home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
System Booster
/
System Booster.iso
/
Virushunter
/
VIB
/
Virus
/
E
/
Eleni 3
< prev
next >
Wrap
Text File
|
1996-09-26
|
2KB
|
58 lines
Name : Eleni 3
Aliases : No Aliases
Type/Size : Boot/1024
Clones : No Clones
Symptoms : No Symptoms
Discovered : 23-04-94
Way to infect: Boot Infection
Rating : Dangerous
Kickstarts : 2.X/3.X
Damage : Damages LoadFiles
Removal : Install Boot
Comments : If you`re starting the Eleni 3 virus it allocates
20000 byte Chip-memory as long as there isn`t any Chip
memory anymore. The the virus copies itself into the
last available chip-area.
Then the virus patches the DoIO()-Vector to infect
other disks. If you`re now inserting a disk the virus
checks if the disk is already infected by loading the
bootblock at address $70000. If the disk is already
infected the virus subs 1 from a special address,
which is on some AMIGAS the Clock-Address (A2000, I
think). But all this will be done if there was a
bootblock READ-Access. If a WRITE-Access is requested,
the virus patches the LoadSeg()-Vector from the
"dos.library".
This LoadSeg-patch will do the following:
If a file will be loaded the virus checks for the
Clock Address. If this address reached the value 1 the
virus insert a new name for LoadSeg, "ELENI!". In the
CLI you will get this error:
`Unknown command: "ELENI!"`
If the Clock-Address reached 0 the virus loads the
actual file into address $70000 und some bytes in this
file will be changed. You will see a GURU.
NOTE from Alex:
All in all the virus is very LAME-Coded. Please guys!
Don`t pollute our beloved AMIGA with such shit!
A.D 11-94