home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
The Epic Collection
/
Epic Collection, The (Epic Marketing)(1996).iso
/
lsdtools
/
lsd113.dms
/
lsd113.adf
/
docs
/
FuckVirus.DOC.pp
/
FuckVirus.DOC
Wrap
Text File
|
1990-09-13
|
2KB
|
43 lines
What is Fuck Virus?
-------------------
The fuck virus is the latest and the worst amiga virus ever programmed.
Actually it's distributed into an archieve called 'MCHECK.LHA' that
contains a program called ModemChecker that pretends to be a modem checker
but really it's a Trojan Horse that install the virus into yuor system
partition device.
ModemChecker give ok results to any test of the modem also if the modem does
not exists! Also ModemChecker CLOSE any snoopdos task open to prevent the
user to understand what it really does.
The virus is installed by modemchecker into the LoadWB command, then at the
next time you boot the system also the virus will be executed.
The new LoadWB, if infected, will be 3600 bytes long instead of the usual 1100
bytes. The 'LoadWB' that contains the virus is the 2.1 version, so the virus
isn't danger for any machine with 1.2 or 1.3. Your startup-sequence, if you
were infected, will halt at the execution of the infected loadwb: 'LoadWB
failed returncode xx...', the only thing you have to do is to replace it with
a 1.2 or 1.3 loadWB.
What does Fuck Virus do?
------------------------
Once installed at the boot Fuck Virus will wait patiently and if not IDCMP
message of any type is registered in #$7300 /50 of Seconds (Delay DOS routine)
equals of 10 minutes, it will proceed to low level format simultaneously any
physical device of your system filling casually the tracks with 'FUCKFUCKFUCK'
Even if you reset suddenly a great part of your datas will be compromised, so
it's better to install my antivirus into your startup.
You can check if FUCK virus is already in memory by watching with a program
like XOPER, ARTM or also Sysinfo, if there is a process called
'DiskDriver.proc' that the virus creates. In fact it doesn't do anything of
illegal and then it isn't detected by any virus checker (BootX, VirusZ, Virus
Checker...).
Keep your eyes open!
Gabriele Greco
Via Banchi 12
16030 Uscio (GE)
Tel. 0185/91068
FIDONET ADDRESS: 2:331/106.7