home *** CD-ROM | disk | FTP | other *** search
- VIRUSES
- ~~~~~~~
- VZap v1.33 - This version currently copes with around 120 viruses and/or
- variants of virus.
-
-
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- The following information is provided for reference and is aimed at the
- more technical reader. It is by no means exhaustive and not all viruses
- detected by !VZap are listed. However, if you think you've found a
- new virus, or a strain of existing virus that you don't think !VZap
- detects, please send it to me on a CLEARLY LABELLED disc, together with
- the version number of !VZap you are using and a SAE.
-
- I will then endeavour to modify and upgrade !VZap accordingly and send
- you back your disc with the latest version of !VZap. Again, this service
- is FREE OF CHARGE (on receipt of disc and SAE) to registered users.
-
- N.B. Please do not try to disable and/or make viruses inoperative, as this
- can lead to problems in reactivating them. Just send me them 'as they are',
- on a clearly labelled disc.
-
- In alphabetical order:-
-
- All New ID virus (also known as 'Options' virus)
- Seems similar to the icon virus in that !Boot files have a couple of
- lines added to them to run a basic program called 'Options'. This
- doesn't appear to have any side-effects other than taking up memory in
- the computer and being unable to Quit, so seems reasonably harmless.
- !VZap detects it's presence and deletes it.
-
- ArchieVirus (also known as &FF8 virus) - possibly similar to 'Jester'
- This affects files with the filetype 'Absolute' (hence FF8) by adding
- code to the end and then calling this new code.
- I haven't actually seen this virus so !VZap detects it but does not
- destroy it. Please let me know if you locate it.
-
- BBCEconet (affects 'absolute' files)
- Adds virus code onto the end of 'absolute' filetypes and also installs
- a modified 'BBCEconet' module.
-
- BigFoot (detection added at v1.33)
- A quite tricky one to track down because it generates a random filename
- to save the virus code as, and amend the !Boot file.
- It gives various error messages depending whether it's 25th Dec, 5th Nov,
- 4th Jul or 15th Mar.
-
- Breakfast (various different variations)
- This virus affects Absolute (&FF8) filetypes by adding around 6.5k onto
- the end of the file, then changing the first few instructions to jump to
- the virus code at the end. This is quite a nasty one to detect as the
- virus code itself is EOR encoded, using random codes. It also scrambles
- bytes &18 to &94 of the original file.
- !VZap will detect and restore affected files to their original condition
- by deleting the virus code and amending the beginning of the file to
- the original instructions. This virus quite often hides in the Squeeze
- utility (if you have it in your library directory)
-
- Datadqm (also known as Vigay virus)
- This virus seems to be linked to me for some reason, presumably because
- being written in BASIC it can be modified easily by people. Therefore
- there could be variations of this one around, some with my name added to
- them - possibly by competitive virus killer authors.
- It doesn't seem to be a virus as such, merely a desktop 'silly' capable of
- replicating itself into any application without a !Boot file.
- Note, it does not delete or change any data, so is harmless. The program
- itself flickers the screen occasionally to make it look as though you have
- a loose monitor connection. However, as it can be easily altered, other
- variations could do other effects.
- !VZap kills both the new !Boot file and the 'Datadqm' file.
- IF ANY COMPANY SELLING A COMMERCIAL VIRUS KILLER CLAIMS THAT I HAVE WRITTEN
- MANY VIRUSES THEY ARE LYING AND I WOULD LIKE TO BE INFORMED - BEFORE TAKING
- LEGAL ACTION.
-
- Die Hard (seems to be a variation on the Icon virus)
- This virus adds a line to the !Boot file and saves itself under the
- filename 'setup'.
- It is capable of killing the Vprotect virus killer module and will
- delete the 'Killer' virus killer. It seems incapable of deleting
- !VZap.
- !VZap restores the !Boot file and deletes the relevant virus program.
-
- Extend (also known as MonitorRM, ColourRM, FastMod, CheckMod, ExtendRM,
- OSExtend, CodeRM or MemRM)
- Again, this virus doesn't seem to be that harmful but will waste memory
- and occasionally crash modules with the 'Address exception' error.
- Extend is incapable of loading when !VZap is already installed, as
- !VZap will delete it as soon as it tries to load. !VZap will also
- inform you if it's already in memory when you load !VZap.
- !VZap removes the offending lines from the !Boot file and deletes the
- additional virus module. !VZap also amends the !Boot file so that
- the Extend virus thinks it's already been infected and won't infect it
- again. This gives increased protection against repeated attack.
- Some variants call themselves Amiga!, andrew or more tasteless names.
-
- Extent
- Seems to be a variation on the Extend virus (above). VZap recognises and
- zaps a number of different versions.
-
- Icon (also known as Filer, Icon-A, Poison, Splodge or NewVirus)
- This is a short BASIC program that is filetyped as a sprite and named
- 'Icon'.
- This is another virus with a number of variations floating around,
- again presumably because it is written in BASIC. VZap will attempt to
- detect possibly new variations of this virus, but if you ever have any
- doubts about a particular file, you are always welcome to contact me for
- more information.
- !VZap restores the !Boot file and deletes the 'Icon' file.
- Versions 1.03 upwards also eliminate the Icon5574 variation.
- Versions 1.28 also scan all sprite files to verify that they are indeed
- sprite files.
-
- Image
- No specific data available on this one. !VZap simply detects it's
- presence. Please contact me if you suspect you are infected.
-
- IRQfix (also known as RiscExtRM, WimpPoll, OSSystem, MiscUtil, FastRom,
- or AppRM)
- Works in a similar way to the Extend virus but using one of the names
- above.
- !VZap restores the !Boot file and deletes the relevant virus module.
-
- Honey Monster (detection added at v1.32)
- Adds a !Boot file which in turn loads a file called "Bab", which is
- written in BASIC and gives a 'dripping' screen effect if the date is
- Fri 13th. Note, that this virus can replicate itself.
- !VZap deletes the virus loading lines from the !Boot file and deletes the
- BASIC "Bab" file.
-
- Jester (detection added at v1.14) (could be a variation to the ArchieVirus!)
- Affects 'absolute' (&FF8) files by adding virus code onto the end of the
- application code and then adjusting the original execution address to call
- the new virus code. Once loaded, Jester installs a module called 'Filer'
- which contains it's reproduction code. It can be detected from the
- RISC OS Filer because of an additional hard space, CHR$(160), at the
- end of the module name.
- There currently seem to be two variations; one affecting files which start
- with a BL instruction and another for the B instruction.
- !VZap deletes the virus code and restores affected files. It will also
- detect this virus loading into memory and give you the option to
- remove it.
-
- Link (detection added at v1.33) also known as BSToDel.
- Seems to be a variation of the Extend virus.
-
- Module
- Another quite common module virus.
- VZap detects and restores affected modules.
-
- MonitorDAT (detection added at v1.33)
- Seems to be a variation on the DataDQM/Vigay virus. Some versions seem
- to have copyright messages to imply they were written by anti-virus
- authors. These names are no doubt added by people modifying them.
- VZap deletes the relevant !Boot and program files.
-
- Net Manager
- No specific data available on this one. !VZap simply detects it's
- presence. Please contact me if you suspect you are infected.
-
- NetStatus (also known as Arcuebus, GraphMdl, InfoFile, ModularR, ProgUtil,
- PureMath, Resource, SoundMdl or SystemRS)
- This is similar to the IRQfix virus, but replaces one of the modules
- already present in RiscOS - The NetStatus one.
- This virus is detectable because it's version number (3.07) is higher
- than that currently in RISC OS, yet it is dated 1988.
- !VZap restores the !Boot file and deletes the relevant virus module.
-
- Nitemare (detection added at v1.33)
- Rather a nasty one which tends to copy loads of files with names " ..."
- etc into any <Obey$Dir> directories. The virus code is randomly
- generated, as are the lines added to !Boot and !Run files.
- VZap scans !Boot and !Run files amending them back to their original
- status as well as deleting any files referenced by lines in either !Run
- or !Boot.
- VZap also deletes any additional sprite files which are added.
- A tell tale sign of this virus is either lots of filenames with " "
- characters in them or lots of additional sprite files containing a single
- sprite called "file_394".
-
- Pattern
- Seems to be a variation on the Extend virus (above). VZap recognises and
- zaps a number of different versions.
-
- !Room
- Appears to be a Trojan which triggers itself when it receives a !Help
- request (wimp message &502), when it kills VProtect and sets an Obey
- command to run the file and then delete the directory containing the
- file.
- !VZap stops the module from loading whilst !VZap is loaded, and also
- detects and deletes the module from discs.
-
- Simple (detection added at v1.33)
- No specific data on this one.
- It just has a message (C) 1994 The Dark Lord in it
- VZap deletes it.
-
- Thunderpants (detection added at v1.33)
- VZap copes with about 20 variants of this virus.
- Some variations attempt to wipe <Killer$Dir> presumably in an attempt
- to delete copies of Pineapple's virus killer.
- Some try to rename the floppy disc in drive 0.
- Others are generally harmless, but again it's easy to modify.
-
- VanDamme
- This is quite a nasty one to detect as it's name is chosen from a
- random assortment of letters and it affects either !Boot files or !Run
- files. One danger of this virus is that there is a slim (1 in 100000)
- chance of it re-formatting the disc in drive 0.
- !VZaps protection is two-fold. Firstly, it will restore affected
- !Boot files and delete the relevant virus program. Secondly, whilst
- !VZap is installed, it will detect the VanDamme virus attempting to
- load and bleep, opening the wimp watcher (status) window.
-
- Other known viruses
- ~~~~~~~~~~~~~~~~~~~
- Cebit/Lord of Darkness/TlodMod
- Link
- Millennium
- MyMod (fairly harmless)
- Parasite (nasty one)
- Sprite (also quite nasty)
- Thanatos/RiscOSext/TaskAlloc (also nasty)
- TrapHandler
- Valid
-
- These viruses seem to be very rare, as I have yet to be notified of any
- actual infections 'in the field' so to speak. Please always feel free to
- contact me if you suspect that your machine may be infected with a new or
- unrecognised virus. I will then endeavour to help and update !VZap as
- quickly as possible.
-
- ⌐P.Vigay, 1997