home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!uknet!acorn!aglover
- From: aglover@acorn.co.uk (Alan Glover)
- Newsgroups: comp.sys.acorn
- Subject: Re: Viruses (again...)
- Message-ID: <18584@acorn.co.uk>
- Date: 15 Sep 92 08:08:28 GMT
- References: <92258.223421RFRANCIS@ESTEC.BITNET>
- Sender: aglover@acorn.co.uk
- Organization: Acorn Computers Ltd, Cambridge, England
- Lines: 70
-
- In article <92258.223421RFRANCIS@ESTEC.BITNET> RFRANCIS@ESTEC.BITNET (C R Francis) writes:
-
- >OK, I admit it, I didn't read any of the recent postings about viruses,
- >as I haven't got any (or so I thought...).
- >
- >So, this evening I switch on...
- >... and there's this anoying message whenever a !boot or
- >!run file is activated. Something about being 'a friendly virus'
- >(whatever that is), to be careful using illeagal software, and a
- >generation number of 17 or 18.
- >
- >Oh yes, and now some applications freeze up, even _ones I've written
- >myself_. That really annoys me -- how can I develop applications
- >when the thing freezes up?
- >
- >And I haven't even got any illegal software.
- >
- >So, what can I do about it?
-
- You are one of the many, many people who has -just- discovered that
- you have the Module virus, and have probably had it since early this
- year.
-
- The virus first came to light late last year, and since then has been
- spread in any number of ways including Archimedes World (Feb '92),
- Micro User (Apr '92), Orion IDE card EPROMS (V1.06 and V1.07 I
- believe), several commercial programs and I don't want to know how
- many PD/ShareWare programs. In short - it's spread so successfully
- that very few people will have got it from illegally obtained
- software.
-
- The message is only displayed after 6th Sept 1992 - which is why most
- people have been unaware of it until then. Despite the message content
- it is still there, and still active.
-
- It infects modules by appending about 1K of code and modifying the
- entry offsets in the module header to pass through the viral code and
- then back to the original code. This will upset any program which
- relies upon the module being of known length, and will also upset some
- kinds of protected discs (since saving to them disrupts the protection
- leaving the disc unusable). A quick check for infection is to see if
-
- i) the datestamps on the modules have been changed, and
-
- ii) loading the module into !edit reveals a string 'Press any key to
- continue' in the last page or so of the module.
-
- There are several ways of removing it, but in all cases a program of
- some kind is needed.
-
- Archimedes World Mar '92 contained two small programs intended
- specifically for this virus. They have also been posted to c.b.a (a
- long time back - have you access to an archive site ?).
-
- !Scanner can detect it from version 1.14 and remove it from version
- 1.46. !Scanner is available from Tor Houghton, Fjellveien 4, PO Box
- 142, 1361 Billingstad, NORWAY and 'costs' three floppy discs.
-
- !Killer can detect it from version 1.17 and remove it from version
- 1.26. !Killer is available from Pineapple Software, Tel: 081 599 1476
- and costs 24 pounds ex-VAT for an annual subscription including
- updates.
-
- !Hunter version 1.00 and !Guardian version ?.?? can also detect and
- remove it. !Hunter can be found on BBSs and PD libraries, !Guardian
- can be found in a similar manner, or obtained directly from the
- author, Paul Vigay on his own BBS (which I think is still going) 0705
- 871531 (Viewdata, 7E1).
-
- Alan
-