CompuServe Thread

Forum unknown · Hot News & Rumors

#WARNING! Virus loose!

5 messages in this thread
#87294From: John DraperOct 2, 1987 1:41 AM
Well, it had to happen sooner or later. There are a variety of programs that are variously known as Trojan Horses, Bombs, and Viruses. While Bombs are generally destructive (as evidenced by their name), and Trojan Horses are either destructive or for the purpose of theft of data, Viruses have been known to be benign or malignant both. A Virus has shown up on the Amiga, arriving from Europe, and coming from a group calling themselves SCA. Since it is uncertain yet what its purpose is, that is, how destructive it may or may not be, it will pay to check any disks you boot from and kill the virus if found. The method of propogation is as follows. An Amiga is booted with an infected disk. All works normally, with no sign that anything is amiss. If you then reboot the machine with the CTRL-Amiga-Amiga key using an uninfected disk, the virus is transferred to the boot disk, and it too becomes a "carrier", ready to pass it on, and so on. The presence of the virus can be detected by looking at block 1 on a disk. Normally, this will have random data or a pattern of data in it, but you will be able to see the virus quite easily if it is there. Using Sectorama (SEC.ARC in DL 9… DiskZap will not show it), look at block 1 (Cyl 0, Hd 0, Sector 1). If the virus is present, run INSTALL on the disk. INSTALL will rewrite sectors 0 and 1, killing the virus. Then, AND MOST IMPORTANTLY, TURN OFF the Amiga's power. If you have booted from an infected disk, and have used INSTALL to kill the virus, rebooting without powering off/on will only reinfect the disk. There have been a couple of reports of a message showing up on the screen, and one was followed by the disk being uniusable afterward, but I can't confirm that it was trashed by the virus. The message was: "Something wonderful has happened. Your AMIGA is alive !!! and, even better,,, Some of your disks are infected by a VIRUS !!!" This is the same message that appears in block 1 of an infected disk. Watch for it… stomp it out. Regards, Larry.
#87306From: Barry MassoniOct 2, 1987 3:43 AM
I`m not a programer or an expert, but I thought that re-booting the system was supposed to clear the machines memory-how can the virus be transmited? Also, should someone without the ability to look at a disk in the way you suggested run across this message will a cold reboot solve the problem (so long as the "infected" disk is not used again)? Will initalizing an "infected" disk (after a cold boot) remove the infection? (along with anything else on the disk). One more thing, don`t you think that this message is important enough to go at the head of the forum-so that you see it when you enter the forum?
#87327From: John DraperOct 2, 1987 3:17 PM
The memory is not only not cleared upon rebooting, but there is a way to allow a program to survive a warm boot (CTRL-Amiga-Amiga). The virus itself is contained in the "boot block", and when you boot from an infected disk, installs itself in this manner. When you reboot with an uninfected disk, the virus writes itself out to the boot block of that disk, infecting it as well. A cold reboot (power off, power on) will indeed remove it from the memory. The problem is, you must know in advance that the disk you are currently booted from is infected before you would think to go through this procedure. As for looking at the disk to determine if the virus is there, the program to use is "Sectorama", which is in DL 9 as SEC.ARC. Perhaps someone will come up with a program that will detect and kill the virus, giving you a warning at the same time. I do think it's important, and we will probably put it into one of the Data Libraries and mention it in the short bulletin which everyone will see upon entry to the forum.
#87327From: John DraperOct 2, 1987 3:17 PM
The memory is not only not cleared upon rebooting, but there is a way to allow a program to survive a warm boot (CTRL-Amiga-Amiga). The virus itself is contained in the "boot block", and when you boot from an infected disk, installs itself in this manner. When you reboot with an uninfected disk, the virus writes itself out to the boot block of that disk, infecting it as well. A cold reboot (power off, power on) will indeed remove it from the memory. The problem is, you must know in advance that the disk you are currently booted from is infected before you would think to go through this procedure. As for looking at the disk to determine if the virus is there, the program to use is "Sectorama", which is in DL 9 as SEC.ARC. Perhaps someone will come up with a program that will detect and kill the virus, giving you a warning at the same time. I do think it's important, and we will probably put it into one of the Data Libraries and mention it in the short bulletin which everyone will see upon entry to the forum.
#87306From: Barry MassoniOct 2, 1987 3:43 AM
I`m not a programer or an expert, but I thought that re-booting the system was supposed to clear the machines memory-how can the virus be transmited? Also, should someone without the ability to look at a disk in the way you suggested run across this message will a cold reboot solve the problem (so long as the "infected" disk is not used again)? Will initalizing an "infected" disk (after a cold boot) remove the infection? (along with anything else on the disk). One more thing, don`t you think that this message is important enough to go at the head of the forum-so that you see it when you enter the forum?