home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
The Atari Compendium
/
The Atari Compendium (Toad Computers) (1994).iso
/
files
/
umich
/
utils
/
virus
/
atarivir.lzh
/
atarivir.690
< prev
next >
Wrap
Text File
|
1992-03-10
|
34KB
|
643 lines
========================================================================
== Computer Virus Catalog (Version 1.2) ==
== *** 18 Atari Viruses *** ==
========================================================================
== Status: June 5, 1990 ==
== Classified: 6 Atari-Viruses (ATARIVIR.A89): Nov. 15, 1989 ==
== +12 Atari-Viruses (ATARIVIR.690): June 5, 1990 ==
========================================================================
== List of classified Atari Viruses: =Doc=
== --------------------------------- =---=
== + 1) ACA Virus =690=
== 2) Anthrax = Milzbrand Virus =A89=
== + 3) ANTI-2 Virus =690=
== + 4) Blot Virus =690=
== 5) c't Virus =A89=
== 6) Emil 1A = "Key" = "BPL" Virus ="Virus 1A" =A89=
== 7) Emil 2A Virus = "Virus 2A" =A89=
== + 8) Goblins Virus =690=
== + 9) Kobold 2 Virus =690=
== + 10) LAB Virus =690=
== + 11) MAD Virus =690=
== + 12) Maulwurf (=Mole) Virus =690=
== 13) Mouse (Inverter) Virus =A89=
== + 14) Oli Virus =690=
== + 15) Pirate Trap Virus =690=
== + 16) Screen Virus =690=
== 17) Zimmermann-Virus =A89=
== + 18) 5th Generation Virus =690=
== Remark: new entries are marked "+" in column 13; the suffix (A89, ==
== 690) refers to the specific documents where entry is published. ==
== ==
== Presently, the following viruses are analysed: ==
== .) Freeze Virus ==
== Generally, we have problems to receive Atari viruses for analysis, ==
== since many users wish to exchange their viruses (like stamps) ==
== against our's, which we principally refuse: the Virus Test Centers ==
== ethical standard is, that we do not spread viruses! ==
========================================================================
======== Computer Virus Catalog 1.2: "ACA"-VIRUS (5-June-1990) ========
Entry............... "ACA" Virus
Alias............... ---
Strain.............. ---
Detected when....... October 1988
where...... Utrecht (Netherlands)
Classification...... System (Bootsector) Virus, Reset-resident
Length of virus..... 512 Bytes
------------------------Preconditions----------------------------------
Operating System(s). Atari TOS
Version\Release..... All versions
Computer models..... All Atari ST,STE
-------------------------Attributes------------------------------------
Easy identification. If the bootsector is infected, the string "ACA"
can be found at bootsector position $04 and $4E.
In memory, the same string can be found at $630.
Type of infection...: Self-Identification: The Virus tests boot sector-
position 4 for String "AC"; if string does not
match, virus infects boot sector.
Reset-resident at address $600 via magic long-
word ($12123456) and checksum ($1234).
Infection Trigger...: Reset
Storage media affected: The virus infects drive A,B!
Interrupts hooked...: No Interrupts used.
No system vectors changed
Damage..............: Permanent Damage: Only after reset overwriting
boot sectors.
Transient Damage: Clearing first track
Damage Trigger......: Damage occurs after 10 infections.
Particularities.....: ---
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Program that search for reset-resident programs,
especialy lower system area ($800).
Programs that calculate the checksum and change
it, if it is $1234; the sector is then regarded
as not executable. Reboot the system with a
'clean' disk! ( Category 1.3 ).
Countermeasures successful:---
Standard means......: Write-protect the disk.
Write a well-known program to the boot sector;
'manually' change the checksum to a value other
than $1234.
--------------------- Acknowledgement ---------------------------------
Location............: Virus Test Center, University Hamburg, FRG
Classification by...: Thomas Piehl
Documentation by....: Thomas Piehl
Information Source..: from George R. Woodside
Date................: 5-June-1990
==================== End of "ACA"-VIRUS ===============================
======== Computer Virus Catalog 1.2 "ANTI-2" Virus (5-June-1990) ======
Entry............... "Anti-2" Antivirus Virus
Alias............... ---
Strain.............. ---
Detected when....... October 1988
where...... Helmond (Netherlands)
Clssification....... Bootsector Virus
Length of virus..... 512 Bytes
------------------------Preconditions----------------------------------
Operating System(s). Atari TOS
Version\Release..... All versions
Computer models..... All Atari ST
-------------------------Attributes------------------------------------
Easy identification. The string : "This Anti-Virus beeps" can be found
in the bootsector at Byte Nr. $1E, or in memory
at Dskbufp+$600+$1E.
Type of infection... Any non-executable Bootsector will be overwritten
Infection Trigger... Execution of BIOS disk function Getbpb.
Media affected...... Any kind of media.
Interrupts hooked... hdv_bpb vector (used by BIOS disk functions).
Damage.............. ---
Damage trigger...... ---
Particularities..... The Program can be used as an anti-virus. If the
bootsector is executable, the program produces
a sound and the screen flashes.
Similarities........ ---
-----------------------------------------------------------------------
Countermeasures..... Make sure that the virus is not in memory. Modify
the last byte in bootsector to another value.
Standart means...... Clear all bytes in bootsector beginning at
offset 30 decimal.
-----------------------Acknowledgements--------------------------------
Location............ Virus Test Center, University of Hamburg, FRG
Classification by... Andre' Schaper
Documentation by.... Andre' Schaper
Information Source.. George R. Woodside
Date................ 5-June-1990
==================== End of "Anti-2" Virus ============================
======== Computer Virus Catalog 1.2: "Blot" Virus (5-June-1990) =======
Entry............... "Blot" Virus
Alias............... ---
Strain.............. ---
Detected when....... May 1988
where...... Amherst (USA)
Classification...... Boot sector virus
Length of virus..... 681 Bytes
------------------------Preconditions----------------------------------
Operating System(s). Atari TOS
Version\Release..... ROM TOS from 02.06.1986; in other versions,
no action is performed.
Computer models..... All Atari ST
-------------------------Attributes------------------------------------
Easy identification. In memory at Phystop +34 and in the boot sector at
the same offset, the following bytes can be found:
$0206198600FC0018
Type of i