CompuServe Thread

#Jeff 2 Virus

5 messages in this thread
#124751From: Peter JonesDec 11, 1993 2:42 PM
I posted the following message on 4 December. So far no reply. Is there really nobody out there who can help? >A young friend of mine is having trouble with viruses. He has an A500 without hard disk. Using VirusX 4.4 he is told that the Australian Parasite Virus was found in memory and has been disabled. The Link Protector virus killer tells him that "Jeff 2 has been found and destroyed", While Kill the Virus warns him that "a reset vector has been alerted Cold is C7E1A0, Cool is 0, Zarm is 0" When told to fix it, a second warning comes up" "Warning something is resident kicktag dtr is C0AB3A, Warning something is intercepting track disk calls to C7E256" Additionally, sometimes when resetting, he gets the following message on the screen in a red rectangle: Hi, Jeff's speaking here … (w) By the genius butonic V3.00/9.2.89 – Gen.00030 Greetings to Hackmack Atlantic and Alex Franck Wolfram Gerlinck Miguel Klaus and Snoopydata. He has run all his floppy disks thru various virus killers, to no effect. Can anyone help?? All advice appreciated.
#124769From: Karl F. KugelDec 11, 1993 6:03 PM
I have never heard of the "Jeff" virus, 2 or otherwise, but you could contact the "Safe Hex guys at: Safe Hex International Erik Loevendahl Soerensen Snaphanevej 10 DK-4720 Praestoe Denmark Phone: + 45 55 99 25 12 Fax: + 45 55 99 34 98 They say that you need to "Please send 2 "Coupon Response International" and a self addressed envelope, if you want info about SHI by letter." They should be able to help if anyone can.
#124988From: Peter JonesDec 13, 1993 2:15 PM
Karl, Thanks, Shall do. I have a desperate student on my hands! Pete Jones, flying on AutoPilot from Brussels, Belgium
#124788From: John GagerDec 11, 1993 9:45 PM
Peter: Although I have never heard of the Jeff virus, the message from the screen in a red rectangle that shows (w) By the genius butonic, a search through the Virus Checker docs does show this: BUTONIC: This is another file type virus. It uses the DoIO vector to check for reads to the Root Block of a disk. It will then write the virus to the disk and add it to the startup-sequence as the first instruction. The filename of the virus and its comment make it invisible when doing a DIR but shows up with a LIST. This will also bring up GURU messages and change the title of the active window to some german stuff. To get rid of it we clear the ROMTAG, restore the DoIO vector and delete the file off the disk. You will need to remove the blank line from the startup-sequence where the virus was. The second version of this infects the Level 2 Interrupt as well and uses different file names to hide itself in the Startup-Sequence. So I would suggest downloading VC633.LHA in Library 9 of this forum and see if it will help. Actually I have a hard time understanding the mentality (which isn't much) of someone who writes a virus. They certainly are not proving their preceived superior programming skills and offer nothing to the Amiga community. I know Dave Haynie doesn't like them <g>.
#124989From: Peter JonesDec 13, 1993 2:17 PM
Thanks for the info. I have meanwhile downloaded VC33 and shall give it to my young friend. Trying to sort out somebody's virus problems from a distance is really difficult!