
     ---------------------------------------------------------------------
                            VT 2.39 ENGLISH VERSION.

     Translated (as much as possible) from German to English by Marco
     'Topic' van den Hout, June 27th 1991,"SHI".  Updated by "SAFE HEX
     INTERNATIONAL" a world  wide federation against virus spreading. If
     you want more info then contact:

     SAFE HEX INTERNATIONAL, MAIN CENTRAL VIRUS CENTRE:

     Erik Lovendahl Sorensen
     Snaphanevej 10
     DK-4720 Praesto
     Denmark
           Phone   : + 45 55 992512, Modem Robotics HST V. 42 38.400 Baud.
           Fax     : + 45 55 993498
           Fidonet : 2:23424/43

           Attention:  Fidonet mail is only replied to by postal letters or
                       by fax, therefore state your name and address.

           Virus helpline: Phone +45 55 992512 between 1600-2200
           Virus helpline: Fax   +45 55 993498 between 0000-2400

                        ATTENTION DO YOU WANT 1000 USD?
              THEN SEND THE NAME AND ADDRESS OF A VIRUS PROGRAMMER

                                     ALIAS:
           * * * * *             SPEEDY GONZALES            * * * * *

     SHI translation changed line 247-255, line 366-396, date 05-04-92

     ---------------------------------------------------------------------
        VT2.39 DOC [-vz] [-bt]                        (Version DD.MM.YY)

                   ?   This Text, then program end
          <Par1>   -vz test vectors, OK = don't show them
                   OK = Do not branch to main menu
          <Par2>   -bt don't test bootblock in df0!!!
                    Equals less protection!!!
                    parameters are optional!
           Heiner Schneegold, Am Steinert 8, 8701 Eibelstadt
     Note:

     - Please read VT.LiesMich (VT.ReadMe) first. Thanks !
     - PD distributors should contact me first !!

       Heiner

     IMPORTANT IMPORTANT IMPORTANT

       Do not use VT as a background running killer, it uses too much RAM.
     If you use another program together with VT the bitmapblock will
     probably change, in case you are de-protecting your disks.

     IMPORTANT IMPORTANT IMPORTANT

       With Kickstart 2.04 hardlinks can be shown (with makelink) and
     softlink, (e.g. with assembler).  VT is effective with hardlinks
     together with Kickstart 1.3 and 2.04.  VT Softlinks is shown only with
     Kickstart 2.04.  With Kickstart 1.3 VT breaks down with a guru by
     File- and Blocktest.

       The links are found with Kickstart 1.3 by using a different code,
     and without any guru.

       Last changes 31.03.92

       Changes since VT2.38
      ----------------------

     IMPORTANT !!!!!
       In order to be sure to find LinkViruses that attach AFTER the 1st
     hunk, you MUST use the filetest!!!

     - Nast File virus, KS2.04 too                                29.03.93
     - Red October File virus, KS2.04 too                         27.03.92
     - Program end in the "Filetest" feed back changed
     - Irak Clones please read "VT-Knows" about Saddam virus      22.03.92
     - Agnus Test changed                                         21.03.92
     - Mallander. BB Block 0-3, KS2.04 too                        20.03.92
     - BootX-Virus BB, KS2.04 too                                 18.03.92
     - You can now use the "Space" or left mouse button for
       several options                                            16.03.92
     - Most of the options can be                                 16.03.92
       cancelled either by pressing the ESC
       key, or the right mouse-button.

     Program requirements:

     - The program needs up to 150KB Mem (Fast and Chip (when no Fast
     available only Chip is used [obviously]).

     Typical requirements:
         - 55KB own program (with stack and memory built in the program)
         - 20KB Main window (operating system)
         - 15-20KB for requesters (operating system)
         - 5KB temporarily for newly inserted disk (operating system)
         - 10KB file requester
         - KickRom V1.2 or V1.3
         - works also on an A3000 under KickV1.3
         - works with Exec 36.202 on A3000
         - does  not work with Kickit B1-Bx on A2000
         - I expect problems with patched KickStart Eproms
         - with KickDisk V1.2 Vers.33.166 my program doesn't work
          (Trackdisk.device in a different place)
         - PalScreen  (not always available, Commodore knows that !!)

        ATTENTION PLEASE! If you only have 512 k RAM, then break to CLI
                          using CTRL-D to start VT.

     Program start:

     - Start program from CLI or WorkBench
     - or put in Startup-Sequence
     I advise you to use "VT2.32 -vz," etc.


     Note:
       When started with VT2.35 -vz the program only starts in full when a
     vector is set or a BB is non-standard.

     The sequence of events after startup:

     - Test for KickRomV1.2, V1.3 or V2.0
     - Test for PAL-Screen
     - Some windows are opened (should ALWAYS appear for a short while!!!)
     - Some vectors are tested and shown
     - When no change, the program ends
     - When change, then:
     - Search for known viruses (see below) starts.
     - If search proves positive
     - virus name is given
     - vectors are reset and shown
     - virusprogram is overwritten with zeros
     - no reset needed
     - after 2 Secs. program ends

     - when test is positive 2
       for technical programming reasons, with some viruses it is necessary
     to remove the virus before showing the vectors (e.g. Extreme) and to
     fill it with zeros.  The following requester will appear:

                                XYZ-NameVirus
                               war im Speicher
                     Weiter                     Weiter

                          [      XYZ-NameVirus      ]
                          [      was in memory      ]
                          [Continue         Continue]

     - when test is negative you get this requester:

                           unbekanntes Programm
                               im Speicher
                     KReset                     weiter

                          [     unknown program     ]
                          [        in memory        ]
                          [Cold Reset       Continue]

     - weiter [Continue]:
           No changes are made and the program is ended

     - KReset [Cold Reset]:
       Vectors are reset (note this a cold reset, just like switching off)

     - reset
       This way is chosen so that future viruses with their own tasks (you
     can't reset pointers without removing that task) can be killed without
     switching the computer off and on.

       Simple program virus test for Startup-S.
       ========================================
     - only when a disk is present in df0: !!!!!!
       have no fear when the drive runs for a second, it's got to be read!

     - Search for initial cli                    length: 6048 Bytes

     - Search for JEFF Butonic V3.10             length: 2916 Bytes

     - Search for Lamer-LoadWB                   length: 4172 Bytes

     - Search for icon.library-BlueBox-Virus

     - Search for BRET HAWNES
       Name in Root:C0A0E0A0C0

     - Test for Orginal Disk-Validator KS1.2/3   Length: 1848 Bytes

     - Test for long Disk-Validator              Length: 1892 Bytes
       Source unknown, but harmless
       (this way it finds Return of the Lamer and SADDAM-Virus)

     - Search for BGS9 I in DF0:devs and DF0:
       Name: A0A0A0202020A0202020A0 (the moved original program )
       so it's an indirect BGS9 I-Test

     - Search for BGS9 II in DF0:devs and DF0:
       Name: A0E0A0202020A0202020A0 (the moved original program )
       so it's an indirect BGS9 II-Test

     - Search for Terrorists in DF0:
       Name: A0202020A02020A020A0A0 (the moved original program )
       so it's an indirect Terrorists test

     - Search for Disaster Master V2 in DF0:c/cls

     - Search for JEFF-BUTONIC-name V3.00 in DF0:s
       Name in startup: A0A0A0209B41
       important: ?!?!?!
       Test only 1st line !!!!!!

     - Search for Revenge of the Lamer I+II in DF0:
       Name: A0A0A0A0A0

     - test for Tarnnames of Jeff-Butonic V1.31

     - test for TimeBomb V0.9

     - test for TimeBomber

     - Search for $A0 (EM-Worm) in df0:c

     - NO  test for IRQ-Program in startup-s.

     - NO  test for XENO-Program in startup-s.

     - NO  test for THE SMILY CANCER  in startup-s.

        BOOTBLOCKTEST
        =============
     - can be switched off using -bt
     - when not switched off, tests  ONLY  df0:
     - only when disk present
     - no fear, drive must run shortly

        MAIN window:
        ============
     - You can only come to this part of the program when the -vz switch is
     not set or a NonStandardBB is found in Df0
       TWO TIMES 'PLEASE' if you want to write to disk !!!!!!

       [You must confirm a "write" instruction by clicking twice.]

     - Set the original vectors in first part of program, also when you
     will have to reload a (for you important) resident program after exit.

     - Work with a disk backup (Please notice, that program bugs can also
     happen to me !!!!)

     Explanation:
       Ende = program end

       Listen: (List actual task)
       ------
       With this feature you can get quick information about what task your
     computer is actually running (like the program SnoopDOS).  This
     feature is very excellent to find a virus task too!
       Attention: You have to do an analyse special, if you DON'T get an
     address in your ROM ($F8 - $FC).  Note the "Listen" only runs once,
     that means the tasks don't change dynamically.

     Explanation to IntVec:
       With KS2.04 Aud 0-3 runs first after the first call to the
     audio.device.  This is to every time the meaning with the start line
     for IntVec, although the calling is done by Listen.  Virus programmers
     do not only use Listen, but use direct (often used nr 5).  Therefore
     this line (Example the Dasa virus).  To stop - Use ESC or right mouse
     button.

       Z.Zyl. (Show Cylinder)
       -----

       Physical cylinder 0

       Logical cylinder 0

       Root cylinder 0

       To stop - Use ESC

     Note: The root block of a hard disk MUST not be placed in block 0, but
     must be placed in a track of this cylinder.

       Example: Your hard disk has 6 surfaces and 33 blocks in each
     cylinder.  Then the root block can be placed in block 99 of the
     cylinders.  You have therefore to use the PropGadget to find where it
     is placed.
       Basically this feature was only made for hard disks, but is
     excellent to show special viruses on disks, (e.g. The French Kiss
     containing 6 blocks)

       Block Test - Right up to begin with 0!

       You can save the block when you've done by using the FileRequester!

       Why this feature?
       Because Commodore have placed the Rigid Block out of each partition,
     then all disk monitors (jan92), can't be used to investigate this
     area.
       Now we have boot viruses, that are able to infect hard disks by
     writing block 0 of cylinder 0.  The result of this is that the
     Trackdisk.device has disappeared (you get O.F.S.and not F.F.S mode of
     your hard disk (autoboot hard disks are always F.F.S!))

       To prevent hard disk infection caused by boot viruses you can save
     and re-install the boot blocks 0-3 of your hard disk.

       Error Messages: See BlockIITest

     - Disk Bad:  Problems with a track of the hard disk, which is
     corrupted by Low-level-Format.  Then re-install your boot back-up
     again.  Use the PropGadget and find the actual block.

     - With Disk: Track failure, or not a DOS disk

       Compare:
       -------

     - every 1024 bytes

     - analysis Testbegin for 2nd object or 0
       This mode has to be done FIRST, when the Begin by 2nd object is
     analysed.

       Why:
       Several "Bootblock Save Utilities" place a "recognize" for 1st
     device in the start of the bootblock.  You have therefore to use 4th.
       You have a well-known linkfile and you have to compare this file
     with another file.  Because 2nd file have more hunks (calls for 3rd
     device), you have to wait for Testbegin the 2nd file to $000003E9.

     - BB <-> BB
       Load 2 bootblocks at the same time from track 0.  Then you are able
     to do a comparison test.  You can use this option to analyse the
     special re-coding bootblock viruses (e.g. with $DFF006)

     - BB <-> File
       Compare BB from track 0 with a comparison BB from Track 0 held in an
     archived file.

     - File <-> File
       Compare two files

       VT - Prefs :
       ------------

     - with page (seiten) stopp    Yes (Ja) / No (Nein)
       [This appears to be a scroll-lock option - PEB]
     - BB with expansion.lib       Yes (Ja) / No (Nein)
     - DOS 2/3 for KS 2.04         Yes (Ja) / No (Nein)

       VT -Tools
       ---------
     - Show vectors
       Return to main program with weiter
       The configuration is only quite done with KS2.04 or SetCpu with
     KS1.3.  I have to work with KS1.3 Supervisor and Trap, this is too
     dangerous I mean.

     New: LoadSegVector
       You will be surprised how many user programs there are that use this
     vector.  Use then Loadseg in tools and try to find an ASCII-text, or
     use Systemtest in Tools.  If you find any hidden value in Dos.Library
     -$94, then use a memory monitor to analyse this for a virus.


     - SystemTest
       Next screen: Space or left mouse button
       Tests all ground vectors: Libs, Devices and Resources, that are to
     found in memory.  Vectors that are not in ROM are analysed.  All
     vectors from running programs (e.g.diskfont.library) are not placed in
     ROM.  Vector analyse, which does not analyse the ROM in addresses
     greater than +- $6000 is ignored by VT, if you use "Nein", (No) in the
     requester.

               Example: DoIo       Exec -$1c8     KS2.04
                        -$1c8      -$1c6
                        $4ef9      $00f80808
                        JMP        address call
                        2          4 bytes     =  6 bytes

       DoIo is hidden, then VT shows -$1c6 (analysing the source)
       Example: Setpach from KS1.3 hides several vectors.

     - LW-Info:
       Load a disk in your drive.
       Informs you about disk drives DF0-3 and the disks therein.
       Attention with KS1.2 and KS1.3: you don't get an analysis for the
     following: PreAlloc, MaxTransfer, Mask, BootPri and DOSType (All
     missing in the old Commodore ROMs).

       Analyse: Used blocks, Freeblocks + 2 bootblocks

                          SectorPerBlock    BlocksPerTrack
       Normal drive             1                11

       H.D.   drive             2                22

       Please note that you can use the Chinon FB357A hard drive with
     KS2.04 in Amiga 2000C.

     - setze OrgVec = sets all important vectors, but a program is not
     filled with zeros, as in 1st part of program

     - zeige Vec = shows vectors  without  virus test

     - KRESET with safety-asking [confirmation].

     - Base
       Dos.lib is shown where it is placed in the memory and after block
     2$00.  In block 0 and 1 the negative offsets are also placed.  In
     block 2 and 3 are the positive offsets.
       (Not recommend to use by Commodore)
       Exec.lib / Dos.lib positive offsets recommend by Commodore
       Graphics.lib
       Int.lib
       TrackDiskDevice (the structure is very small)

     -Zeropage shows the memory from $0 with the important vectors

       BitMapTest
       ----------

       Please only use this prg. part on disks infected with Disk-Validator
     Viruses.  (Filetest and BlockLink "Blockkette" reports Bitmap invalid
     "ungueltig").

       Case 1 :  Bitmapflag = $138 in Rootblock is zero


       VT gives you the chance to recalculate the bitmap.  You have to
     remove the disk for 10 seconds (the Dos system refuses to use load the
     disk) then you have to load the disk again, and run filetest.

       Case 2 : SADDAM has changed the pointer from the bitmapblock = $13c
     to $140.  VT gives you the chance to change it; remove the disk,
     please (see "Case 1" above).

       Case 3 : SADDAM is not removed from L/Disk-validator.  VT gives you
     chance to rename to a new name: "Zisk-Validat", (to solve in this way
     the "Hash-content").  Please remove the disk (see "Case 2" above).

       Case 4 : The greatest problem, I have 3 disks this way.  S13c and
     s140 contain 0, here VT needs your help!!!

       The solution:

       Please use the "Bitmaptest" for the Disk-validator and rename it.
     You MUST rename when you find an infected Disk-validator.  Remove the
     infected disk!!!  Please write enable the disk.  Please then use
     KReset or a coldboot (shut your Amiga off).  Insert a disk with the
     ORIGINAL Disk-validator, and then the damaged disk in Df0 or Df1.
       The  operating  system will now find the $13c error, and try to load
     the the damaged disk, but can't because you have changed the name (I
     hope?).  Then the original Disk-validator from the second disk will be
     loaded into the system.  If you are using only one diskdrive you have
     to change disks when you get the requester "Insert.....".  The Dos
     system will now get the $13c in this way... take your time and wait
     until the diskdrive LED is off.
       Then you have to restart VT, and VT repairs the damaged IRAK files
     and removes the "Zisk-validat" file.
       To date (10.07.91), I have been able to repair ALL disks I have got
     by using the method described above.

       VT knows Zombi-Disk, please read the Zombi Virustext.
       VT knows Freedom-disk, please read the Freedom-Text.

       VT cannot ,of course, show original games with disk formats other
     than those with the standard DOS rootblock (S370=880)


       BlockITest
       ----------
       Shows possibly corrupt blocks (of course not with trackerror)

     Test1:
       Search for Trackerrors (marked green).

     - Error 30 SeekError         Track not found

     - Error 29  Disk Changed
       (even if you don't believe it, this error is often in Byte 31 of the
     DiskIoReq.  It happens mostly when the read head gets to the next
     cylinder.  If this happens, stop the test and restart it)

     - Error 28  WriteProtected    not checked here

     - Error 27  BadSecHdr         illegal Sector-Header

     - Error 26  TooFewSecs        too few Sectors found

     - Error 25  BadSecSum         bad Sector-Checksum

     - Error 24  BadHdrSum         bad Header-Checksum

     - Error 23  BadSecId          bad Sektor-ID

     - Error 22  BadSecPreamble    bad Sektor-Preamble

     - Error 21  NoSecHdr          no Sector-Header found

     - Error 20                    error (but unknown to me)

       Advice:   (NOT for orginal copies of games with own format !!!!)
     - save what's possible by copying files one by one or by using
     DiskSalv or similar
     - reformat disk, if orginal commodore format breaks down, put the disk
     in the trashcan [a real wastebasket as this means the disk itself is
     damaged/faulty and cannot be used].
       Please don't XYZ-Format WITHOUT Verifying.

     Test2:
       Search for block contents, made by viruses (marked orange):
     - Lamer!    85 times + 1 times !! = 512 Bytes

     - LAMER!    85 times + 1 times !! = 512 Bytes

     - LAMER!!!  64 times = 512 Bytes    (Return of the Lamer)

     - VIRUS     Track 0      (Digital Emotion)

     - Warsaw    85 times + 1 times !! = 512 Bytes

     - MAD       85 times

     - IRAK      1st FileDataBlock coded by SADDAM-VIRUS

     - 11111111 22222222 44444444 88888888  = Glastnost from $100 in Block

     - Sachsen3  64 times = 512 Bytes

     - Should one of these blocks contain a file (test with Blockkette),
     then it could be that this file CANNOT be rebuilt.

     - IRAK      1.Filedatablock coded SADDAM-VIRUS can now be rebuilt.

     - test for $5555 (UU) removed again, because it's made using delete
     and rename (Fastmem and FastFileSystem needed!!!)

     Test3:
       When blocktype 2,8 or $10 is recognized (FFS-Datablocks,
     BootGirlDatas or similar are not seen by the 8-Test) :
       The checksum of the block is calculated and compared with the 5th
     longword.

     Error message (green):

     - BadBloCheckSum
       Note for Test3 and FFS Hard drives:
       HDs with 165000 Blocks often show an FFS sector starting with 2 or
     $10.  Please don't take this error message too seriously, but check it
     once in a while using a disk monitor.
        On old AmigaDosSystem (Disk or HD) it DEFINITELY is a corrupt
     block!!!

     Test4:
       All LinkViruses that I know of are marked orange with their
     blocknumber (ADos and FFS).  Use Filetest to obtain more info.

       Note: BlockITest tests ALL Blocks, so a LinkVirus can be found
     that's already deleted and therefore cannot be found using PrgFtest
     and can't be activated.
       Reason: after Rename or Delete Amiga-Dos only removes the filename
     from the directory and marks the blocks in the BitMap as free.  The
     FileDataBlocks, however, are NOT changed.
       decode IRAK (09/10.07.91)

       BlockLink (Blockkette)
       -----------------------

       Tests  ALL  Blocks in a file for errors (see also the BlockITest
     section) and viruses (see also the FileTest section).
       Note: The old Amiga file system works with a double link up.  Should
     a "Soft" error appear (e.g. bad HeaderKey), this can often be fixed by
     copying df0: to df1:.  If you're having Trackerrors, then please use a
     program such as Disksalv to repair the damage and salvage your files.

       BB -> Speicher
       ---------------

       please click DF0: or Devs

       Loads bootblocks in memory and tests them.

       Viruses that I have are tested for 3!!! Longwords in BB.

       When a virusname and upside-down question marks appear, I don't have
     the BBVirus myself, but found a longword in some publication.

       I do not take any!! responsibilities for this!!  Please send me this
     BB!!

       Hard disk: From the Partition with the lowest LowCyl the real
     PHYSICAL block 0 is shown.  From other partitions the LOGIC block 0.
     Please don't change the REAL block 0!!
       ONE fault and access to ALL files on the HD becomes impossible!!

       Speicher -> BB
       ---------------

       please click DF0: or Devs

       writes buffer to block 0 and 1 of DfX

       You can copy bootblocks using this command (but please no viruses!)

       write condition:
                 - 512 Bytes/Sector
        Think twice before writing the BB on a Hard disk!!!!!!!!!!!
        NOTE: One doesn't write one Block 0 of the HD, when one doesn't
              want to have a nervous breakdown!!!

       Speicher
       --------

       all changes are only made in memory


       Changes to disk are made using Speicher -> BB (see above)

       NoBoot = make blocks without bootprogram.
              click:
                    AD  for old AmigaDosSystem
                    FF  for FastFileSystem

       insta. = install bootable BB
              click:
                    AD  for old AmigaDosSystem
                    FF  for FastFileSystem

       BLK0/1 = gadget-switch for display of block 0 and 1 in HEX and ASCII

       With Install (Ver.37.5 from 28.04.91) WB 37.67 would write a new
     bootblock, patched with the expansion.library.  Because the ROM-
     Version from KS2.0 also are necessary. [can't rephrase this bit -PEB]

       BB-KS2.0 with expansion..library
         dc.l s444F5300,sE33D0E73,s00000370,s43FA003E
         dc.l s70254EAE,sFDD84A80,s670C2240,s08E90006
         dc.l s00224EAE,sFE6243FA,s00184EAE,sFFA04A80
         dc.l s670A2040,s20680016,s70004E75,s70FF4E75
         dc.l s646F732E,s6C696272,s61727900,s65787061
         dc.l s6E73696F,s6E2E6C69,s62726172,s79000000

       BB-FFS-KS2.0 with expansion.library
         dc.l s444F5300,sE33D0E72,s00000370,s43FA003E
         dc.l s70254EAE,sFDD84A80,s670C2240,s08E90006
         dc.l s00224EAE,sFE6243FA,s00184EAE,sFFA04A80
         dc.l s670A2040,s20680016,s70004E75,s70FF4E75
         dc.l s646F732E,s6C696272,s61727900,s65787061
         dc.l s6E73696F,s6E2E6C69,s62726172,s79000000

       BB KS2.0 with expansion library    25.08.91
                ;DOS0     Pruefsumme    Show of Root
         000A0000 444F5300 E33D0E73    00000370
                ;Show of name  "expan...."
         000A000C 43FA003E                               LEA sA004C(PC),A1
                ;mind. Vers 37
         000A0010 7025                                   MOVEQ  #s25,D0
                ;openlib
         000A0012 4EAEFDD8                               JSR  -s228(A6)
         000A0016 4A80                                   TST.L D0
                ;Not found
         000A0018 670C                                   BEQ.S sA0026
         000A001A 2240                                   MOVEA.L D0,A1
                ;patch
         000A001C 08E900060022                           BSET #6,s22(A1)
                ;closelib
         000A0022 4EAEFE62                               JSR  -s19E(A6)
                ;show of name  "dos..."
         000A0026 43FA0018                               LEA sA0040(PC),A1
                ;Findresident
         000A002A 4EAEFFA0                               JSR -s60(A6)
         000A002E 4A80                                   TST.L D0
                ;Not Found
         000A0030 670A                                   BEQ.S sA003C
         000A0032 2040                                   MOVEA.L D0,A0
                ;hole Shower of initial. to a0
         000A0034 20680016                               MOVEA.L s16(A0),A0
         000A0038 7000                                   MOVEQ #0,D0
         000A003A 4E75                                   RTS
                ;ErrorFlag
         000A003C 70FF                                   MOVEQ #-1,D0
         000A003E 4E75                                   RTS
         000A0040 dc.b "dos.library",0
         000A004C dc.b "expansion.library",0,0,0
         000A0060 00000000 00000000 00000000 00000000



       Lam3 = only activated when Lamer3 is found.  Lamer3 codes the
     original BB  and moves it to block 2 and 3.  Block 2 and 3 are decoded
     and moved to buffer (memory).  After that you can write back the
     original BB.

       When is it useless ???
       - When the copy protection starts on block 0 (longtrack etc.)
         (The program hasn't worked since the infection).
       - When a file or BootblockIntro has used block 2 and 3.
         I have found Lamer 3 on a PD-Disk in this form.
         (The file is already damaged by Lamer3).

       FileTest:           (ProgramFileTest)
       ---------

     - Insert disk and wait until the drive LED is off!!!

     - click DF0: or Devs

     - Requester appears: Weiter nach jeder Seite mit Leertaste
                                     Ja    Nein
       (Continue after each page using spacebar  Yes/No)
       This was necessary because with a 68030 the name of a crunched file
     was almost unreadable.

     - Break by using ESC-key
       I wonder with what other programs problems appear now.

     - Multi-Tasking is hard to obtain with my program anyway.
       There are always some tricks that have to be done, e.g. changing
     some pointers to make sure no Dummy-BB's are shown (Like Lamer 3
     tries)

       Test1:
       This test is only done when DOS0 is found.

          Test Longword 0 of Filedatablock for 8 :
             error message: bad T.DATA
          Test whether pointer in longword 1 points to Fileheader:
             error message: bad HEADERKEY
          Test whether value in longword 2 contains right values:
             error message: bad SEQNumber

       - normal writing: nothing found


       Test2:

     - normal writing: nothing found

     - orange chars and requester: probably a virus in File

     - green chars: File is crunched or archived
                    NO  test for infection possible
                    please decrunch and test again

     - orange chars and Text:    File corrupt?
         Structure at start of file is corrupt. Please remember the
         filenames and try to start them from the CLI.
         Note: an error e.g. in the 55th datablock of a file is NOT
         found!!!
         If a large number of errors are found on a disk, this can cause
         VT to crash.
         This is not my fault, it's AmigaDos'.
         Every corrupt file started from CLI causes a guru.
         Anyone who doesn't believe this should try it for themselves.

     - find IRQ I, IRQ II, BGS9 I, BGS9 II, Disaster Master, Revenge
     Lamer1+2, Org. programs moved by BGS9 I, BGS9 II or Terrorists, XENO,
     JEFF-BUTONIC I+II+3.10, Terrorists, THE SMILY CANCER1+2, Travelling
     Jack I+II, Return Of The Lamer (Disk-Validator), CCCP-Link TimeBomb
     V0.9, TimeBomber, EM-Wurm, BRET HAWNES, SADDAM, Colour, BlueBox, LZ,
     Lamer-LoadWB, Gotcha, PP-Bomb, Virusblaster V2.3, ByteParasite,
     Freedom, initial_cli, NoGuru, Disk.info, LAMER8-File, Mem-Check,
     Golden Rider, Disktroyer V1.0, Chaos-Master, NoVi,

     - Removes file viruses if you want it to.
       A requester appears, with Continue (weiter) option.  It's necessary
     most of the time to remove the 1st line in the Startup-Sequence.

           NoVi: Tries first to rename with .fastdir, $a0.  Chance of the
                 startup-s is then to ignore.  If the file is not found,
                 the virus program has to re-boot, (then you have to change
                 the startup-sequence.

           Chaos-Master = dir and disk.info is removed, then copy the
                          original dir command from Org.WB

           Disktroyer V1.0:
              Is deleted, please check your startup-sequence.
           Golden Rider:
              VT tries to remove the linkpart.  Note that as the link virus
              possibly had infected itself several times, you have to run
              the removal again.
              Memcheck is deleted. Please delete 1st line in startup-
              sequence with ED!!

           LAMER8-File:    (links to the VirusX virus killer)
              Is deleted, please copy a new one to the disk.

           Disk.info:
              Is deleted, please copy a new one to the disk

            NoGuru:
              Is deleted, more work is not necessary

            initial_cli:    (AMIGAKNIGHTSVIRUS)
              Is deleted, Please delete 1st line in startup-sequence with
              ED!!

            Freedom:
              Is deleted

            JEFF BUTONIC V3.10:

              Is deleted, Please delete 1st line in startup-sequence with
              ED!!

            ByteParasite:
              Is deleted

            VirusBlaster V2.3:
              Is deleted

            PP-Bomb:
              Is deleted (Please get Powerpacker 3.0b)

            Gotcha Lamer:
              Is deleted (Please copy back dir, run, cd or execute from
              Org.WB)

            Lamer-LoadWB:
              Is deleted (Please copy back the LoadWB command from WB)

            icon.library-BlueBox-Virus:
              Is deleted (Please copy back icon.library from the original
              WB disk)

            colour-Filevirus:
              Is deleted (no changes in Startup-Sequence needed)

            IRAK-DataBlock:
              Decodes the Datablock and writes it back

            SADDAM:
              Deletes Disk-Validator (no changes in Startup-Sequence
              needed)

            BRET HAWNES:
              Deletes $C0A0E0A0C0 in Root.
              Remove first line in startup-sequence using Ed

            EM-Wurm:
              Deletes $A0 in c.
              Deletes found damaged file when wanted
            Disaster Master:
              Deletes cls.

            Revenge Lamer 1 u. 2 :
              Deletes A0A0A0A0A0

            Jeff-Butonic 1 u. 2 :
              Deletes invisible file or Alias-Name (e.g. Jeff)

            TimeBomb V0.9:
              Deletes .info in c and when available pic.xx in Root

            TimeBomber:
              Deletes virustest and when available VIRUSTEST.DATA

            Return of the Lamer:
              Deletes Disk-Validator (no changes in Startup-Sequence
              needed)

            BGS9 1+2 and Terrorists:
              First tries Rename with invisible File
              (no changes in Startup-Sequence needed then)

              when the invisible file isn't found, Vt asks to delete the
              virus

            Travelling Jack
              Deletes, when wanted, file made by Jack (VIRUS.xy)

     - When requested removes CCCP, IRQ1+2, The Smily Cancer1+2, Travelling
     Jack1+2 or Xeno from a file.

      (NOT  100% Certain that the file will start!!!  If the attempt to
     remove fails, please send me the original infected file.  Thanks!)

      IF removal fails, copy file to an empty, formatted disk and try again
     or to prevent fragmentation in memory (can be a cause of failure!)
     Cold-reset or switch off the computer for a few minutes

       Important:
       After repair, the program restarts to check whether the file was
     written correctly.  If the filename is still orange, please inform me!
       or:
       You have a file that is infected more than once.  I have an IRQ2 or
     Smily infected file with six links and a Smily file with four links.
       You should see the filelength decrease using the filerequester and
     you should keep removing the links until no virus is on it any more.

       Startup-S DF0/Devs
       ------------------

     - shows 1KB of the startup-sequence when available, please switch
     display using BLK0/1-Gadget, useful for quick search for $A0 chars
     etc.

       in 1st line
         Note: $A0 - is not $0A !!

     - does NOT show startupII or startup-sequence.hd
       (Possible though, using filerequester)

       Sp -> File -> Sp    = FileRequester
       -----------------------------------

        Status:  Used for error messages

        Ende:   end filerequester

        Parent: Go back one drawer

       Drive gadgets:  load dir
           Errors occur when there are more than 250!!! entries in any of
           the directories.  Should be enough even with DH0:c anyway.


       Pfad:
        Shows drives and possible subdirectories.
        String gadget with max. 255 chars and UnDo-Buffer. You can also
        change using right Amiga key + Q (when you haven't quit the
        requester yet).  Using the cursor keys you can scroll left and
        right.  When, for example, you press return after DH0: Assembler,
        the program tries to show the directory called 'Assembler' of DH0:.
        Please don't forget the "/" chars when using complex
        subdirectories.
        BUT: The last char may not be "/". It's easier to select with the
        mouse than the keyboard.  (subdirectories are marked orange)

       Datei:
        The chosen file is shown.
        String gadget with UnDo-Buffer.

       DateiRe:
        String gadget with Undo-Buffer
        Rename.  Include -entire- directory in name to rename
         (e.g. DF0:C/Copy)

       Load:
        Merges contents of 'Pfad' + when needed '/' + contents of 'Datei',
        and then tries to load and show 1024 bytes of the file. Use
        Block0/1 to change display. Select 'Datei' (file) using mouse or
        keyboard.
        This option was made to show saved bootblocks, but works with other
        files too, e.g. when you want to see StartupII.

       Save:
        Merges contents of 'Pfad' + when needed '/' + contents of 'Datei',
        and then tries to save 1024 bytes of the buffer to the file.
        Select 'Datei' (file) using mouse or keyboard. When you don't edit
        filename (Datei), the old file you chose will be overwritten.
        Useful only for saving bootblocks, because it always saves 1024
        bytes.

       Delete:
        Merges contents of 'Pfad' + when needed '/' + contents of 'Datei',
        and then tries to delete the file. (sets protection bits when
        necessary).
        Select 'Datei' (file) using mouse or keyboard.
        Note: I know three ways to protect a file from deleting using DOS
        routines. Deleting is then only possible using a Disk-monitor.

       Rename:
        Merges contents of 'Pfad' + when needed '/' + contents of 'Datei'
        together = Altname (Oldname).
        Takes contents of DateiRe = Neuname (Newname) and tries a rename.
        In the DateiRe-Stringgadget you must state the complete 'Pfad'
        (Path in English) and the Datei-name.
        E.g. DH0:aa/ddddd/Nameneu
        A rename between different drives is  NOT  supported by AmigaDOS.
        So this will not work :
                 Rename df0:aa/dddd/Altname df1:aa/dddd/Neuname
                 when it's different drives

       But this will :
                 Rename df0:aa/dddd/Altname df0: xxx/yyy/Neuname
       FileTest:
        When activating FileTest there is a test for... in order:
           - Test for Crunchers
           - Test for Linkvirus
           - Test for BB-Virus
           Names are shown in Status order, or "Unknown"

           Note: LZ-Virus, IRAK and BootGirl-bild can be "known" here as
                  "unknown".
           Because another routine is necessary here.

       Protect: Deletes or sets Protection-Bit 0 - 7 in a Fileheader or
                Subdir.  Note: Bit 7 (Hidden) is also from KS2.0.

       File=BB?:
        Checks if file is a saved bootblock.  If yes, what type of
        bootblock.

       Devs=Device-Requester
       =====================

       Includes up to 30 mounted devices. (NO assign, NO RAW, AUX etc.)
       After 30 devices the search is ended.
       Ende  - cancel (without select)
       select using left mouse-button
       Scroll using PropGadget
       The "simple" Commodore-RAM-Disk is not recognized.

       What the program can't do
       -------------------------

     - not memory resistent
     - please don't set P-Bit - causes Guru !!!!
     - remove virus names from Startup-Sequence
       (Please use your text editor, TxED, QED etc.)

       Only viruses that I have reassembled are deleted without a reset.
       Unfortunately the virus programs get better all the time (more and
     more lists and pointers changed), so that the original situation can't
     be restored.
       Because of this, some viruses that I have reassembled, also need a
     cold reset.
       Everything else is too dangerous for me!! (forgotten pointer, Task
     not recognized etc.)

       KNOWN PROBLEMS:
       ===============

     - Problems with Mach2.4, please use MachII V2.6 (e.g. Fish254)
       and please read Mach2.6Doc !!
       Tip from J.K. for Mach2.4 :
              Move mouse-pointer when Vt starts.
     - or MachIII (e.g. Fish378)

     - or MachIII.1 (e.g. Fish471)

     - Problems using MyMenu, please try PAMR (Fish 419)
       MyMenu is not programmed 'neat'. (not 100% Commodore compatible)

     - VT sees a 68030 as a 68020 under Kick1.3.  Under Kick2.0 the 68030
     is ALWAYS recognized correctly.  The error is in Kick1.3 (also
     documented in the books by now), because Bit 0 and 1 are not set, but
     bit 2 is.  Note: SetCPU (also without parameters) sets bit 2.

     - Memory values from VT and ex. Mach III are different.  Please give
     the Mach-III-value 3 Zeros (000), and divide then with 1024 (= 1kb).
     You then get the VT value.  Consequently VT calculates correctly.
     This happened only together with huge memory value!

     - Please send me other bug reports

     - I'm always glad to get suggestions!
       (Please send texts on disk and mark with "an Heiner") ('to Heiner')
       (but please not crunched, but plain ASCII, According to Murphy's Law
     I won't have your text editor or cruncher!)


       T H A N K S !!   T H A N K S !!

       Please mark disk with "Viren" ('viruses')!!!
       Don't forget to mention your address and telephone number, a little
     note wouldn't be bad.
       (Both not necessary, only the VIRUS counts)
       Note:  I only search for new viruses and crunchers!! the disk
              will be formatted after copying the virus!.
              Address and Tel.Nr. is thrown in the trashcan after analysis!
              (no questions needed then)
                           I always keep my promise!!

       Heiner Schneegold
       Am Steinert 8
       8701 Eibelstadt
       (Germany)

       Tel: 09303/8369
       (19.00 - 20.00)

       see you soon !!
       Heiner
