Article 85381 of comp.sys.amiga.misc:
Lines: 71
Newsgroups: comp.sys.amiga.misc,z-netz.rechner.amiga.viren,de.comp.sys.amiga.misc
Message-ID: <wF7P8MD409asz2@ldb-ms.ldb.han.de>
From: M.SCHMALL@LDB.han.de (Markus Schmall)
Path: news.PEAK.ORG!engr.orst.edu!reuter.cse.ogi.edu!uwm.edu!hookup!news.mathworks.com!zombie.ncsc.mil!news.duke.edu!godot.cc.duq.edu!newsfeed.pitt.edu!uunet!in1.uu.net!news.gun.de!linteuto.teuto.de!bi-node.zerberus.de!bionic.zerberus.de!ldb.han.de!M.SCHMALL
Organization: TRSi - VirusWorkshop
Subject: Mount-972 Linkvirus
Date: Thu, 27 Jul 1995 14:42:52 +0200
X-Mailer: MicroDot 1.11beta12 [REGISTERED 000409]
X-Gateway: ZCONNECT UB bi-node.zerberus.de [UNIX/Connect v0.73]
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
X-Z-Post: von Graevemeyerweg 25, 30539 Hannover
X-Z-Telefon: 0511-514944 (Germany)


 Hi ! A new linkvirus appeared in the last days. Here a first quick analyse:
 Hi ! Ein neuer Linkvirus ist in den letzten Tagen erschienen. Hier eine
 erste Analyse:


  Mount-972 Linkvirus:
  --------------------

  Kickstart: 2.04 and higher (V37+)
  Patched vectors: several vectors in the device basis (quite tricky)
  Length: 972 bytes
  Processors: MC68000-MC68040 (68060 not tested)
  Discoverd: Jul`95
  Linking method: Infiltrator

  This is one  of the most  complicated viruses on AMIGA, which I have
  ever seen. It`s coded very well and at  many constructs even  a very
  professional resourcing system from a friend has problems with  this
  nasty virus. It is crypted  using  a "normal" logical  (exclusiv or)
  routine,  only  the  cryptword changes  (depending on $dff006).  The
  virus itself searches from the start of the file on for a "$4eae" to
  replace it with a pc relative jsr (-> as a result the first hunk can
  have only wordsize) and links its code at the end of the first hunk.
  The linking method do not contain  any other tricks, a simple  hunk-
  copying is enough to remove it  from the infected file  (+ rewriting
  the original longword).

  The virus checks for Kickstart V37+ and does not start, if the check
  wasn`t succesfull. If the check was succesfull, then the Caches will
  be cleared.

  The virus detects its existence in  memory by testing the  lastalert
  entry in the execbase. If -$17 is the number of the  lastalert, then
  it will not activate.
  
  The virus allocates 972 bytes chipmemory to secure, that it will  be
  not overwritten.

  This virus  uses a  lot of  special commands, which are a little bit
  crazy and probably should irritate  the resource-programms. I  could
  not  resource some  parts of  the virus 100%, but the  VirusWorkshop
  recognition routine for the memory  will disable all  the  spreading
  functions.

  The patches from the virus will be done very clever and I must admit
  that I have only once seen a comparable routine so far on AMIGA.

  If you start a normal vectorchecker, no modification is visible. The
  name of the virus is based on the lengthincrease and because a  text
  saying "c/mount".

  The virus seems to be not resetproof.


                                 
  Gruss

          Markus


                                 ___________________  __________________
        Markus Schmall           \_____ \___  \___  \/  __ \  \   _____/\
 Programmer of VirusWorkshop      \\____   /  /  / _/___  \/  /\ ____/\\/
   Tel.:+49(0)511/514944            \\___ /  /     /\__/  /  / /___/\\/
 E-Mail:M.Schmall@LDB.han.de          \__/__/__/__/\_____/__/ /\___\/
                                         \\_\\_\\_\/\____\\_\/  NL


 P.S.: (C) by Markus Schmall
       It`s not allowed to use this analyse in any SHI publication !


