyros Cache-Disk Install 2 Hauke LVD Interferon Pro Haukeexterminator PatchLoaderSeq Magic BB CRUNCHERS : Jeff Butonic V3.10 PP-Patcher Meikel ============ No-Guru V2.0 Prokiller V1.03 Mosh-BB OP1 Tracksalve V1.3 Peter Stuer V5.0 Lightpack V1.5 Paramount Revenge of MAD LZHuf Sachsen 1. Starlight Max Packer V1.2 Sachsen 2. DISK CRUNCH : Stone Cracker Starlight 1. ============= Starlight 2. Travelling Jack 3. Disk Imploader Zombi 1. VT2.32 knows: ============== (or should know) Update: 03.08.91 - Please read VT.LiesMich (VT.ReadMe) first. Thanks! - PD Distributors should contact me first! Heiner Schneegold Am Steinert 8 8701 Eibelstadt Germany Tel. 09303/8369 not 100% certain found viruses: (I don't have, only 2 old viruses) - Requester contains for questionmarks up side-down - TestLongwords have been taken from other (PD) programs - Therefore only cold-reset or continue - known viruses (I have): ============================== (Known by the prg. and are being removed from memory without reset if recognized(execpt 3 virus-prg. see below...) Test for 3 longwords in memory!!! No Fastmem means, that the virus crashes when I try it with a FastMem expansion. Can possibly work with $C00000 or other FastMem expansions. - .info other name: TimeBomb V0.9 see down - 16 Bit Crew Cool, in Prg. also DoIo, FastMem works, in memory always at $7ec00 spreads: over BB in BB the uncoded text: The 16 Bit Crew 1988 - 2001 SCA-Clone, Cool always 7EC3E, only changed Text - Abraham see Claas Abraham - Aids Vkill-Clone see there Difference: 3 Bytes 1.Byte: in the checksum 2.Byte: generation counter 3.Byte: jump into encoded text (one Prg. jumps e.g. to $7ebc3, the 2nd to $7eba9) - AIDS-HIV SCA-Clone, Cool always 7EC3E, only changed text - AlienNewBeat Cold, Cool, DoIo, only KS1.2, Fastmem yes in memory always at $20000 spreads: over BB generation counter: $2037e Text in BB: e.g. THIS IS THE ALIEN NEW BEAT BOOT! - Amiga Freak Forpib-Clone see below only name in BB changed - AMIGAKNIGHTSVIRUS filevirus size: 6048 (unpacked) DoIo, KickTag, KickChecksum Writes in Root that the file init Cli and in startup-sequence no terribly damages BUT. After 5 reset's gets the screen black with pink text. And the following is displayed on the screen: In the Top: YEAH, THE INVASION HAS STARTED! YOUR TIME HAS RUN OUT, AND SOON WE WILL BE EVERYWHERE! In the middle: Vectordemo In the bottom: THIS IS GENERATION 0039 OF THE EVIL AMIGAKNIGHTSVIRUS GREETINGS TO DUFTY, DWARF, ACID CUCUMBER ASTERIX, ANDY, AND ALL AMIGIANS I KNOW Vectordemo: 3 texts with some kind of Zoomeffect a) Toco of b) THE c) AMIGAKNIGHTS - Art Byte Bandit other name: ByteBanditPlus see below - ASV-Virus always $7DC00, Cool, in Prg Forbid, clears KickTag etc. no copy routine damage: changes using setfunction Forbid to ChipAllocMem-Routine that is: at every Forbid-Call ChipMem gets lost. - Australian Parasite Fastmem yes, Cool, DoIo, in Prg. BeginIo spreads: over BB text display is being flipped over graphic routine in BB: The Australien Parasite! By Gremlin 18/5/88! Will NOT destroy game bootsectors or corrupt disks, and kill other viruses! - BAHAN other name BUTONIC_1.1 see there - BGS9 I (copies original prg. to devs directory) Bytes 2608 Call 12.05.91: On an A500 without harddisk BGS9 I copies the OrigPrg. invisible to root dir when devs directory isn't on disk. KickMem, KickTag, KickCheckSum, OpenWindow PrgParts coded using eori.l #$1AF45869,(a0)+ invisible File in devs: A0A0A0202020A0202020A0 at end of prg.file visible using a monitor: TTV1 at 4th reset text display over graphic routine: black background, white characters: A COMPUTER VIRUS IS A DISEASE TERRORISM IS A TRANSGRESSION SOFTWARE PIRACY IS A CRIME THIS IS THE CURE BGS9 BUNDESGRENZSCHUTZ SEKTION 9 SONDERKOMMANDO "EDV" Remove: rename file in devs to original name delete BGSVirusFile copy OrgPrg to old directory - BGS9 II like BGS9 I only: File in devs is now called: A0E0A0202020A0202020A0 Tip: $E0 ist an accented 'a' (e.g. å) Call 12.05.91: On an A500 without harddisk BGS9 I copies the OrigPrg. invisible to root dir when devs directory isn't on disk. change in Text: :SOFTWARE' The changes in the text lie within coded part of program. in PrgFile TTV1 visible - BLACKFLASH V2.0 Cool, DoIo, FastMem yes in memory always at $7F000 Counter = $13 text display using graphic routine (see below) chars red, background black spreads: over BB uncoded text in BB: HELLO, I AM AMIGA ! PLEASE HELP ME ! I FEEL STICK ! I HAVE A VIRUS ! ! BY BLACKFLASH ! - BlackStar other name: Starfire1/NorthStar1 see over there - Blade Runners SCA-Clone, always at 7EC00, Cool, in Prg. DoIo Text: Hello! We are the Blade Runners! etc. - BLF-Virus always at $7F000, Cool, DoIo, BeginIo clears KickTag etc. Virusprogram doesn't show itself (no requester, graphics, colour) program part decoded using eori.b #$28,(a1)+ visible : This is the new virus by BLF (and more) damage and spreading: BB - BlowJob KickTag, KickCheckSum, in Prg. DoIo and $6c, always $7f000 Pretends to be Memory Allocator 3.01 (by text) spreading und damage: Bootblock as soon as counter has reached $7530 , a program part is decoded using subi.b #$71,D0 and using Display Alert the text is displayed: ONCE AGAIN SOMETHING WONDERFULL HAPPENED (HE HE HE) PLEASE POWER OFF - PLEASE POWER OFF - PLEASE POWER OFF - BlueBox Filevirus, no known vectors changed length (crunched) 5608, only Cold reset (I'm sorry!) is said to be spread among modem users and mailbox operators, but there are no special conditions for spreading (includes Source for serial port $DFF030, $DFF018 ???!!!??? Disables connection?!?!) Crunched Prg. (Bluebox) consists of 3 parts: - a selector: enables >Tonfolge mit Zehnertastatur< (Pardon me? enables beep pattern using 10-key keyboard?!!!) - a complete icon.library - length:6680 - Additional text: input.device , RAM: - different year - a copy-part for bad(virus!) icon.library - tests whether icon.library exists, if not, no change - tests whether disk is validated - sets back Protection-Bits - copies bad(virus!) icon.library - also works with HD !!!!!! After reset starts a process 'input.device' (with empty chars) using icon.library. VT finds this process, but can't remove it (cold reset) makes in RAM: an invisible ($A0) File (not always). Further tips: VT recognizes the virus carrier Bluebox only when crunched !! Ignore the cold reset requester and first delete the bad icon.library. The copy an original icon.library to the Disk or HD (otherwise no WorkBench!) At the end please start the cold reset-Prg. My machine reacted normal again after that. This could be different with modem / mailbox programs??? Please tell me about problems. thanks Source: Bluebox.lzh 23033 Bytes -Bluebox 5608 (crunched once again) -Bluebox.info 325 -Bluebox.DOC 37271 -Bluebox.DOC.info 354 - BRET HAWNES Filevirus length: 2608 , always at $7F000 Kicktag, SumKickData, KickCheckSum, OpenNewLib, $6c spreading and damage: writes in root and in 1st line of Startup-Sequence: C0A0E0A0C0 after 20 mins. blue graphic screen and white chars: GUESS WHO`S BACK ??? VEP. BRET HAWNES BLOPS YOUR SCREEN I`VE TAKEN THE CONTROLL OVER YOUR AMIGA!!! THERE`S ONLY ONE CURE: POWER OFF AND REBOOT ! ! ! ! ! In stead of the 10th copy tracks are damaged! - BS1! (SCA clone again) - BUTONIC 1.1 other name BAHAN (in BB always readable) Cool, in Prg. DoIo, always at $7ec00, FastMem yes spreads: over BB when DOS0 found text display using PrintIText (decoded with eori.b #-1,d1 nach $7eb0c) after decoding in memory: BUTONIC'S VIRUS 1.1 GREETINGS TO HACKMACK ... - Byte Bandit without FastMem Begin, KickTag, KickCheckSum, Vec5 - Byte Bandit 2 other name: No name 1 see below - Byte Bandit Clone without Fastmem Difference with OrgByteBandit: 180 Bytes ( Byte B.. Text has been removed from BB!!) - ByteBanditError The OrginalByteBanditVirusPrg. starts in BB at $0C, here at $32. Because the old BB-Copy Routine is used, the 1st LW in the new Copy-BB NOT DOS0, that is: The now infected disk is "Not a DOS-Disk" That means that it is neither spreading nor bootable. - ByteBanditPlus Kick1.2 without FastMem Begin, KickTag, KickCheckSum, Vec5 difference to OBB: 92 Bytes (trackdisk.... removed) - ByteParasite size: 2108 should be on S6c, but before then GURU Damage: should be between cd, dir and startup-sequence with 1 Byte between but it is very very BAD coded (The author plays better with a Joystick). Therfore: many GURU's. No text displayed. - BYTE VOYAGER I Kicktag, KickCheckSum, in Prg. DoIo and $6c always at $7F000, coded with $DFF006 spreading and damage (HD too!!): Bootblock and writes in Block 880 "Infected by BYTE VOYAGER !!!!!" Text is on disks the new diskname. - Byte Voyager II Kicktag, KickCheckSum, in Prg. DoIo and $6c always at $7F000, coded with $DFF006 spreading and damage (HD too!!): Bootblock and writes in Block 880 "Another Virus by Byte Voyager" Text is on disks the new diskname. - Byte Warrior (DASA) (KickV1.2) DoIo, KickTag, KickCheckSum First encrypted BB-Virus - CCCP-Virus Cool, in Prg. Vec3, DoIo, Openwindow, NewOpenLib !!!! first VirusPrg. spreadable as BB and as Link!! in BB visible: CCCP VIRUS Link: filesize is increased by approx. 1044 Bytes infects no Prg. in l* (e.g.libs), d* (e.g.devs), f* (e.g.fonts) - CENTURIONS other name: THE SMILY CANCER see over there - Chaos Cool, DoIo BB coded with value from $DFF006 damage: spreads: over BB as soon as the counter has reached 8 all blocks on the disk are being filled with random values (or in other terms : it writes garbage on all blocks), DisplayAlert: Chaos! by Tai-Pan ect. and then reset Source : Virusinstall V2.0 - Charlie Brown other name : Hireling Protector V1.0 Forpibclone see below only text changed - Check Filevirus PP-Crunched Lenght : 18644 Process: Harddisk.device in C-Aztek damage: All 5 min. (delay $3A98) pictures (Totenkopf) and sound for a short while. N O spreading routines found. - Claas Abraham other names: Abraham, MCA Cold, Cool, KickTag, KickCheckSum, $68 needs FastRam !!!!! requested using move.l #$4,d1 and AllocMem (programmer mistake????) While prg. running first BeginIo spreads: over BB damage: after $F (#15) resets formats disk. Eor-Byte for new BB is chosen using $DFF006 decoded in memory: >>> Claas Abraham Virus !!! <<< - Clist-Virus other name: U.K.LamerStyle Begin, Kicktag, KickCheckSum decoded in memory: expansion ram.trackdisk.device..clist.library.clist 33.80 (8 Oct 1986). spreads: over BB New BB is again coded with eori.b. The encryption byte is chosen using $DFF006. memory for VirusMainPrg is allocated using StructMemList and! allocabs. - CODER other name: Coders Nightmare always $7f600, DoIo, KickTag, KickCheckSum, $68 in BB uncoded: Bootblock installed with 'CODER' - The Ultimate Viruskiller!! spreads: over BB in memory (decoded with ror.b #2,d1): Something WONDERFUL has happened!! Your Amiga is alive, and it is infected with the 'Coders Nightmare Virus'. - The ultimate key-killer, masterminded by the megamighty Mr. N of The Power Bomb Systems!! - Coders Nightmare other name: CODER see there - Color Filevirus length: 2196Bytes DoIo always $70000, Cool Allocates 102400 Bytes ChipMem (not used by program), Changes between graphic demo, black backgroand and 3 bars (red, green, blue) and installs at the same time from $70000 the Virusprogram and at 7F000 the Virus-BB (TURK). DOES NOT change Startup-Sequence. damage: Bei DoIo-jump Virus-BB is written. Bei Cool-jump $5000 x TURK is written in memory. - Crackright other name: Diskdoctors see below - DAG Cool, in Prg DoIo, Fastmem yes, always at $7ec00 Cool piece of coding: in the original SCA-Text is inserted: Try ANTIVIRUS from DAG - DASA other name: ByteWarrior see there - DAT '89 only KS1.2 because of DoIo-ROM-jump, KickTag, KickCheckSum always 7F800, tries to swap text in BB THIS BOOT RESETS ALL VECTORS etc. as soon as counter reaches $F, DisplayAlert: DAT '89!!! DOESN'T use trackdisk.device !!!! damage: writes BB damages Block 880 and 881 (Disk Root) - Destructor Cold in BB visible: Destructor_Virus v1.2 Written by Aldo Reset. (c) M.C.T. Ltd 1990- Everything is ander control ! (eh!eh!) no copy routine found damages at next reset over Cold a write enabled disk by overwriting every fourth track. - DIGITAL EMOTIONS Cool, in Prg. DoIo, always $7ec00 in BB always visible: *** DIGITAL EMOTIONS *** Using counter chosen between: - copy BB - 'VIRUS ' written on track 0 :No Dos-Disk text display (decoded with -1) over DisplayAlert: KickStart ROM Corrupted at $c00276 - DISASTER MASTER V2 ( cls * ) 1740 Bytes seperately working Prg. for startup-sequence kicktag, kickcheck in Prg. DoIo cool and cold are cleared Remove: delete first line in Startup-Sequence delete file 'CLS' in C: dir. Written to disk by: Intro-Maker by T.C.R. - DiskDoctors (KickV1.2) Mutants can be distinguished by looking at $4 (Checksum) and from $390-$3A8 (Variables)=different every reset - Disk-Herpes Cool, in Prg. DoIo, in memory always at $7ec00 Often wrongly seen as Phantasmumble, Fastmem yes spreads: over BB damage: dumps memory from $60000 to Track 80 (Root): Disk BAD graphic routine: German flag + Text (in BB visible) --- Hello Computerfreak --- You've got now your first VIRUS ** D i s k - H e r p e s ** Many Disks are infected !! Written by >tshteopghraanptha< c 27.07.1987 in Berlin - DIVINA EXTERMINATOR I Cool, DoIo, Inter.5 and $64. in Prg also $68 and $6c. overwrites SetPatchList at $C0. Codes BB again with value taken from $DFF006 (value saved in BB at $3F6) after eor.w d0,d1 in memory: VIRGO PRESENTS DIVINA EXTERMINATOR I Pretends to be a normal installed BB. damage and spreading: BB after 3 copies: starts reading the K-key and after ten times ExecBase is set to zero => system crash Source: -p-turbo.dms - DOSSPEED (NewZealand) real name: Revenge of the Lamer - Dotty-Virus always S7f000 Kicktag, KickChecksum in program: DoIo, Vec5 No Trackdisk.device Spreads by: BB Damage: Change PRIVAT-Intuition-structur - EM-Wurm (deliberately against EUROMAIL) doesn't survive reset always: writes in startup-sequence $A0,$0A (1st line) own Process: clipboard.device writes in c: $A0, length: 3888 Bytes (ASCII-Text available) writes in 5th Byte of c:protect (when available) $01 Result: protect useless Damage routine: Works only when devices EM, EUROMAIL or EUROSYS are available. overwrites all Files in these directories with memory from MsgPort. In damaged files: from $BC text 'clipboard.device'. After that a pause of 3mins using dosdelay $259A After pause damage routine is called again. Source: QuickInt PP-crunched length: 3196 Bytes VT does NOT clear the process, but fills it with NOPs Some parts, e.g. Autorequester, con etc. couldn't be tested, because I don't have EUROMAIL. These parts are also filled with NOPs. If you have problems with this virus because of these NOPs, please help me. - EXTREME DoIo, KickTag, KickCheckSum, RasterBeam either 7f800 or ff800 => uses SysStkLower+ $1000 readable text in BB : THE EXTREME ANTIVIRUS ect. as soon as the counter reach zero : Alert and damages (Disk BAD) all write enabled disks in all drives. spreads: over BB - F.A.S.T. Cool, DoIo , FreeMem, always at $7F000 Alert (coded with eori-Byte taken from $DFF006) and deletes also changes $C0-$E0 (SetPatchList!) spreads: BB - F.A.S.T. 1 FAST-Clone To insert Dos.Library in top of program, coded part is moved down a little. Memory usage is the same. - F.I.C.A BeginIO, KickTag, KickCheckSum, SumKickData spreads: BB Special: pretends to be clean BB. visible Text in BB at $288 e.g. F.I.C.A RULES! - FORPIB no FastMem, BeginIo, KickTag, KickCheckSum, Vec5 spreads: over BB gets memory using MemList, memory for new BB using AllocMem in BB: - FORPIB - 09.88 - N° 197102 - etc. - Freedom size: 10876 Bytes Source: Freedom!.LZH 8153 Bytes No secret Vectors Tryes to give a good impression by writing: Freedom! by Steve Tibbett Checking Df0: for 126 viruses After a while you will get a message ex: SADDAM-Virus removed ! or SMILY CANCER-VIRUS removed ! Damage: Writes in every 5th Block (Also in Root=880) Computertrash, change maybe contents of a track! (Problaly should this prevent knowing the virus by blocks) Between the destroyed blocks is a reestablishment hopeless. rewrite the data and format the disk. With luck knows VT by BitMapTest a Freedom-Disk. By BlockITest shows it not VT, that the datatrash from disk to disk, and the tracks changes. - FrenchKiss uses Block 0-5 in track 0 I only have Block 0 and 1. A real virus !!! Cool, DoIo, $6c, Vec5, always at $7f0d0 spreading: Block 0 to 5 , Track 0 damage: Counter: Track 0 overwritten or Track 80 damaged. I can't tell you more, because I only have block 0 and 1. send me an infected disk!! - Frity Forpib-Clone see there - Future Disaster only K1.2, Cool, DoIo, BeginIo, Always at S7FB00 Uses trackdisk.device Speading: By BB Damage: Wenn the counter reaches 7: - Writes Memorycontents at S10000 to block 0 u 1 - Writes Memorycontents at S7Fb00 to Block 880 and further Following: You can't use the disk anymore. - Gadaffi (KickRomV1.2 Floppymusic) Cool, DoIo, KickTag, KickCheckSum - Glasnost Block 0 to 3, Lenght also 2048, KickTag, KickChechsum in prg also DoIo, $6C, in memory always at $7F000 Does NOT need a trackdisk.device. Is active when Block 880 is being read. damage: Blocks up the computer after 15-20 min. of calculations Writes it owns BB and destroys also files in block 2 & 3 choose a block over $DFF006 through muly #6,d7 and writes in this block from $100 four longwords ($11111111, $22222222, $4444444, $8888888). This block can N O T repaired! Text in block 3: Glasnost VIRUS by Gorba!! First release - Gotcha Lamer Linkvirus also called "Lamer Bomb" Prgsize increased by 372, bytes DoIo, only infects the C/commands Dir, Run, Cd, Execute. Damage: KEINE infection in other files than the above named files. Diskdrive Heads start to step. DisplayAlert and reset " HAHAHA....Gotcha LAMER!!!" Look to link C/Dir, DH0:c/run, DH0:C/cd, DH0:c/execute. Source Program Minidemo.Exe. 773 bytes - Graffiti resembles 16Bit Crew + 3D-Graphics FastMem yes, Cool, in Prg DoIo, in memory always $7ec00 spreads: over BB graphic routine with 3D uncoded in BB: VIRUS! written by Graffiti - GREMLIN Cool, KickSumData, in Prg. DoIo, in memory always $7f400 spreads: over BB text display with graphic routine: red backgroand, white chars GREMLIN - GX.TEAM Fastmem yes, only KS1.2 because of absolute DoIo-jump Cool, DoIo, KickTag, KickCheckSum, in memory always at $7f4d0 spreads: over BB Text display with displayAlert (decoded with sub.b #$41,d0 after $7f300): Mais qui voila ???C'est le nouveau VIRUS de GX.TEAM !! AAAHH! Les salauds! Les ...(Insultes diverses) He!He! SILENCE : GX.TEAM entre enfin dans la legende ... BYE!!! - Gyros Cool, DoIo, always at S7EC00 Uses NOT trackdisk.device Spreads by: BB Damage: Wenn the counter reaches 10 happens this: - Stop the Computer in BB: Your Amiga is fucked from a nice GYROS. - Hauke Byte-BanditClone text changed: Hauke Jean Marc - Haukeexterminator I Disk-DoctorsKlone text changed: Haukeexterminator I. - Hilly KickTag, KickCheckSum, Kick1.2 DoIo in Prg with absolute ROM jump Test for special Kickstartversion (patched at $FC0090) If available no virusinfection. Doesn't affect trackdisk.device, so writing to harddisk is possible In memory: always at $7f300 (ResStruc.) spreads: over BB No further routine found (No graghic ect.) - Hireling Protector V1.0 other name : Charlie Braun Forpib clone see above only text changed. - HODEN V33.17 only KS1.2, because of absolute DoIO jump DoIo, KickTag, KickCheckSum, in memory always $7f000 spreads: over BB Features: after 5 copies a yellow head moves from left to right on screen. uncoded in BB: HODEN V33.17 - ICE SCAClone, Cool, in Prg. DoIo, in memory always at $7ec00 spreads: over BB text display by graphic routine uncoded in BB: Greets from The Iceman & The IRQ etc. - Incognito other name Trojan DoIo, KickMem, KickTag, KickCheckSum, FastMem yes only KS1.2, because of absolute DoIO jump in ROM spreads: over BB No further damage and no Text in BB: no text, trackdisk.device coded. - Inger IQ ByteBandit/Forpib-Clone see there Text: "Inger IQ Virus - Ersmark 1953" - IRQ-TeamV41.0 Link-Virus, increases prg. size with 1096 Bytes Jump after reset: KickTag Jump when active: OldOpenLib Text in CliTitle: (decoded with eor.l d0,(a0)+ addq.l #3,d0 ; for a new virus the contents of D0 is changed by move.l OldValue,d0 and add.l $dff004,d0) AmigaDOS presents:a new virus by the IRQ-TeamV41.0 Either c/dir or the first file in startup-sequence gets infected. N O File gets infected twice. The file may not be longer than 100000 bytes. Remove: delete first line in Startup-Sequence copy original file back. - IRQ II like IRQ I, but the test routine to see if a file is already infected (cmpi. #$fffe6100,30(a4,d6.l) is changed. The first file in startup-sequence is infected untill disk is full. IRQI+II: With my FastmemCard no spreading possible after reset ???? Remark: I have an IRQ2-File with six links - JEFF-BUTONIC V1.31/05.11.88 PrgFileVirus 3408 Bytes DoIo, KickTag, KickCheckSum, $68 writes itself in the 1st line of the Startup-Sequence on a write enabled disk. Tarnnames: see below Texte coded with: eori.l #$AAAAAAAA,(a0)+ Text for DisplayAlert: "Einen ganz wanderschönen guten Tag!" "* I am JEFF - the new Virus generation on Amiga *" "(w) by the genious BUTONIC." "V 1.31/05.11.88 - Generation Nr.00037" "Greetings to * Hackmack *,* Atlantic *, Wolfram, Frank," "Miguel, Alex, Gerlach, and to the whole Physik-LK from MPG !!" Texte fuer die Fensterleiste: "Ich brauch jetzt'n Bier!" "Stau auf Datenbus bei Speicherkilometer 128!" "Mehr Buszyklen für den Prozessor!" "Ein dreifach MITLEID für Atarist!" "BUTONIC!" "Schon die Steinzeitmenschen benutzten MS-DOS...einige sogar heut noch!" "Schon mal den Sound vom PS/2 gehört???" "PC/XT-AT: Spendenkonto 004..." "Unabhängigkeit & Selbstbestimmung für den Tastaturprozessor!" "Paula meint, Agnus sei zu dick." "IBM PC/XT: Ein Fall für den Antiquitätenhändler..." "Sag mir, ob du Assembler kannst, und ich sage dir, wer du bist." Tarnnames: for RootDir: in Startup-Sequence: AddBuffers "AddBuffers 20" Add21K "Add21K " Fault "Fault 206" break "break 1 D" changetaskpri "changetaskpri 5" wait "wait " $A0 $A020 $A0A0A0 $A0A0A020 Arthus "Arthus " Helmar "Helmar " Aloisius "Aloisius " ?? $20 $2020 ?? The making of the $20-Tarnname has failed, but is included in the program. - JEFF-BUTONIC V3.00/9.2.89 PrgFileVirus 2916Bytes name in root dir: A0A0A0 1st line in startup. A0A0A0209B41 DoIo, KickTag, KickCheckSum spreads: every write enabled DOS-Disk with startup Remove: delete 1st line in startup Delete file in DfX: Decode routine: decoded Text: move.w #$013a,D0 Hi. loop: JEFF`s speaking here... move.w (A0)+,(a1) (w) by the genious BUTONIC. eori.w #$b4ed,(A1)+ etc. in total over $270 Bytes Text dbf D0, loop - JEFF-BUTONIC V3.10 Filevirus size: 2916 Read the text about Jeff 3.00 Programcode is changed (Now anti-Virus-Program ??) + coded text changed: ex. Sauf blos keinen Wodka!. Further: eori.w #Sb4ed,(a1)+ Sourceprogram: *JEFF* VIRUSKILLER Mastercruncher: 7368 unpacked: 9064 also: Jeff-Maker, Jeff-Remover Writes really JEFF 3.10 on the disk instead of 3.00: Virus Gefunden - bitte warten Startup-Sequence desinfiziert und Virus beseitigt! In this program is JEFF V3.10 coded [ eori.b SFF,(a0)+ ]. - JITR Cool, DoIo, FastMem yes, in memory always at $7ec10 spreads: over BB No further routine !!!! VirusPrg. only $200 Bytes long. in BB readable: I'm a safe virus! Don't kill me! I want to travel! And now a joke : ATARI ST This virus is a product of JITR - Joshua Text 'Joshua' from top to bottom (vertical) over graphic routine Begin, Kickmem, KickTag, KickCheck, Vec5 - Joshua 2 other name: Joshua3 or Switch-Off Cold, Begin, Vec5 Has a problem with C-SubD. on WB1.3 Bootblock now coded: loop: move.b (A0),D0 eori.b #$18,D0 The eor-Byte changes and is also at move.b D0,(A0)+ $3ff in the BB. Joshua 2 is to be cmpa.l A1,A0 recognized by the series of bytes at bne loop the end of BB, where X changes rts EOR-byte dependent: .XX...XXX........XX.XX.XXXX...X.XX. The points (periods) can also be other chars. - Joshua 3 other name and real one: Joshua 2 There is a virus librrary that calls a real ByteBandit Joshua 1. because of that Joshua 2 is called Joshua 3. At this moment it's corrected allready. (April 15th 1991) - Julie other name Tick always $7f800, cool, DoIo, BeginIo and $20 Doesn't work correctly with 1MB Chip tests a few pointers and 3 values (e.g. at $7ec00) spreads: without warning over (only bootable) BB's - Kauki always $7ec00, Cool, in Prg. $80, $84, $88 in Prg. DoIo, writes back DoIo of KS1.2 later on in Prg (after spreading) Most bytes are used by the Copperlists. The CopperIntro works on KS1.3 too. Kauki in BB invisible. - Kefrens SCA-Clone Text in BB: Ohh noo!!!! I think something is wrong! and even better... Some of your disks are sick Watch out! By Kefrens offcourse!!! - L.A.D.S DoIo, KickTag, KickCheckSum, always $7F400 Attempts to 'hide' itself using DisplayAlert at bootup: (Text also readable in BB) L.A.D.S Virus Hunter No virus in memory Press any mouse button NO viruscheck is done, but the own program is installed (survives reset) spreads: every BB of a disk without asking as soon as counter reaches 8: A part of the virusprogram is decoded with eori.b #$41,(a0)+ and with DisplayAlert the text is displayed: AMIGA COMPUTING Presents: The GREMLIN Virus All Code (c) 1989 By Simon Rockman - LamerBlame! Cool, DoIo BB coded with value from $DFF006 damage: spreads over BB As soon as counter reach 8 : DisplayAlert: LameBlame! by Tai-Pan usw. else nothing happends Source : Virusinstall V2.0 - Lameralt (old Lamer Exterminator) abcd at $3a6 writes Lamer in randomly chosen Block FastMem yes, Begin, KickTag, KickCheckSum, SumKickData - Lamerneu (new Lamer Exterminator) abcd at $396 writes LAMER in randomly chosen Block FastMem yes, Begin, KickTag, KickCheckSum, SumKickData - Lamer1 fedc at $342 writes LAMER Begin, KickTag, KickCheckSum - Lamer2 abcd at $392 writes LAMER FastMem yes, Begin, KickTag, KickCheckSum, SumKickData - Lamer3 abcd at $3f4 (origBB in 2 and 3) Fastmem yes, Begin, KickTag, KickCheckSum, SumKickData - Lamer4 abcd at $3ae BeginIo, KickTag, KickCheckSum and SumKickData spreads: over BB Damage: overwrites a Block with 85 x LAMER! and because two bytes are left, '!!'. Blocknummer is chosen using $DFF006 A new BB is recoded with eori.b. The coding byte is chosen using $DFF007. Memory for VirusMainPrg is allocated using StructMemList. - Lamer5 abcd at $3aa FastMem yes BeginIo, KickTag, KickCheckSum and SumKickData spreads: over BB Damage: overwrites a Block with 85 x LAMER! and because two bytes are left, '!!'. Blocknummer is chosen using $DFF006 A new BB is recoded with eori.b. The coding byte is chosen using $DFF007. Memory for VirusMainPrg is allocated using SysStkLower. - Lamer6 abcd at $396 FastMem yes Like LamerNeu difference 48 Bytes BeginIo, KickTag, KickCheckSum and SumKickData spreads: over BB Damage: overwrites a Block with 85 x LAMER! and because two bytes are left, '!!'. Blocknummer is chosen using $DFF006 A new BB is recoded with eori.b. The coding byte is chosen using $DFF007. Memory for VirusMainPrg is allocated using SysStkLower. In Prg. also Remove Node, Test for Cool and Cold. - Lamer7 other names: Selfwriter, Pseudoselfwriter no significant end, length BB $3BD, BeginIo, KickTag, KickCheckSum spreads: over BB Damage: overwrites a Block with 85 x LAMER! and because two bytes are left, '!!'. Blocknummer is chosen using $DFF006 A new BB is recoded with eori.b. The coding byte is chosen using $DFF007. Memory for VirusMainPrg is allocated using StructMemList and !!!! with AllocABS. (other Lamers don't) - Lamer8 No known end BeginIo, KickTag, KickCheckSum, SumKickData spreads: over BB damage: Format all drives A new BB is recoded with eori.b. The coding byte is chosen using $DFF007. BB ist coded von $3e bis $3cc Remark: There is a "Lamer"-Bootblock spread, in which Lamer Exterminator is visible in BB. This BB is NOT bootable and because of that is only known by Vt as Nicht-Standard-BB. (Non-standard bootblock) - Lamer-LoadWb Filevirus 4172 Bytes KickTag, KickChecksum, SumKickData, BeginIo in SubDir C Visibel in LoadWb: The Lamer Exterminator !! The virus is executed and written to memory, before the LoadWB command. Does not spread as "LoadWB but writes (Infects) a Lamer bootblock. - Lamer Bomb see: Gotcha Lamer - le RoLE French name for Return of The Lamer Exterminator see below - LOGIC BOMB other name: PARADOX I see there - LSD! (again an SCA!) - LZ-Virus (named by Aaron Digulla , who send this one thanks Aaron) Linkvirus Prgsize increased by 400 Bytes. Look for the Doslibrary version number, when more than "34" or less than 33 the virus does not activate . Changes GlobVec 06 = write. Links to behind Codehunk (normaly 1) , und change e.g. $4e75 = rts against $6004 = bra 4 or $4eee = jup against $60xy . Does therefore not have to change the Hunknumber , but only how many longword you have to reach Hunk $ 64. Condition for a file: 0.LW = $3f3 executebel 1.LW = 0 no resident Libs to load (No overlay) You will find a codehunk, which is more than # 1000 bytes PLEASE: To improve the test , I need more infected files (13.07.91) thank you! This virus is reported to be a strain of the wellknown LZ packer - MAD (ForpibClone) only Text changed see there - MAD II only KS1.2, because of absolute DoIo-ROM-jump Cool, DoIo, KickTag, KickCheckSum, in memory always $7FB00 in BB visible: MAD II VIRUS is better etc. spreads: over BB as soon as the contents of counter is higher than $D, a DiskStepRoutine is called. Because this routine is wrongly coded and therefore doesn't work, only the screen gets dark. - MAD III only KS1.2 Byte-Warrior-Clone see there changed: DASA0.2 in MAD.III - MAD IV LamerAltClone see there difference: in stead of 'Lamer!' the data written should be 'MAD'. - MicroSystems FastMem yes only KS1.2 gets names from ROM (e.g. dos.library) Cool and Cold in Prg. when needed: AddTask, RemTask and DoIo spreads: over BB text display over graphic routine uncoded in BB: YOUR AMIGA IS INFECTED BY A NEW GENERATION OF VIRUS CREATED IN SWEDEN BY MICROSYSTEMS - MCA see Claas Abraham - MEGAMASTER Cool, DoIo, always $7e300 two coded ranges in BB 1st range: eori.b #-$45,(a0)+ ; tests for other viruses 2nd range: eori.b #-$11,(a0)+ ; text display using graphics black background, red chars Surprise!!! Your Amiga is controlled by MEGAMASTER spreads: over BB - MEXX SCA-Clone Text: Hello there... Here I'm again... I've infected ya Disx ! I'm a simple VIRUS and I came from a group called --- MEXX --- Yeah, reset now !!! Or I will infect more! - MGM89 other name: MEGAMASTER see there - Micro-Master (SCA! again) - Morbid Angel Forpib-Clone see there only visible text and some insignificant bytes were changed. - NO BANDIT (see below - virusdetectors) - No head see ByteBanditPlus - No name 1 other and right name : Byte Bandit 2 no FastMem, BeginIo, KickTag, KickCheckSum, Vec5 Memory using structMemList, Allocate for new BBvirus using Allocmem, Counter: Virusstart + $1c spreads: over BB in BB readable: trackdisk.device (almost at the end) a ByteBanditClone, without keyboard check, only 5 copies and smaller timeout. - No-Guru V2.0 size: 1224 Bytes (With PP-Data-Prg.) My opinion is it is BAD for AmiExpress-Users Changes: Alert, Autorequest Text in Cli: u.a. Making life with AmiExpress just that little bit easier... Sucht nach bss:user.data ; Falls exists wenn S8000 Bytes My Advise: Turn off - NorthStar other name: Starfire see below - Obelisk1 (German flag + graphic text) jump: cool writes in memory at $00000060 the word GURU: damages level 7 interrupt. - Obelisk2 Begin, KickTag, KickCheckSum, Vec5 jump: KickTag ,three counters, graphic text with message saying it's going to format, but that is only faked using motor step. Watch with TrackDisplay !! Memory address $60 see Obelisk 1 - OP1 (NewZealand) real name: Joshua - OPAPA Begin, KickTag, KickCheckSum, Vec5 counter: yes, spreads: over BB of any drive text display (graphics) OPAPA-VIRUS READY STEADY FORMAT All drives step to track 0. - PARADOX I KickTag, KickCheckSum, in Prg. DoIo and $6c, always $7F800 spreading and damage: Bootblock Text visible in BB: * A new age of virus-production has begun ... This time PARADOX brings you the "LOGIC BOMB" Virus !!! * - PARADOX II Kicktag, KickChecksum in Prg. DoIo and $6c, always $7F000 coded with move.b $DFF006,D1 and eor.b d1,(a0)+ spreading and damage: Bootblock Text after decoding: This is the second VIRUS by PARADOX - For swapping call: 42-455416 - ask for Hendrik Hansen - PARAMOUNT only KS1.2 KickTag, KickCheckSum, DoIo, Always S7F800 Byte-Warrior-Clone, Turns off Cold and Cool uses NOT trackdisk.device Spreads by: BB in BB : Paramount Softworks. - PARATAX SCA-Clone, Cool always 7EC3E, only changed text - PARATAX II Disk-Dokters-Clone, only KS1.2 because of DoIo-ROM jump Cold, Cool, DoIo, in Prg. Vec5 in BB visible: PARATAX II clipboard.device replaced by ".dos.library" Depending on counter own BB is written or disk is formatted from Cylinder 40 (ROOT) - PARATAX III 16BitCrewClone see there Difference: The 16Bit Crew 1988 changed to PARATAX III (!!!) A really great effort!!!! - PentagonCircle cool,kickchecksum Fastmem yes, in memory always at $7fb00, in Prg. also DoIo tests for some viruses, Alert spreads: over BB Text in BB: e.g. The Pentagon Circle VirusSlayer by Mr.Moutainlake! - PentagonVirusSlayer2: cool, KickCheckSum, always at $7f000 Fastmem yes, in Prg. DoIo, coding entirely different from Pentagon, Alert spreads: over BB Text in BB: e.g. The Pentagon Circle VirusSlayer 2 by Mr.Mountainlake! - PentagonVirusSlayer3: Cool, KickCheckSum, always at $7e000 Fastmem yes, in Prg. DoIo, FindResident Alert spreads: over BB Text in BB: e.g. The Pentagon Circle VirusSlayer by Mr.Mountainlake! - POWERBOMB ByteBandit/Forpib-Clone see there Text: POWERBOMB SYSTEMS PRESENTS: BYTE BANDIT V2.0 !!! - PP-Bomb Poverpacker (3.2) ? False!, Trojan Horse. Is not spreading. - 3 program parts - Short Codehunk with 2 Jsr-Commands (Needs for the running) - Crunced Bomb part. - Poverpacker 3.0b (I think: Not canged and not crunced) Bomb-Part: - Look first for SnoopDos-Task, if found bomb stoped. - Look in DH0:C, and/or DH1: for the "Why" command and changes this file = 0 bytes - Does not change other C/command files (Is tested). - Does change the program "AmiExpres", but not tested. - Looks the following : BBS:, DH0:BBS/, DH1:BBS/, DH0:, DH1:, to delete special files. Source: qtx_pow.lzh.3.2 139670 Bytes. Recommandation delete this false one, and use the original one! - Pseudoselfwriter other names: Selfwriter, Lamer7 - Rene other name: Lamer8 (I use Lamer8) Because 'The LAMER Ex...' is in decoded program and works like a Lamervirus, I think adding to the Lamer group is correct. - Return Of The Lamer PrgFileVirus length 1848 Bytes only Cold reset (Sorry!) Pretends to be Disk-Validator KickTag, KickCheckSum, BeginIo and other recognize: No readable text (original Disk-Validator has) damage depending on time: a) chooses blocknumber with $DFF007 and writes 64 x LAMER!!! b) Fastformatroutine for all drives and over DisplayAlert text display: The Return Of The Lamer Exterminator c) writes bad Disk-Validator (virus) to disk - Revenge Bootloader! Begin, KickTag, KickCheckSum, Vec5 Fastmem: no spreads over BB - Revenge V1.2 cool,doio,vec5 , in memory always $7e000 and memory addresses $C0-$FF (danger for Setpatch-List) spreads: over BB damage: new mousepointer after a while in BB: Revenge V1.2GCount: - Revenge of the Lamer PrgFileVirus length 4560 Bytes only Cold reset (Sorry!!) -Too many pointers changed (10!!) decoded in memory: dos.library.graphics.library.intuition.library. trackdisk.device.DOS s/startup.sequence etc. name:$A0A0A0A0A0 is in root dir and 1st line of Startup tests before spreading whether enough free disk space is available. After 6 resets (I think), Formats all write enabled disks inserted. 3 Page Alert-Meldung - Revenge of the Lamer 2 PrgFileVirus length 4448 Bytes some Write-Test-Routines removed, further like Revenge of the Lamer W A R N I N G: While tesing I managed to let Revenge of the Lamer 1 and 2 spread themselves in a way, that SID and other programs do NOT show the A0A0A0A0A0 file. My FileRequester can't either. The VirusPrg. is nevertheless also spreadable from these disks!!! Using a DiskMonitor the program can be found. In my PrgTest appears in that case: Rev. Lam. unvisible This is NO JOKE! Other programmers have checked it after my discovery and found a bug in ExNext of KickStart 1.3. In V2.0 this bug is fixed. (see also Fish 429 Dr.doc) - RIPPER Programcode = Northstar, only changed text cool in Prg. DoIo always at $7ec00 spreads: BB Text (also visible in BB):ATARI KILLS COMMODORE! RIP! RIP THE RIPPER etc. - Riska Forpib-Clone see there - Sachsen Virus No.1 Cool, always at S78000 BB coded with: move.b #S70,d0 add.b d0,(a0)+ decode in memory: ** SACHSEN VIRUS NO.1 ** Spreads by: BB No real damages and no report GURU: Wenn the virus is in memory and you resets, should CloseDevice changes. With FastMem at S200000 then GURU. - Sachsen Virus N0.3 Cool, DoIo, Wait, always at S78000 Block 0-3 (d.h. a file at block 2 should also be destroyed) Uses NOT trackdisk.device (HD!!!!) All text coded. Spread by: Bootblock 0 - 3 Damages: Writes to block 880 (Root) new disk name SACHSEN NO.3 ON DISK Writes in Block (from SDFF006) 64 x SACHSEN3 Should this block be in a file, then you can NOT rebuilt the file. DisplayAlert and then RESET SACHSEN VIRUS NO.3 in Generation : is running... (for me generation 23). - SADDAM HUSSEIN Bootblockvirus (see also BlowJob) KickTag, KickCheckSum, in Prg. DoIo and $6c, always $7f000 Attempts to mislead the user by text in BB: A2000 MB Memory Controller V2 spreading and damage: Bootblock as soon as the counter has reached the value $7530, a part of the program is decoded with subi.b #$71,D0 and with displayAlert the following text is displayed: TOO BAD BROTHER ... SADDAM HUSSEIN STRIKES BACK !!! THE ONLY ESCAPE IS TO TURN THE POWER OFF !!! - SADDAM-VIRUS Disk-Validator length:1848 Bytes The first virusprogram, that survives a keyboard reset with 1 MB Chip, Kick1.3 and without setpatch r !!!!!!!! Cold, BeginIo, Close in Trackdisk.device, Beam pos. $90(a6) in Prg. also OpenWindow, InitResident, direct Dos.lib-jumps decoded in memory with: eor.b d0,(a0)+ subq.l #2,d0 dbra d1,loop New values for coding are chosen using $DFF007 in D0 Memory: SysStkLower - changed value from $DFF007 - Virusprogramlength damage and danger: Inserting a disk with bad BitMap is enough to activate SADDAM! depending on counter: HeadStep all drives (Disk BAD afterwards) and DisplayAlert: SADDAM-VIRUS overwrites every real Disk-Validator on a write enabled disk!!! When there's no L dir on disk, it is made and SADDAM is copied into it. No other virus has ever made directories by itself! Searches using the FileHeaderBlock the first FileDataBlock and writes in T.DATA the LongWord IRAK . The rest of the FileDataBlock is coded using eor.l d1,(a0)+ dbra d0,loop When SADDAM-VIRUS is active, in stead of IRAK the real value 8 is displayed! (Fake!! see also Lamer Exterminator, which pretends to be a clean BB!) Often writes in ROOT in $13c (=pointer to BitMapBlock) the value zero. When lucky, you will find the original value in $140 (put there by virus) Wenn unlucky, an other part of the virus code has changed the value at that address to 0 shortly after that. Then you should try to start the orginal Disk-Validator from a good disk or try to find the BitMapBlock using a diskmonitor and set it in $13c again on your own. Or read the BitMapTest.dok (11.07.91)(in the VT2.28d file) Remark : Please do N O T try to decode IRAK from a fms.device (Because physical and logical blocks are not the same). You must decode IRAK from a disk!!! - SCA! - SCA 2 no danger, not bootable, always GURU therefore in my prg. only Nicht-Standard-BB (Non-standard-BB) reason: read $200 to $7FC00 from Cylinder 79 and then jmp $7FA00 (everything OK beginners!!) - SCARFACE BeginIo, KickTag, KickCheckSum, Vec5 FastMem no spreads: over BB ResetRoutine, controlled by Vec5 (counter > $2710) in BB: e.g. SCARFACE - Self-Writer other names: Pseudoselfwriter I call it Lamer7 Because 'The LAMER Ex...' is in decoded program and it looks like a Lamervirus, I think adding to the Lamer group is correct. - Sendarian Revenge V1.2-Clone, Cool, DoIo, Vec5, in memory $7e000 and memory address $C0-$FF (dangerous for setpatch-List) spreads: over BB damage: new mauspointer after a while in BB: Sendarian #1Count: - STARFIRE/NorthStar 1 other name BlackStar Cool, DoIo, in memory always at $7ec00, VersionNr: 1 doesn't check for SystemZ, only for SCA, ByteBandit = DisplayAlert spreads: over BB in BB: Virus detected on this disk etc. Reset,WriteProt OFF (not in NorthStar2) - STARFIRE/NorthStar 2 = OldNorthStar ???? Cool, DoIo, in memory always at $7ec00, VersionNr: 2 tests for SCA, ByteBandit, SystemZ, NorthStar1, -> DisplayAlert spreads: over BB in BB: VIRUS detected on this disk etc. My AntiVirus is better! (not in NorthStar1) - STARLIGHT Warhawk-Clone only the text is changed - STARLIGHT II MicroSystems-Clone only the text changed - Suntronic cool,doio, only Kick1.2 because of absolute ROM-jumps spreads over BB , always $7fa00 Suntronic-Text in BB - SuperBoy Cool, in Prg DoIo, in memory always at $7ec00 spreads over BB Alert with .... The Famous SuperBoy - Switch-Off other name: Joshua 2 see there - Target cool, in Prg. DoIo , always $7ec00 writes to every write enabled disk, which contains in Block 880 at $1b0/1 (=Diskname) a certain series of bytes , from Track 80 to the end (something new) useless data source: target.install (Malta) - Termigator: Kick 1.2 (because of absolute ROM-jumps) always $7f4d0, Cool and DoIo decoded Alert: Only the TERMIGATOR'VIRUS makes it possible! Bye!... spreads: over BB - Terrorists PrgFileVirus length 1612 Bytes KickMem, KickTag, KickCheckSum text display with graphic routine takes name of 1st file in Startup and moves OrgPrg. to Root dir (invisible see there) spreads: every write enabled disk with Startup visible in PrgFile: TTV1 black backgroand, white chars, row for row THE NAMES HAVE BEEN CHANGED TO PROTECT THE INNOCENT... THE TERRORISTS HAVE YOU UNDER CONTROL EVERYTHING IS DESTROYED YOUR SYSTEM IS INFECTED THERE IS NO HOPE FOR BETTER TIMES THE FIRST TERRORISTS VIRUS !!! - THE SMILY CANCER LinkVirus, Fastmem yes, in memory always at $7F000, KickTag, KickCheckSum, SumKickData, in Prg. BeginIo and $6c = Vec3 PrgPart decoded with ror.b #2,d1 or coded with rol.b #2,d1 infects first file of startup-sequence, d o e s n ' t test for strange chars in Filename, that is: every file is infected after 20 spreads: Mauszeiger changes to yellow head (smily) with blue hat and continuously a red scroll: "????????.........." " HI THERE!!! A NEW AGE IN VIRUS MAKING HAS BEGUN!!!" " THANX TO US... THANKX TO: --- CENTURIONS --- " " AND WE HAVE THE PLEASURE TO INFORM YOU THAT SOME" " OF YOUR DISKS ARE INFECTED BY OUR FIRST MASTERPIECE" " CALLED: ` THE SMILY CANCER ` " " HAVE FUN LOOKING FOR IT... AND STAY TUNED FOR OUR NEXT PRODUCTIONS. " " CENTURIONS: THE FUTURE IS NEAR!" " " In decoded Prg also: (not in scroll) HELLO HACKERS OUT THERE!! A NEW FORCE HAS BORN IN ITALY: --- CENTURIONS ---. OUR TEAM IS COMPOSED OF 2 GUYZ: ME & HIM.(AHAHHA!) THE AIM OF - - CENTURIONS - - IS JUST VIRUS MAKING.. WE HAVE LOTTA FUN DOING THIS AND WE ALSO HOPE TO GIVE FUN TO THE KILLERS MAKERS (HI STEVE TIBBETT!) HAW! HAW! HAW! SIGNED: ME & HIM / CENTURIONS Remark: I have a Smily-File with four links - The Smily Cancer II Filevirus length: 4676 2x coded after 1x decoding with eori.b #$90,d1 subi.b #$22,d1 at file-end: CENTURIONS STRIKES BACK: THE SMILY CANCER II when starting the program the loadWB command is simulated and the virus copies itself to memory. Spreading is done like Smily 1, that is: No spreading as Smily II! See Smily I - The Traveller 1.0 KickTag, KickCheckSum, in Prg. DoIo u. $6c, always $7F000 dependent on counter: text display red,green and blue bars, black chars NEVER HEARD OF VIRUS-PROTECTION ??? -LAMER !!! spreading and damage: BB (HD too!!!!!!!!!) - Tick see Julie - TimeBomb V0.9 Trojan horse Is made using Prg. BMassacre (It says TimeBomb V0.9 too.) consists of 2 parts in SubDir c and Root: in c: .info = Virus length: 7840 Bytes in Root: pic.xx = counter (Start value=6) length: 1 Byte in 1st line of startup: c/.info not resident, no copy routine in .info Contents: decreases counter value in pic.xx with 1 at every new start. as soon as counter is 0, disk is formatted. To change value in pic.xx, the disk may not be write protected. If it is, the message appears: User Request : Please remove write Protection and press left Mouse Button to continue.. A further use of startup-sequence is without write enabling the disk impossible. in CLI always : RAM CHECKED - NO VIRUS FOUND. - TimeBomb V1.0 BB-Virus (changes no "known" pointers) (depending on counter own BB is written, ((jump at $70208)) or Track 80 (Directory) is overwritten with memory contents from $20000 = Disk becomes unreadable !!!) ((jump to $70026)) - TimeBomber Trojan horse made using the program TimeBomber consistes of 2 parts in RootDir: virustest = Virus length: 936 Bytes virustest.data = counter (Start value=5) length: 1 Byte in 1st line of startup: virustest not resident, no copy routine in virustest Features: decreases counter in virustest.data with 1 at every start As soon as 0 is reached, the disk gets formatted. To change value in virustest.data, the disk may not be write protected. If it is, the message appears: User Request : Please remove write Protection and press left Mouse Button to continue.. A further use of startup-sequence is without write enabling the disk impossible. in CLI always : RAM CHECKED - NO VIRUS FOUND. - Tomates-Gentechnic-Service = TimeBomb-BB-Clone only the text was changed - Traveling Jack LinkVirusPrg with variable Hunklength changes DosBase+$2E (= dos.library-pointer in ROM), doesn't survive reset. a) writes a file to disk VIRUS.xy length always 198 Bytes x and y are HexNumbers, chosen using $BFE801. Text in VIRUS.xy: The Traveling Jack.... I'm traveling from town to town looking for respect, and all the girls I could lay down make me go erect. -Jack, 21st of September 1990 b) links to other programs Conditions: DOS0-Disk, Disk validated, 12 Blocks free on disk, Filelength at least 2000 Bytes, Filename at least 5 chars, Filename contains no chars with value lower than $40, no Info.File Type A: LinkHunklengthnCalculation: $24C + value from $DFF006 decoded in memory $909+1 Bytes Type B: LinkHunklengthnCalculation: $25B + value from $DFF006 decoded in memory $945+1 Bytes - Travelling Jack 3 is it not, it is typ B, I Think. Many Viruscheckers has a bug, becourse they know this one as another than the typ B, maybe they are right. (28.09.91) - TRISTAR-Viruskiller V1.0 It's NOT the Orginal TRISTAR- BB, but somebody has put the text in a Target-BB. (very short code) Oh, you beginners!! VT recognizes Target see there - Trojan other name: Incognito see there - TURK_V1.3 Cool, DoIo, in memory always $7f000 writes TURK to $60 spreads: over BB text display (decoded with subq #6,d0) over DisplayAlert: Amiga Failure... Cause: TURK VIRUS Version 1.3! in BB: TURK - Twinz Santa Claus coder-strain The text is changed to: The Santa Claus virus !!! - U.K.LamerStyle other name: Clist see there - UF-Virus other name: UltraFox see below - ULDV8 NOfastmem, KickTag, KickChecksum, BeginIo, IntVec 5 writes in bootblock (visible): ULDV8 Needs Trackdisk.device Spreads over BB. - UltraFox Cool, DoIo, FastMem yes, only KS1.2 because of $fc06dc spreads: over BB in memory always at $7eb00 counter higher than $f = text display, graphic routine background dark blue, bars light blue, chars yellow Greetings from ULTRAFOX of Aust. - Umyj Dupe only KS1.2 the absolutly DoIo-ROMjumper Kicktag, KickChecksum, DoIo, always at S7F800 Uses NOT trackdisk.device Damage and Spreading by: BB Writes in block 880 (Root) Umyj Dupe DisplayAlert: Umyj Dupe - Vermin Cool, in Prg DoIo always at $7eb10 fills not needed space in BB with contents of $DFF006. spreading and damage: Bootblock - Virusblaster V2.3 unpacked 9232 Bytes I don't have the packed version (Powerpacker??) Is not spreading . Destroy disk in DF0: By loading in Cli you will se a promt as Antivirus Killer from M & T 7/91 . Easy to remove: - virustest other name: TimeBomber see there - VKill 1.0 other name: Aids, changes PutMsg with FastMem: (clears e v e r y write enabled Bootblock w i t h o u t warning !!!, also when it's an Org. Bootblock!! ) with ChipMem only: (writes own BB without warning) DecodeLongWord: " KEN" - Warhawk Cool, in Prg. DoIo, always at $7e600 - Warshaw Avenger BeginIo, KickTag, KickChechSum, SumKickData Very much like Lamer, but BB is uncoded writes depending on counter BB or writes in a Diskblock (place chosen using $dff006) $55 x Warsaw and 1 x !! . - XENO Link-Virus, size of infected prg. increased by 1124 Bytes changes DosOpen, DosLock and DosLoadSeg doesn't increase Hunk-Value in File-Header!!! tests for 0-9, a-z and A-Z before infection, Result: programs with a name that has special chars, are n o t infected. Neither are programs in L or Devs infected. Text display (Output, Write) depending on $DFF006 Text is decoded first ( eori.b #-$80,(a0)+ ) : Greetings Amiga user from the Xeno virus! in an infected file near $460 visible using a monitor: l.devs.fastfilesystem. - ZACCESS V1.0 16Bit-Clone look above only Text changed - ZACCESS V2.0 Forpib-Clone look above only Text changed - ZACCESS V3.0 Extreme-Clone look above only Text changed - Zombi I-Virus Cool, in Prg DoIo, always at S7A000 uses NOT trackdisk.device Spreading by: BB Damage: Wenn the counter has reach SF: - Rewrites RootBlock and BitMapblock. - Names the disk: ZOMBI I - Text with Displayalert text is decoded on S70000 with eori.l #SAAAAAAAA,(A0)+ >>>>> Hello Amiga User !!! <<<<< HERE IS ZOMBI I If you want to clean your Disks se Zombi I without risks! BitMapblock always at S371, can a file that begin at Block S371 be destroyed. All in RootBlock are zero. VT knows this disk on BitMapTest at S1B0. Rebuilt with: DiskDoctor or DiskSalv. end of list.... - known Virus detectors: ====================== partly KickRomV1.2, with Bootblock-write, old, resident, are being removed after request. - ASS VirusProtector V1.0 (KickV1.2, beeps) FastMem yes, KickTag, KickCheckSum, Vec5 - Blizzard Protector V1.0 tests Cool, Vec3, when changed without warning own BB is written (uses therefore over changed CoolVector the other Prg (jsr 82(a0)) Advise: remove - BlizzPro V3.1 cool, Fastmem yes, in Prg. closedevice (oh, something new) spreads: over BB knows some viruses, but writes back KS1.2 DoIo DisplayAlert message uncoded Text in BB: BlizzPro V3.1 and virusnames - CLONK! DoIo, KickMem, KickTag, KickCheckSum, SumKickData only 512KB Chip (or 1MB which survives reset), because for activating a reset is always done. ($7D042 to $80, TRAP 0) source: Clonk! (Alcatraz) - DISKGUARD v1.0 cool, in Prg DoIo, always $7FA00 spreads: over BB Message strange BB using DisplayAlert always writes DoIo of KS1.2, result: Guru with KS1.3 Advise: remove - H.C.S I changes cool, in Prg DoIo, clears KickTag in memory always at $7EC00 spreads: every DOS-BB without warning !!!! - H.C.S II changes cool recognizes some old BB viruses (Alert message) at first BBwrite the DoIO vector is changed and stays changed when drive empty, PowerLed flahes. - Monkey-Killer ASSProt-Clone Advice: Turn off VT knows this BB as ASS-Prot BB - NO BANDIT should prevent from ByteBandit Text: NO BANDIT ANYMORE! R.T. Advise: remove - Sherlock AntiVirusBB , Cool, DoIo, resident in memory, in memory always at $7FA00, also uses $7CA00, text display with DisplayAlert writes wrong value to BeginIO when more than 512KB available, Advise: remove - SystemZ V3.0, 4.0, 5.0, 5.1, 5.3, 5.4, 6.1, 6.3, 6.4, 6.5 KickTag, KickCheckSum, clears Cool, in Prg. DoIo Melody and colourbars from 6.3 no absolute adresses anymore new name Virusprotector (asks before writing) - Virus-Killer KickMem, KickTag, KickCheckSum - VIRUS SLAYER V1.0 Cool, DoIo, in memory always $7FA00 only KS1.2 because of absolute ROM-DoIo old, advise: remove spreads: over BB - known utilities: ================ partly with (N) - ACT-Killer ;BeginIo, KickTag, KickCheckSum, SumKickData (Antivirusprogram) - ALF2-HD ;KickTag, KickCheckSum, KickMem - ATool ;almost all Vectors (Utilities) - Berserker 5 (AntiVirusPrg.) - BOIL3-HD ;KickTag, KickCheckSum, KickMem - BootPic ;KickMen, KickTag, KickCheckSum - Bootpreventor ;Cool, in Prg DoIo advise: remove - Cache-Disk ;BeginIo Taskname; Cachedisk.device - FaccII ;BeginIo (FloppySpeeder) - Guardian V1.1/V1.2 ;KickMem, KickTag, KickCheckSum (Antivirus) - LVD loadseq Typ B: Changes auch KickTag - MemGuard 4 (Memory control) - MemWatch (Memory control) - PatchLoadseq ;Loadseq (Pieter Van Leuven) - PCL deluxe V1.10 ;Cold, Cool, SumKickData, Vec5. (Antivirus program) - Power-Utility ;BeginIo, KickTag, KickMem, KickCheckSum - PP-Patcher ;Fish 515 changes dos.lib open,close, write, examine - ProKiller V1.03 ;Anti-Virus-Program - Protec III ;KickTag, KickCheckSum (antivirus) - Pseudo-Ops ;KickMem, KickTag, KickCheckSum (antivirus) - RAD: (RAMB0) ; KickTag - RETRAX ;Cool, $6c (antivirus) - RRam Disk ;KickMem, KickTag, KickCheckSum (Recoverable Ram Disk) - Setpatch r V1.34 1MB RAD ; Cold - TrackSalve V1.3 ;Disk-Utility - TurboPrint II+Prof ;KickTag, KickCheckSum, (Prof. also Cold) (Printer-Utility) (Prof. 21.04.91) - Ultrakill ;Cold, Cool (antivirus) - VD0: (ASDG-RamDisk) - VirusControlV2.0 ;Cold, Cool, DoIo, BeginIo (antivirus) - VIRUS MURDERER ;Cold always $7EC00 tests Vectors - Damage Programs: ================ - ByteWarriorCreator packed: 6012 Bytes (TNM) unpacked: 7360 Bytes With Fastmem a NDOS-DISK Without Fastmem writes it ByteWarrior to the disk. - Disk.info size: 370 Bytes NO Spreading An Original WB1.3Icon is about to be changed in the struktur. With text: This is a little present for all Lamers. Wenn you insert this disk, and it tries to rebuilt The WB-Icon, can the computer GURU. Has you the startup-sequence in cli, then would none of the icons be changed, and then could you with this disk work with the problem. Help: Change the disk.info with the disk.info on this disk. - Lhwarp V1.40 size: 47880 Bytes (unpacked) Writes (for me) at the target-disk, falls diskstruktur and then the destroyes it the disk. Please try with non-important disk and test with BlockKette. - Virusmaker You an choose between: Byte Bandit, Byte Warrior, S.C.A, Northstar 1+2 and System Z. - X-Ripper V1.1 size: 41360 Bytes (unpacked) Allows you to write a Lamer-BB. And it's gonna be a NDos-Disk, Becourse the DOS-Knowledge is on 8 bytes. - other Bootblocks: ================= - Amiga Action Replay harmless - Anachos Virus-Slayer 3.12 harmless - AntiRipperBoot other name: The Punisher see below - Bavarian I mean that the BB is harmless. - Bootgen V3.4 Botmenu harmless - BootGirl harmless visible in BB: BBM 1987 - Bootintro V1.2 von R.F. Harmless - BootLeg V2.1 harmless - Bootpreventor harmless visible:Bootpreventor - countach v1 tests vectors, no copyroutine, harmless - Copylock 91 harmless - Countach v1 tests vectors, no writeroutine, harmless - DiskSafe PROTECTOR v1.0 harmless - Fastloader by Byte Warrior only changes values in Portstructure (step-routine and time routine for head pause) not resident, no spreading, Reset when LMouse pressed at bootup My opinion: Install, because new values are too extreme (WriteErrors!!) in BB: >>Fastloader by Byte Warrior !<< - Hallon Boot F1-F6 Menu advise: remove - Hypnosis Boot harmless - Install 2 BB Ralph Babel harmless - INTERFERON harmless, not resident tests Cold, Cool, Kicktag to zero, when impossible: ROM-Reset text display over graphic routine in BB visible: I N T E R F E R O N etc. - INTERFERON PRO! harmless - Magic BB harmless tests vectors and for PAL - Meikel BB Harmless tests vectors - MemoryAllocator V1.3 harmless - MemoryController V1.3 harmless - MOSH-BB Cool, after reset S68 always at S7C000 should be af Virusdemo. code with eor.l d0,(a0)+ Advice: Turn off - NoBoot Cold, Cool, in Prg. DoIo etc. , no spreading see Kickstart 10.90 S87ff - NOLL DETECTOR harmless, not resident tests Cold, Cool, Kicktag to zero, when impossible: ROM-Reset text display over graphic routine in BB visible: DIETMAR NOLL etc. - N.O.M.A.D harmless - Outlaw-VirusChecker no spreading, recognizes SCA. However, always writes KS1.2 values (e.g. Vec5 $fc12fc). results in a GURU with KS1.3 not resident - Peter Stuer V5.0 BB harmless test vectors - PROBOOT 1.0 F1-F7 Menu, tests vectors with Install !?!? (user's choice), besides that harmless - PVL Sound BB does not harm Green Display, sound , does not close the "Graphics.Library. - Random Access CopperIntro writes GURU to $60, not resident, no spreading advise: remove - REVENGE OF MAD normal BB - Scoopex utility V1.0 harmless, useful Bootblock - Seek & Destroy harmless - Sinister Syndicate , not resident recognized as a viurs by ZeroVirus 3 I just think it's a CopperIntro, without eor- or spreadings- routine, GURU is written in $60, can be set back in menu (see Obelisk) - Starlight harmless This is really the Viruscope V1.0 BB, but someone had changed the text. - Telstar cold, cool, counter $c0 very mean, pretends to be Virusprotector 6.0 (text), decoded (neg.b) BBpart after $7fc00, every 4/2.Reset graphics (Dutch Flagg and Text e.g. Telstar), no copy routine found - The IRQ Protector (BB) and FilePrg no spreading changes OpenLibVector to $120, but doesn't check whether it's already set. FilePrg: changes OldOpenLib to a random address, without Vectortest. advise: remove - The Punisher other name: AntiRipperBoot, Cold changes Cold and writes a value lower than $FF at this place. reult: when booted from a different BB, a reset is caused advise: remove - The Supply Team not resident, no spreading, but writes KS1.2-vectors therefore advise: Install clears Cool, KickMem, KickTag, KickCheckSum. always writes only absolute KS1.2-vectors: DoIo, BeginIo, Vec5 Also text display over graphic routine, dark background light brown bars, dark brown chars Text in BB too: The Supply Team - UNICORN V1.1 harmless I think it's a CrackerBB with PictureLoadFunction some Viruskillers think to find a Formatroutine: the instruction move.w #$b,$1c(a1) is there, but when this line is reached, the trackdisk.device is already closed and input.device is opened. (Writeevent?) - Viruscope V1.0 BB harmless - VIRUS MURDERER as BB harmless - Virus v4.2 harmless DisplayAlert when booting : I control your computer ect. no vektors are changed and no spreading routines. Advise : delete - VirusTerminator 1.0 = A.C.I.D no spreading, recognizes SCA, Byte and DASA. writes always KS1.2 values (e.g. DoIo $fc06dc). result: GURU with KS1.3 not resident - VirusTerminator 3.0 = A.C.I.D no spreading, recognizes some Viruses, DisplayAlert, then clears Cool and resets with ROM-Jump. not resident, harmless, because no already set pointers are set. Only Viruses are removed using Cold reset, that I have reassemled. Unfortunately viruses get better all the time (more lists and pointer changes), So that the original situation can not be restored. Therefore also with some viruses I have already reassembled, only a cold reset! Everything else is too dangerous to me!! (pointer forgotten, Task not recognized etc.) Crunchers: ========== - Black & Decker V2.0 - Byte Killer V1.2+ - Compacker+ V4.2 - Crunch Master V1.0 - DEFJAM Packer V3.2 - Double Action V1.0 - DRAGPACK v1.0 - High Pressure Cruncher - HQC-Compress - HQC-Cruncher - Imploder - ISC V1.5 (Rainbow Trio) - Lightpack V1.5 - LzHuf - Mastercruncher V3.0 - Max Packer V1.2 - Mega Cruncher V1.2 - PackIt V1.0 - PowerPacker - PowerPacker-Data - PowerPacker-Clone - Relokit V1.0 - RSI-Cruncher - Stone Cracker V2.99b - Super Cruncher V2.7 - SupplexCruncher - Syncro Packer V4.6 - Tetra-Crunch V1.1 - Tetra-Pack V2.1, V2.2 - Time-Cruncher V1.7 - TITANICS-Cruncher - TNM-Cruncher V1.1 - TryIt V1.01 - TUC-Cruncher - TURBOSQUEEZER V8.0 Archive: ======== - APE - ARC - compress - LHSFX - LhArc - LhArcA - LZ - PKAZip - ZOO 2.x Disk- and Trackcrunchers: ========================= - Disk Imploader - Lhwarp Vorsicht mit LHwarp V1.40 - The Disk Masher (DMS) - Warp - ZOOM 4.1 Heiner Schneegold Am Steinert 8 8701 Eibelstadt (Germany) Tel: 09303/8369 (19.00 - 20.00) see you soon !! Heiner