
              _____          _________________________________
             /    /\        /                                 \
            /    / /       /    ___________________________    \
           /    / /       /    / _________________________/\    \
          /    / /       /    /_/___________      _____   \ \    \
         /    / /       /                   \    /\    \   \ \    \
        /    / /       /_________________    \   \ \    \   \ \    \
       /    / /        \________________/\    \   \ \    \   \ \    \
      /    /_/__________________________\_\    \   \ \    \___\/     \
     /                                          \   \ \              /
    /____________________________________________\   \ \____________/
    \____________________________________________/    \/___________/

                            P R E S E N T


                           N U K E  1 . 5 a


                       WRITTEN BY DAVE DE PAUW

                         aka SHAGRATT OF LSD

                        RELEASE DATE 21/02/92



                     NUKE 1.5a FULL DOCUMENTATION



                          *** IMPORTANT ***

Due to changes in the KS2.04 I strongly suggest that you stop using
any previous versions of NUKE!  This version has been thoroughly
tested on many different Amiga`s for one month prior to its release.
It is greatly enhanced and fixed for KS2.04 (and I think for future
kickstarts).


                         *** INTRODUCTION ***

Welcome to a major re-code of NUKE, the worlds smallest viruskiller,
which recognises and fixes literally hundreds of viruses.  It was
origianally designed to destroy and fix the Saddam virus but now
enhanced to cover other link-viruses and all boot-viruses etc!
Please read ALL of this documentation.


                       *** ABOUT SADDAM VIRUS ***

I first read about the Saddam virus in Zine #9 and realised we have had
disks infected with this.  I've worked out what Saddam is and does, here
are my findings (note that these may not be complete).

First, Saddam changes the "beginio" and "close" of the
"trackdisk.device", and "coldcapture" and "vertb" in "execbase".  Then
it creates an "l" directory (if you don't already have one) and puts
itself into it, disguised as the disk-validator, (it's even the same
length, if you had a real disk-validator you don't now!).  It alters
data blocks to "IRAK" blocks and EORs the rest of the data within the
block with the block number.  

Next it unvalidates your disk, and AmigaDOS `tricks' itself into believing
the disk is validated, yes the `stupid` hardware is being exploited (The 
"bitmap page" is now set to 0).  When you insert an infected disk into any 
drive (you don't need to boot from an infected disk to infect the system), 
Saddam is immediatly activated (as one of the first priorities of dos 
library is to validate your disk).

Each time you access a file from disk, Saddam modifies the data blocks
in this file.  This causes no immidate problems, providing Saddam is
always present.  But if it's not in the system your disk has read
errors.

Saddam also totally destroys your disks data, but I can't find a pattern 
to when this happerns (but it is quite quickly!).

It doesn't appear to infect hard drives, but I advise caution!

Saddam is the cleverest virus I have seen so far, but its unfortunate
that it is used for destructive purposes.


                  *** ABOUT LIBERATOR FILE-VIRUS ***

This was new to version 1.4b, many thanks go to Greg Hughes of
Birmingham for sending me this. Here is some info about it. I have
only spent a couple of hours on it as this is the time it took me to
produce a killer for it.

Liberator can only be executed from a booted disk, it copies itself
from sys: and does NOT set any of the usual virus execbase-vectors,
instead it enters memory for a couple of seconds, and spreads to all
write enabled drives.

It adds an extra first line to the startup-sequence "memcheck s", and
claims to be Slipstreams Memcheck 8.1 by Marc.  After a few software
resets I am told it prints up a message, (but I never got one, Hard-
drive only perhaps?) then prevents DOS access to the infected disk.

It claims to be an anti-anti-virus! In Liberator are these following
words ZeroVirus, VirusExpert, PVL, ZeroVirus, VirusChecker, MVK 2.1,
BLVC, Berserker and Berserker 5.0. from this I assume it looks for the
filenames on disk (or in memory?) and kills them.   Also inside
Liberator are the words January to December and all the days of the
week. I've no idea what they are for (yet!) maybe something to do with
a battery backed clock?  If you type "memcheck" from the CLI on an
infected disk you will get a 'Memcheck' screen. NOTE: IT IS A ROGUE
VERSION OF MEMCHECK! If you find it, destroy it - it does not check
anything.  Liberator is packed with Powerpacker 3.2 my version is 6492
bytes long.

THIS IS WHAT THE LIBERATOR SCREEN LOOKS LIKE;


           <<<<<<<< MemCheck v8.1 - August 1991 >>>>>>>>

     THIS PROGRAM IN THE STARTUP-SEQUENCE WILL KILL ALL VIRUSES
                                                   ^^^^^

                   <<CODED BY MARC OF SLIPSTREAM>>


          MEMORY CLEAR ------ NO VIRUS ------ MEMORY CLEAR


 DISK-VALIDATORS CLEAN ------ NO VIRUS ------ DISK-VALIDATORS CLEAN




I have also found a bug in Liberator; if you type "df1:memcheck" (ie.
a drive it has not been booted from) it adds "memcheck s" to the
startup-sequrence, but doesn't copy memcheck to the disk!


                *** ABOUT BGS9 (ALSO CALLED TTV1) ***

After this two part link-virus enters memory, when booting another
disk, it moves the first file in your s/startup-sequence into the devs
directory if you have one otherwise it puts in into the root, renaming
it as some control codes, which appears as a unnamed file.  It then
copies the BGS9 virus into the original directory of your renamed file
and gives it the filename of the original file.  When this virus goes
off it does no harm as far as I know.  When the link-BGS9 finds the
BGS9 bootblock version, the virus goes off printing a message on the 
screen starting with the words PIRACY IS A CRIME.


                             *** CCCP ***

This is another two part virus, I haven't managed to get this virus to
go off, as I seem to be quite fast coding a cure for viruses these
days - all I got it to do was spread.  After the virus has entered
memory, on booting an infected disk it creates a new bootblock and
adds itself as a hunk to the first file in the s/startup-sequence, I
think this was written to cause a headache for viruskiller writers as
if you kill only one part of the virus in memory or on disk, the other
part of the virus replaces the erased section. The solution is to kill
both parts simultaneously.  Once NUKE! has repaired an infected disk,
it is "inocculated" against further infection from the file-hunk virus
although the bootblock virus can still re-infect the disk.


           *** REVENGE OF THE LAMER EXTERMINATOR (ROLE) ***

This is the original disk-vaildator virus that Saddam is based upon.
The encription used in this virus is exactly the same as in Saddam, so
I suspect it is either coded by the same person, or Saddam is re-
sourced and produced from this.  This is very similar in operation to
Saddam, after inserting an infected disk, ROLE enters memory and
spreads in the same way as Saddam (see earlier).  When ROLE goes off
it writes "LAMER" through random tracks, destroying any information
PERMENANTLY, causing read errors.  Unlike Saddam, this damage cannot
be repaired, but the virus can still be destroyed of course!


                     *** SADDAM MUTANT STRAIN ***

I got a phonecall one day from a friend telling me about a problem he
had, NUKE! couldn't repair the damage caused by Saddam.  I was sent his
disk and immediately and found the cause, it was a MUTANT strain of Saddam,
called LAME!  I have updated my repair routine and it will now handle ALL
mutants of Saddam, even those not in existence yet!


                      *** BOOTBLOCK VIRUSES ***

There are hundreds of bootblock viruses in existance, and new ones
appear every month.  Often these are mutants of earlier viruses.
NUKE! kills ALL bootblock viruses in existance, and ALL that will be
created, due to my intelligant bootblock-virus identification test and
repair routine.  I am not going to list all these viruses as there are
just so many, and a list would be meaningless.


                    *** ROGUE DISK VALIDATORS ***

If NUKE! finds a non-standard disk validator on your disk it will give
you the optior of replacing it.  I strongly recommend you do this, as
to the best of my knowledge there are no non-standard disk-validators
with any use whatsoever.  NUKE! recognises disk validators from both
1.2 and 1.3 KS.  (If you have doubts copy the disk you are to repair first!)


                      *** NEWS FOR KS2.04 USERS ***

I'm sure you're aware that you have some problems with software
compatability and that is bad news.  The good news is over 90% of
bootblock viruses will do nothing on your machine (at worst just guru)
The Saddam Hussain and Revenge Of The Lamer Exterminator (R.O.L.E.)
viruses have no effect on KS>2.0 and cannot enter memory, although you
will get read/write errors (use NUKE to fix these!).  However some KS2.04
bootblock viruses are certain to appear in the near future.  But don't 
worry, NUKE! will kill all of these.  More KS2.04 news as it happens.


                  *** KILLING BOOTBLOCK VIRUSES ***

This is the recommended procedure for killing a bootblock virus
(assuming NUKE has found one):

Firstly check the Bootblock danger rating, which is carried out during
the "Bootblock scan".  What it does is check the bootblock to see if
it does anything that a bootblock shouldn't do, or for any encription
etc.  If NUKE! warns you that it's a virus, I strongly recommend you 
install on it (use one of the options to install a bootblock, I recommend 
Mini-Nuke or No-Saddam!)

If you want to look further, select display bootblock, look for any
messages, virus often have messages in them telling you they are a
virus (such as REVENGE BOOTLOADER and BYTE BANDIT).  Some viruses
even contain messages such as "This is not a virus" or "Install me
and you've wasted £25", however, these messages can also be genuine.  
It is recommended to backup the bootblock before installing if you have
any doubts.

A good way of determining if the bootblock is a virus is to select
"kill the virus in memory (hard reset)".  If when rebooting NUKE!
finds a virus again you can be almost certain it is a bootblock-virus,
unless of course you have a link-virus on your disk, or some STRANGE
hardware (such as some Amiga 2000 hard disk controllers!).


                     *** KILLING LINK VIRUSES ***

This is very simple, just follow on-screen instructions and NUKE! will
do the rest.  Your Amiga may reset afterwards, and occasionally a
repaired disk may need validating, but the system will do this for
you.


                *** MEMORY RESIDENT OPTION (SLEEP) ***

I have been asked to include this option by many people (Hello Mr. Big
of Anarchy!) so here it is.  You can either use the sleep option on the
menu or start NUKE! with the command "NUKE S".  NUKE! will now check
your drives and then "go to sleep" until you insert another disk into
any drive.  NUKE! will then reappear, check all disks and go back to
sleep.  There is no need to "run NUKE" as it auto runbacks itself!

NOTE: When you have used the sleep option in NUKE! you can re-call
NUKE at any time by pressing <ALT> and <HELP> simultaneously.

I have only found one piece of "system-friendly" software which is
incompatable with the sleep option -Protracker- although I am told
there is an update of this due soon which may cure the problem!  If you
find any IMPORTANT software that isn't compatable with the sleep
option please tell me! (I`m working on this!)

As long as NUKE! is in memory, Saddam and rOLE cannot enter memory!


                          *** QUICK EXIT ***

If you type "NUKE Q" all disks in all drives and memory are checked.
If no virus is found NUKE! will exit automatically.  If you wish to
cancel the quick exit simply hold down a <SHIFT> key while NUKE! is
loading.


                       *** LEARN BOOTBLOCK ***

NUKE! recognises over 100 non-virus bootblocks/utility boots. If you find
a bootblock you wish to use, but NUKE! doesn't currently recognise it,
you can now add it in the form of a small brainfile.  Simply click on
"Learn Bootblock" option when NUKE! says it's a non-standard
bootblock.  You cannot learn any bootblock which NUKE! suspects is a
virus.  The brainfile is always optional and is stored in the "s"
directory.  Each bootblock stored only uses 4 bytes of data.  If you
run NUKE! and have a brainfile on disk but don't want to use it then
hold down the <ALT> key while loading NUKE!


                         *** BACK TO CLI ***

If you need to flip back to the CLI at any time while using NUKE! then
press <ALT> and <HELP> at any time, and the same keys to return to
NUKE!


                      *** KEYBOARD OPERATION ***

For those who like to use the keyboard instead of the mouse, I have
now included this feature.  Just use the cursor keys and <RETURN>,
<ENTER> or <SPACE BAR> to select.


                   *** MINI-NUKE! BOOT PROTECTOR ***

Mini-Nuke! is a bootblock protector, it checks all the execbase
vectors that viruses use, and tell you if they have been altered.  It
is fully KS 1.2, 1.3 and 2.04 compatable.  Mini-Nuke! also spots the 
Saddam virus and BGS9 (aka TTV1) and informs you if your machine is 
infected.  It also detects if you are using `RAD' (ramdrive.device) and
alerts you to the fact it has been found but ignores it (RAD uses the
same pointers as viruses).

    Look out for an LSD Utility Boot KS2.0 compatable in future versions.


               *** FAST FILING SYSTEM FLOPPY DISKS ***

As Fast filing system disks have a differant (better!) structure,
NUKE! treats them as non-dos disks.


                        *** OTHER FEATURES ***

o Nuke informs you if your disk is write enabled.

o Memory usage 35736 Chip and 27504 public. 

o Nuke is under 14k in length.

o Nuke is written in 100% assembler and needs NO libraries, devices etc.


                        *** SHAREWARE NOTICE! ***

NUKE! is Shareware. If you like this program and use it regually I ask
for a minimum donation of £5.00.  For this donation you get the next
update posted to you (or the current version if you don't have it) on
the day of release - with full documentation included and some of my other
utils - and of course my thanks!  If you are sending currency from outside
the UK please remember I charged for turning this into UK sterling, (a $10
New Zealand note is worth £2.75 and £2.50 of this is taken for exchanging it!)


Write to:

Shagratt,
2 South Parade,
Gainsborough,
Lincs,
DN21 1UQ.
England

If you send a cheque, PLEASE LEAVE THE NAME BLANK.  Believe it or not, I DO
NOT have a bank account in the name of Shagratt!  Thanks!


                      *** PD LIBRARIES NOTE ***

You may stock NUKE only if you include this document file with it and
if you do not charge more than £2.00 for the disk this is on.  NUKE!
CLEARLY STATES IT IS COPYRIGHT.  LEGAL ACTION will be considered
against any PD company found to be distributing the program without
the complete documentation IN IT'S ENTIRETY.  Ammendments or additions
to this documentation are strictly prohibited.  Ignorance will not be
considered to be an excuse in this matter.

If you write to me for an upgrade then send at least one disk and
return postage or you will not get a reply.  I am developing NUKE! for
the use of everyone, but I am not a charity!


               *** MAGAZINE COVER DISKS PLEASE NOTE ***

If you wish to include NUKE! on your magazine coverdisk, I INSIST you
contact me first.  The reason for this is I will ensure you get the
latest version, with the full documentation.  LEGAL ACTION will be
considered against any publishing company producing a magazine with a
coverdisk that has a version of NUKE! on it that is not accompanied by
the full documentation IN IT's ENTIRETY.  Ignorance will not be
considered to be an excuse in this matter.  I will answer any magazine
related letters immediately.

A monthly Amiga magazine (that shall remain nameless) recently
included NUKE! on its coverdisk, but used an old version, didn't
include the docs (which are very important), and the address included
in the program is no longer a contact address for me!  If I was
contacted first this STUPID mistake would have been avoided.


                    *** HELPING TO IMPROVE NUKE! ***

I already have hundreds of viruses and I am looking for copies of all
link viruses (but not bootblock - unless they are anything special!),
both new and old.  The reason for this is I wish to make NUKE! check
and repair disks infected with these.  So if you have any please send
them to me.  All disks will, of course, be returned.

I already have many other link-viruses in my collection to impliment but I
am particually after the following link-viruses:

Amiga Knights virus
Freedom
LameBlame
No-Guru 2.0

I would also like to hear from virus-killer writers and even virus writers,
although I doubt any will contact me (but one already has)!


                           *** BUG REPORTS ***

NUKE! has been thoroughly tested by myself and other LSD members on
many different types of Amiga, with ALL of the viruses we have in
storage, and under many different conditions.  This process has taken
about a month to carry out (twice as long as with previous versions).
As usual, we have also tested it with a variety of standard non-
infected disks.


LEGAL DISCLAIMER: I, nor any other member of LSD, can be held responsible
for damage or loss of property or loss of data that results from the
use of this program.  Nor can I be blamed for the world disk shortage
or invasion by killer lard-eating wasps from outer space.

If you have any problems with NUKE! let me know, but PLEASE make sure
it is the CURRENT version, I had a lot of mail telling me about I bug
in version 1.2a TWO MONTHS after I upgraded it!  (Telling me "it
doesn't work on my A500" doesn't help me either. Descriptions please!)


                         *** IMPORTANT NOTE ***

In the February 1992 issue of "PUBLIC DOMAIN" magazine an article
appeared in the News section titled "Nuke disarmed".  The article
stated that the Public Domain Standards for Distribution through its
involvement with the UK Virus Research Centre claimed they had
discovered two "bugs" in the 1.4b version of NUKE!.  They alleged that
NUKE! incorrectly identified standard DOS disks as being infected with
the Saddam virus, and also claimed that NUKE! did not prevent the the
Saddam virus from entering the Amiga's memory when NUKE! was just
checking disks.

In order to check their claims we tested version 1.4b during the same
period of time that we tested this version (1.5a) and we can assure
users of 1.4b that:

NUKE! DOES NOT IDENTIFY STANDARD DOS DISKS AS BEING INFECTED WITH SADDAM!
      ŻŻŻŻŻŻŻŻ

The second so-called "bug" is a farce.  NUKE! 1.4b DOES prevent the
Saddam virus (in fact ANY virus) from entering the while it is
checking disks!  It does not, however, prevent any disk-validator virus 
from entering the Amiga's memory while it is in menu mode awaiting 
instruction from the user.  It will only check for a virus in memory 
during the following conditions:

(i)  Immediately on loading up NUKE!
(ii) During ANY of the SCAN DISK options.

Please note that NUKE! 1.4b and previous versions are obviously not
memory resident, therefore they cannot prevent viruses from entering
memory while NUKE! is not active.  As you are aware, NUKE! 1.5a has the
option of memory residence and CONTINUOUSLY checks the memory for
viruses the whole time it is active.  Many people have contacted me
regarding the article, genuinely suprised at the claims.  No-one that I
have spoken to has voiced any complaints along the lines of the
problems described in the article.  Instead I have recieved letters of
thanks (and contribuitions) from people who have had their disks
infected with Saddam (and ROLE) that NUKE! has discovered, killed and
repaired.

I have not, however, recieved any correspondence regarding the alleged
bugs from either the Public Domain Standards for Distribution OR the
self-proclaimed UK Virus Research Centre (better known as the
"Goldstar Computers" PD company). I am very suprised that neither
organisation has attempted to contact me so that I may discuss any
problems that they may or may not have had with the 1.4b version of
NUKE!.  In fact, my last correspondence with UKVRC/Goldstar was when
they contacted me requesting a copy of the Saddam virus - three months
after Saddam had been discovered and after the third version of NUKE!
had been released!  They still have NOT answered my question which I
put to them on several occasions:

     ---Exactly WHAT research have they done in to Amiga viruses?---
        ---------------------------------------------------------

The ball, as they say, is in your court, UK VRC/Goldstar.


                       *** FUTURE EXPANSION ***

I have more plans for the expansion of NUKE!, to kill more link-
viruses and further features.  I have made the software "think" ahead
in every concievable way, to spot and repair mutants that could be
created, so this should help keep NUKE! up to date.  I am also consideing
making NUKE! totally intuition friendly, any comments on this?


                         *** THE END BIT ***

Heres a quick question for all virus writers:- Who gets more glory,
the guy who writes the virus, or the guy who writes the virus-killer.
Who's wasting the most time?

                Greetings to all our friends everywhere!

My thanks go to:

MARKUS SCHMALL - for help with the Requesters!
PAZZA - for helping me collect the bootblocks included in NUKE!
MAXIMAN - for his varied (legal) support!
GREG HUGHES - Good luck with Trojan-Trauma!
Cyborg/Aero - Good point!
G. Kennedy  - I will reply soon (honest)
Monty Python - Get more memory!
Fugitive - Thanx for your help!
Baser Evil - Cool letting us leech!
Skavenger - "The Pool`s" getting BIG!
Morsecode - Kewl!
Matrix/Plague - Good luck with the demo!
Fish - For the ascii logo!

and to...
Brainstorm - for "Bootshop" (nice protection!)
D-tect - for "Master devpac"
and the rest of LSD for their support!
...and to all our friends


                    *** RECOGNISED BOOTBLOCKS ***


NOTE: There appear to be more than one version of some utility boots,
such as OMNI-BOOT 3.2, INTERFERON 1, etc.


        Normal Installed disk - (8 types)

        Lsd - Mini-Nuke
        Lsd - NoSaddam
        Lsd - LSD 1.1
        Lsd - Vectorcheck 2.0 (by marl)

        Magnetic Fields - Interferon
        Magnetic Fields - Interferon 2

        Inner City - VirusKill 3.4
        Archaos - Virus Slayer 3.12
        Archaos - Virus Slayer 3.13
        Magnetic Fields - Interferion Pro
        Digital - Utility Boot 4.9
        Digital - Utility Boot 3.02

        Crystal - Utility Boot 1.0
        Scoopex - Utility Boot 1.0
        Quartex - Utility Boot 1.0
        Quartex - Utility Boot 2.0 (almost KS 2.04 compatable!)
        Slipstream - Marc of Slipstream utility boot 2.1
        Slipstream - Marc of Slipstream utility boot 3.0
        Slipstream - Marc of Slipstream utility boot 4.0
        Slipstream - Marc of Slipstream utility boot 5.0
        Slipstream - Marc of Slipstream utility boot 6.0
        Slipstream - Marc of Slipstream utility boot 6.1
        Slipstream - Marc of Slipstream utility boot 7.0

        Anarchy - Omniboot 3.2
        Anarchy - Omniboot 5.1
        Anarchy - Anarchy boot 1.1
        Anarchy - Anarchy boot 2.0

        Xcopy - Xcopy (3 types)

        Quartex - No external drives (3 types)

        Scorpion developments - Utility boot 1.0
        Scorpion developments - Utility boot 1.1

        The Special Brothers - Boot Protector
        The Special Brothers - Boot Protector

        CCS - Boot 2.0 (2 Types)
        CCS - Boot 3.0

        VCC - Bootmem
        VCC - Boot 3.2

        Mahoney & Kaktus - Hallon Boot 1.4
        Cave - Stoneboot 1.06
        Seek & Destroy Memcheck
        The Punishers - Proboot 1.0
        Cytax - Powerboot 1.2
        Mirage - Noboot
        Datel - Action Replay 2 boot protector
        Hypnosis - Boot
        Psuedo ops - Virus Killer 2.1
        Tristar - Virus Killer
        Memory Allocator 1.2
        Memory Allocator 1.3
        Fastmem boot Allocator
        Scoopex - Utillity Boot 1.3
        Aspect - Aspect boot 1.0
        Adept - Option boot
        Santurary - Boot
        Random Access - Virus Killer 2.1
        Devware - Antivirus (1988)
        Dietmar noll - No Virus
        Sabaudian - Boot 1.0
        Hyperboot 2.82
        Blizzard Proector 1.0
        Dawn - Quazar boot
        Megaboot 1.3
        Nofastmem
        NTSC Warning
        Pleasure boot 1.3+
        Tristar -  Virus Killer 1.1
        Tetracopy - Formated disk
        Copper boot
        Rebels - Boot
        Razor 1911 - Boot
        Amaze - Protector
        Wizzcat - Wizzboot 1.0
        Messinger
        Bacteria - Bacboot (Saddam Protector)
        Destiny - Boot Protector

end.
