=============================================================================
= - SADDAM VIRUS ---------------------------------------------------------- =
=============================================================================

 If you thought we got finally rid of Saddam you are wrong. This time he is
 back in the form of a filevirus. Even an experienced user as myself had
 quite a difficult time battling against this new generation of viruses.

 I will tell you my story so perhaps you regognize the symptoms. It all 
 started when I started working on a few new PD disks. As always I did 
 put the UGA-logo picture in the bootblock and continued copying files
 to the disks and finally made the new menu and keymap. But every time 
 I faced problems like:

 - Bootpicture was gone, disk wouldn't boot anymore or gave software failures
 - After booting the disk a message popped up saying "Disk not validated"
   which normally appears if there is no diskvalidator on the disk.
   Also if I tried to access the data by using a filecopier it was impossible
   to get access to the files. 
 - Read / write errors on 100% good disks
 - Disks became non-dos disks

As an experienced user I got the feeling that something was giving me a hard 
time and I started thinking about the cause of my problems. I bought sometime
ago an A500 + 52MB SCSI II harddisk and suspected the new system. I turned
back to my old A1000 but again the same problems did appear.

After producing 15 new versions of my PD disk (replacing files with the
original files from my workbench) I still had no idea. Slowly the feeling
of a virus problem was attracting my attention. But where ? The boot was
clean and all files had been checked with an update viruskiller.

Then I received the master copy of our new Powerutility called Kill da 
Virus. I booted the disk and when the program appeared on the screen there
was a message saying "Saddam virus killed in memory". I called Mike Hansell
from Australia (oops phonebill !!) to give me advice. He told me he was
working on an update which could also remove the virus from disk and I 
would get it from him by modem before the AMI-expo in Germany.

I checked all my disks. The whole problem is that as soon as you put an
infected disk in any drive the computer will always activate the disk-
validator to get informations about the files present on the disk.
So even if you not boot a disk but only insert the disk in the drive
you will have the virus in memory.

We now have put a small utility on every PD disk that checks the main
system vectors so you will always see if something has been changed.

If you face the same problems then please always use a viruskiller that
first cleans the memory and after you have cleaned the memory please
exit the program (no reset !!) and start a fileutility to get the 
healthy files on another disk. Some extra advice:

- set a 100% disk-validator (L-directory) on protect using e.g. diskmaster
  or the AMIGA Dos command PROTECT.

- put a vectorchecker in your startup-sequence.

- make backups of important data

- use a reliable viruskiller to check new disks first. You can use bootx (PD)
  or e.g. our own viruskiller Kill da Virus that is available from all UGA
  dealers for a budget price. 

- always set an infected disk to write-protect to avoid further damage.



From [32mCarl Paauwe[31m I received a trick for users with enough memory to save
data from an infected disk to memory.



0.  Power off and then on so memory is clear
1.  Put in your original workbench disk and boot
2.  Choose Shell or CLI 
3.  Put in the infected disk
4.  type the following command : COPY FROM DF0: TO RAM:
    (512K users > please copy everytime a part of the files )
5.  Delete Disk-validator from ram:L 
6.  Type : MOUNT RAD:
    (autostartvector is now directed to RAD)
7.  Put an empty formatted disk in your drive
8.  Type: COPY FROM RAM: TO DF0:
9.  RESET and boot a disk that has a bootblock that kills any virus in 
    memory.
10. Put in your workbench again and let the disk be validated by a 
    healthy diskvalidator (WB). This is needed because the virus leaves
    files open.
11. Copy your disk-validator from your workbench on the new disk.

PS: the easiest thing is to put a filecopier on a copy of your workbench
    disk so and use this tool to copy the files to ram: and back to the
    new data disk.

=============================================================================
= - [33mSADDAM VIRUS[31m ---------------------------------------------------------- =
=============================================================================


