home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Kosovo Orphans' Appeal Charity CD
/
KosovoOrphansAppeal.iso
/
utilities
/
_vzap
/
docs
/
viruses
< prev
Wrap
Text File
|
1998-08-24
|
11KB
|
232 lines
VIRUSES
~~~~~~~
VZap v1.33 - This version currently copes with around 120 viruses and/or
variants of virus.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The following information is provided for reference and is aimed at the
more technical reader. It is by no means exhaustive and not all viruses
detected by !VZap are listed. However, if you think you've found a
new virus, or a strain of existing virus that you don't think !VZap
detects, please send it to me on a CLEARLY LABELLED disc, together with
the version number of !VZap you are using and a SAE.
I will then endeavour to modify and upgrade !VZap accordingly and send
you back your disc with the latest version of !VZap. Again, this service
is FREE OF CHARGE (on receipt of disc and SAE) to registered users.
N.B. Please do not try to disable and/or make viruses inoperative, as this
can lead to problems in reactivating them. Just send me them 'as they are',
on a clearly labelled disc.
In alphabetical order:-
All New ID virus (also known as 'Options' virus)
Seems similar to the icon virus in that !Boot files have a couple of
lines added to them to run a basic program called 'Options'. This
doesn't appear to have any side-effects other than taking up memory in
the computer and being unable to Quit, so seems reasonably harmless.
!VZap detects it's presence and deletes it.
ArchieVirus (also known as &FF8 virus) - possibly similar to 'Jester'
This affects files with the filetype 'Absolute' (hence FF8) by adding
code to the end and then calling this new code.
I haven't actually seen this virus so !VZap detects it but does not
destroy it. Please let me know if you locate it.
BBCEconet (affects 'absolute' files)
Adds virus code onto the end of 'absolute' filetypes and also installs
a modified 'BBCEconet' module.
BigFoot (detection added at v1.33)
A quite tricky one to track down because it generates a random filename
to save the virus code as, and amend the !Boot file.
It gives various error messages depending whether it's 25th Dec, 5th Nov,
4th Jul or 15th Mar.
Breakfast (various different variations)
This virus affects Absolute (&FF8) filetypes by adding around 6.5k onto
the end of the file, then changing the first few instructions to jump to
the virus code at the end. This is quite a nasty one to detect as the
virus code itself is EOR encoded, using random codes. It also scrambles
bytes &18 to &94 of the original file.
!VZap will detect and restore affected files to their original condition
by deleting the virus code and amending the beginning of the file to
the original instructions. This virus quite often hides in the Squeeze
utility (if you have it in your library directory)
Datadqm (also known as Vigay virus)
This virus seems to be linked to me for some reason, presumably because
being written in BASIC it can be modified easily by people. Therefore
there could be variations of this one around, some with my name added to
them - possibly by competitive virus killer authors.
It doesn't seem to be a virus as such, merely a desktop 'silly' capable of
replicating itself into any application without a !Boot file.
Note, it does not delete or change any data, so is harmless. The program
itself flickers the screen occasionally to make it look as though you have
a loose monitor connection. However, as it can be easily altered, other
variations could do other effects.
!VZap kills both the new !Boot file and the 'Datadqm' file.
IF ANY COMPANY SELLING A COMMERCIAL VIRUS KILLER CLAIMS THAT I HAVE WRITTEN
MANY VIRUSES THEY ARE LYING AND I WOULD LIKE TO BE INFORMED - BEFORE TAKING
LEGAL ACTION.
Die Hard (seems to be a variation on the Icon virus)
This virus adds a line to the !Boot file and saves itself under the
filename 'setup'.
It is capable of killing the Vprotect virus killer module and will
delete the 'Killer' virus killer. It seems incapable of deleting
!VZap.
!VZap restores the !Boot file and deletes the relevant virus program.
Extend (also known as MonitorRM, ColourRM, FastMod, CheckMod, ExtendRM,
OSExtend, CodeRM or MemRM)
Again, this virus doesn't seem to be that harmful but will waste memory
and occasionally crash modules with the 'Address exception' error.
Extend is incapable of loading when !VZap is already installed, as
!VZap will delete it as soon as it tries to load. !VZap will also
inform you if it's already in memory when you load !VZap.
!VZap removes the offending lines from the !Boot file and deletes the
additional virus module. !VZap also amends the !Boot file so that
the Extend virus thinks it's already been infected and won't infect it
again. This gives increased protection against repeated attack.
Some variants call themselves Amiga!, andrew or more tasteless names.
Extent
Seems to be a variation on the Extend virus (above). VZap recognises and
zaps a number of different versions.
Icon (also known as Filer, Icon-A, Poison, Splodge or NewVirus)
This is a short BASIC program that is filetyped as a sprite and named
'Icon'.
This is another virus with a number of variations floating around,
again presumably because it is written in BASIC. VZap will attempt to
detect possibly new variations of this virus, but if you ever have any
doubts about a particular file, you are always welcome to contact me for
more information.
!VZap restores the !Boot file and deletes the 'Icon' file.
Versions 1.03 upwards also eliminate the Icon5574 variation.
Versions 1.28 also scan all sprite files to verify that they are indeed
sprite files.
Image
No specific data available on this one. !VZap simply detects it's
presence. Please contact me if you suspect you are infected.
IRQfix (also known as RiscExtRM, WimpPoll, OSSystem, MiscUtil, FastRom,
or AppRM)
Works in a similar way to the Extend virus but using one of the names
above.
!VZap restores the !Boot file and deletes the relevant virus module.
Honey Monster (detection added at v1.32)
Adds a !Boot file which in turn loads a file called "Bab", which is
written in BASIC and gives a 'dripping' screen effect if the date is
Fri 13th. Note, that this virus can replicate itself.
!VZap deletes the virus loading lines from the !Boot file and deletes the
BASIC "Bab" file.
Jester (detection added at v1.14) (could be a variation to the ArchieVirus!)
Affects 'absolute' (&FF8) files by adding virus code onto the end of the
application code and then adjusting the original execution address to call
the new virus code. Once loaded, Jester installs a module called 'Filer'
which contains it's reproduction code. It can be detected from the
RISC OS Filer because of an additional hard space, CHR$(160), at the
end of the module name.
There currently seem to be two variations; one affecting files which start
with a BL instruction and another for the B instruction.
!VZap deletes the virus code and restores affected files. It will also
detect this virus loading into memory and give you the option to
remove it.
Link (detection added at v1.33) also known as BSToDel.
Seems to be a variation of the Extend virus.
Module
Another quite common module virus.
VZap detects and restores affected modules.
MonitorDAT (detection added at v1.33)
Seems to be a variation on the DataDQM/Vigay virus. Some versions seem
to have copyright messages to imply they were written by anti-virus
authors. These names are no doubt added by people modifying them.
VZap deletes the relevant !Boot and program files.
Net Manager
No specific data available on this one. !VZap simply detects it's
presence. Please contact me if you suspect you are infected.
NetStatus (also known as Arcuebus, GraphMdl, InfoFile, ModularR, ProgUtil,
PureMath, Resource, SoundMdl or SystemRS)
This is similar to the IRQfix virus, but replaces one of the modules
already present in RiscOS - The NetStatus one.
This virus is detectable because it's version number (3.07) is higher
than that currently in RISC OS, yet it is dated 1988.
!VZap restores the !Boot file and deletes the relevant virus module.
Nitemare (detection added at v1.33)
Rather a nasty one which tends to copy loads of files with names " ..."
etc into any <Obey$Dir> directories. The virus code is randomly
generated, as are the lines added to !Boot and !Run files.
VZap scans !Boot and !Run files amending them back to their original
status as well as deleting any files referenced by lines in either !Run
or !Boot.
VZap also deletes any additional sprite files which are added.
A tell tale sign of this virus is either lots of filenames with " "
characters in them or lots of additional sprite files containing a single
sprite called "file_394".
Pattern
Seems to be a variation on the Extend virus (above). VZap recognises and
zaps a number of different versions.
!Room
Appears to be a Trojan which triggers itself when it receives a !Help
request (wimp message &502), when it kills VProtect and sets an Obey
command to run the file and then delete the directory containing the
file.
!VZap stops the module from loading whilst !VZap is loaded, and also
detects and deletes the module from discs.
Simple (detection added at v1.33)
No specific data on this one.
It just has a message (C) 1994 The Dark Lord in it
VZap deletes it.
Thunderpants (detection added at v1.33)
VZap copes with about 20 variants of this virus.
Some variations attempt to wipe <Killer$Dir> presumably in an attempt
to delete copies of Pineapple's virus killer.
Some try to rename the floppy disc in drive 0.
Others are generally harmless, but again it's easy to modify.
VanDamme
This is quite a nasty one to detect as it's name is chosen from a
random assortment of letters and it affects either !Boot files or !Run
files. One danger of this virus is that there is a slim (1 in 100000)
chance of it re-formatting the disc in drive 0.
!VZaps protection is two-fold. Firstly, it will restore affected
!Boot files and delete the relevant virus program. Secondly, whilst
!VZap is installed, it will detect the VanDamme virus attempting to
load and bleep, opening the wimp watcher (status) window.
Other known viruses
~~~~~~~~~~~~~~~~~~~
Cebit/Lord of Darkness/TlodMod
Link
Millennium
MyMod (fairly harmless)
Parasite (nasty one)
Sprite (also quite nasty)
Thanatos/RiscOSext/TaskAlloc (also nasty)
TrapHandler
Valid
These viruses seem to be very rare, as I have yet to be notified of any
actual infections 'in the field' so to speak. Please always feel free to
contact me if you suspect that your machine may be infected with a new or
unrecognised virus. I will then endeavour to help and update !VZap as
quickly as possible.
⌐P.Vigay, 1997