----------------------------------------------------------------------------- The Archimedes Virus Reference Document - Version 1.14t (February 14, 1992) ----------------------------------------------------------------------------- ) 1991, 1992 Tor O. Houghton and Alan Glover As the number of people using the Archimedes range of computers has increased over the years, so has the number of viruses. This document contains the compiled information from various virus researchers and their killers and should (hopefully) assist those who think they might be infected by a virus. It is not intented to provide a very detailed technical description (although I might sway from this once or twice! :-), but to allow the reader to understand what the virus generally does, what makes it activate and what it does upon activation. Most important, however, it should help the user with the removal! This document is Public Domain (i.e. no profit based use, etc.). If this is distributed together with commercial software, I would like the latest version of it (whatever it does) and a mention somewhere. I *do* spend a lot of time updating this, and I don't think I am too bold in suggesting this. Please note that this document is also available as an Impression file. Acknowledgements (in alphabetical order): Svlad Cjelli (Dean ) Alan Glover, Acorn Computers Ltd. Eivind Hagen Bjxrn Hotvedt Richard K. Lloyd Terje Slettebx Archimedes, Acorn and RISC OS are registered trademarks of Acorn Computers Ltd. Copyright notice: This document is copyright. Profit based distribution (whether PD or Shareware) without the prior consent from the authors, is strictly illegal. ----------------------------------------------------------------------------- A virus is nothing magical. Anyone with a bit of programming skills and some knowledge about the machine's operating system is capable of creating a virus. Usually these programmers think it is fun, they've read too many cyberpunk books, or they are generally pitiful creatures who like to inflict damage. Final note: In spite of many journalist's secret wishes, a computer virus cannot spread from one type of computer to another. For example, a virus written on PC running DOS or Windows cannot infect the Archimedes - in native mode. If you are using the PC emulator, a virus functions perfectly here too. ----------------------------------------------------------------------------- A few definitions: CONNECTIVITY The level of ability a computer has to connect to other computer. Nowadays it is very easy to, for example, phone a BBS and download new software. The higher lever of connectivity, the higher the level of possible exposure to computer viruses (i.e. the more users the greater the exposure!). TROJAN HORSE This is a generic name (taken from Greek mythology) for a penetration method that includes hidden code. An example of this is the Link virus which, being a helpful in the ways of converting backspace to delete, also launches a virus into your computer environment. VIRUS A computer virus can be defined as a malicious program capable of replicating itself. See "A Computer Security Glossary for the Advanced Practitioner" in the Computer Security Journal IV, No. 1, 1987 for a similar description. Note, however, that most (there are exceptions!!) viruses on the Archimedes do no serious damage (in the form of deletion/encryption/compression of files/media). WORM A computer program which moves through your computer system, altering data as it copies itself and deleting the old copy. If a worm reproduces it could also be called a virus. There are no reports of worms on the Archimedes, mainly because it is such a closed system, and would be detected much too easily to become a hazard. Networks are more exposed to such nasties. Worms may carry malicious code. ----------------------------------------------------------------------------- New viruses (and/or documents), comments, suggestions, backstabbings, flamings etc, should be either: a) mailed to Tor O. Houghton Fjellveien 4 PO Box 142 1361 Billingstad NORWAY or, b) emailed to #121 on The World of Cryton (+44 749 670030 / 300-14400bps) or, c) emailed to Tor Houghton on Excelsior! (M)BBS (+47 2 846379 / 300-14400bps) or, d) mail me through my neighbour's internet address - bhotvedt@gollum.uio.no or to reach Alan Glover you will have to send: e) email to Alan Glover at aglover@acorn.co.uk or, f) snail mail to Alan Glover (Virus) Acorn Computers Ltd. Fulbourn Road Cherry Hinton Cambridge CB1 4JN United Kingdom or, g) emailed to #6 on The World of Cryton (+44 (0)749 670030 / 300-14400bps) or, h) emailed to #244 on Arcade (+44 (0)81 654 2212/655 4412 / 300-9600bps) or, f) by FidoNet netmail to 'alan glover' at 2:253/174. ----------------------------------------------------------------------------- Virus detection utilities referred to in this document: Hunter : ) Michel Fasen (1.13) * Interferon : ) Tor O. Houghton (2.08) IVSearch : - No name present! (2.05) # Killer : ) Alan Glover (Pineapple Software Ltd.) (1.27) Scanner : ) Tor O. Houghton (1.16) VirusKill : ) Terje Sletteboe (1.00) VKiller : ) Richard K. Lloyd (2.30) * # Virus removal utilities referred to in this document: Hunter : ) Michel Fasen (1.13) * Killer : ) Alan Glover (Pineapple Software Ltd.) (1.27) Scanner : ) Tor O. Houghton (1.16) VirusKill : ) Terje Sletteboe (1.00) VKiller : ) Richard K. Lloyd (2.30) * # VProtect : ) Alan Glover (Pineapple Software Ltd.) (1.12) Asterisks (*) mark programs which are known to be incompatible with RISC OS 3. Last known version numbers in are in paranthesis. Hashes (#) mark programs not updated in a long time, and should not be relied upon. ----------------------------------------------------------------------------- Virus name: Most common name of the virus. Often chosen because of some text found in the virus, or like CeBIT, connected to some event (the biggest computer show in Europe). Aliases: Names which other anti-viral agent documents (usually brief notes which are included with the program) use for the same virus. Also names that are commonly used by BBS users etc. Origin: The country where the virus seems to have originated from. Isolation date: The date (as detailed as possible) when the virus was first found. Effective length: The length the virus occupies on the disc. The actual length in memory may well be shorter. Virus type: Task - Refers to viruses written as a multitasking program (i.e. appears on the Task Manager). Resident - Stores itself in the RMA, either as a module or just by reserving some memory. If it stores itself elsewhere, it is noted. Also, if the virus attaches itself to files, this too, is noted. Symptoms: Odd behaviour which might occur if the virus is loaded. This could be spurious crashes or files suddenly appearing. Take note that this has nothing to do with what the virus actually does when it activates, as this will be detailed as extensive as possible under the 'general comments' section. Detection method: Refers to anti-virus agents (complete with earliest version number) to my knowledge which detects the virus. Please be so kind as to update me on this, as I know there are several anti-virus programs wandering around but I do not have them all! Removal instructions: Either which programs to use to remove the virus from the infected file (complete with earliest version number), or if possible, which files to delete without destroying the program. Where it says 'Remove named file(s)', take note that if there is a !Boot file present, be sure to check it too (i.e. with !Edit). In particular, never assume that a Module may be RMKilled, or that an application task may be Quit. It might disappear, but it may also set up a timebomb with serious effects on the system. NOTE: Where there are no removal instructions the only thing to do is delete the whole application/program and copy a clean backup instead (you *do* keep clean backups? :-). More notes on in-memory removal: As a rule, it is unwise to attempt to remove a virus from memory yourself. However some anti-virus programs contain specific code to detect and remove viruses which are present in memory. Where an anti-virus program is known to be able to do this the program and version is given. The criteria for this is that the anti-virus program either neutralises or removes the virus from memory, leaving the machine in a safe enough state for the anti-virus program to remove the infection from your media. Even with this protection, you should still do a CTRL-Reset as soon as possible after you have been infected. General comments: As detailed information about the virus as possible. Also, if there are mutated version of the virus, these are stated here too, along with any relevant information. Sometimes square brackets [] with comments might appear. These are our comments, and often additional information which we thought the original author left out. ----------------------------------------------------------------------------- Viruses documented herein: Name Aliases Archie FF8, Archievirus CeBIT Lord of Darkness, TlodMod virus Extend Icon Icon-A, Filer, Poison, NewVirus Image Link Module ModVir, Illegal MyMod Silicon Herpes NetManager NetStatus Boot * Parasite * Sprite * Thanatos RISCOSext, RISCOS Extentions TrapHandler Vigay DataDQM, Shakes The asterisks ('*') indicate viruses which carry malicious code. Any detection of one of these viruses should be treated thus: 1) Perform a CTRL-RESET as soon as possible. To be safe, press F12 and type FX 200,3 beforehand. This should get the virus out of memory, just leaving the storage media to be cleaned. Remember that infection can be as easy as opening a filer viewer! 2) Load a virus killer, and check that the virus is not active. Some virus killers (eg Pineapple's !Killer) are capable of removing any resident virus, and withstanding infection attempts whilst doing this. 3) Run the virus killer through the system, opening the minimum possible number of filer windows possible. Obviously, if you keep your copy of the virus killer on a write-protected floppy this is quite easy! Remember to check removable discs too! Please note that resets and/or error which occur are usually the results of bad programming, and is therefore not considered as malicious. (It merely depicts the programmer's skills - he should have stuck to LOGO.) ----------------------------------------------------------------------------- Viruses not included yet (missing documentation): Name Aliases ----------------------------------------------------------------------------- Virus name : Archie Aliases : FF8 Origin : United Kingdom Isolation date : 1988 Effective length : 920 bytes Virus type : Resident Absolute (FF8) file infector. Symptoms : May cause "Address exception" or "Undefined instruction" errors. Absolute files will grow in length. Detection methods Media : Killer 1.17+, VKiller 2.00+, Scanner 1.02+ Memory : Interferon 2.00+, Killer 1.17+, VKiller 2.00+ Removal instructions Media : Killer 1.17+ Memory : Killer 1.17+, VKiller 2.00+ General comments This is a piece of ARM code that is appended to executables with the Absolute (&FF8) filetype. It is 920 (&398) bytes long and has a tell-tale 4-character string at the end of its code, "1210", which is used as an "already-infected" flag. The first instruction of the original executable is saved near the end of the virus code space and is replaced by a branch to the first instruction of the ArchieVirus code. What Archievirus does when first run: 1. Attempts to infect executables (Absolute filetype) with the filespecs "@.*" and "%.*". In other words, all executables in the current and library directory are attacked. 2. Uses OS_File 36 as a "semaphore" to see if it is lodged in RMA. If a call to OS_File 36 returns with an error, then it hasn't infected the RMA yet, so it proceeds to claim 920 bytes of RMA, copy itself into there and points a claim of the OS_File vector to its new RMA location. 3. The time is checked to see if it is the 13th of the month. If so, the code loops indefinitely, displaying the 45-character message: Hehe...ArchieVirus strikes again... (In the virus, this message is EORed with &64, and is therefore not easy to spot.) 4. Assuming it wasn't the 13th of the month (and NO, it doesn't check for a Friday!), then the original first instruction of the executable is replaced and the original normal code continues from &8000 onwards. The OS_File vector claim is quite important, because this serves two purposes: a. It allows OS_File 36 to return without an error, signalling that the RMA is already infected. b. It checks for OS_Files 0 and 10 (Save memory to file), 11 (create empty file) and 12,14,16 and 255 (Load file). If any of these are encountered then an infection attack is activated (see step 1 above). (Source: Richard K. Lloyd) --------------------------------------------------------------------------- Virus name : CeBIT Aliases : Lord of Darkness, TlodMod Origin : Germany Isolation date : March 1991 Effective length : 1240 bytes Virus type : Resident !Boot file infector, stores code as separate file. Symptoms : File "TlodMod" in application directories. Detection methods Media : Killer 1.17+, VKiller 2.10+, VProtect 1.06+ Memory : Interferon 2.00+, Killer 1.17+, VKiller 2.10+ Removal instructions Media : Killer 1.17+, VKiller 2.10+, delete named file, remove last line from !Boot. Memory : Killer 1.17+, VKiller 2.10+ General comments This is a module called "TlodMod" with the following title string: TlodMod 1.11 (11 Nov 1990) by Devil the LORD OF DARKNESS It is 1240 (&4D8) bytes long and hooks itself into UpCallV. It then activates once a minute and first checks for the existence of .TlodMod. If this already exists, then no further action is taken. If it doesn't, however, it then attempts to append the following line to .!Boot: rme. TlodMod 0 rml. .TlodMod If it succeeds at this, a counter is incremented and the module is replicated as .TlodMod. Every 16th successful infection will trip the virus into issuing a "*Wipe $.path.file*" (which will inevitably fail!) and then displaying a message accompanied by a simple graphic. The message displayed is: This is a warning to all Users, I am back on the Archimedes ... Your Archie is infected now and with him most of your programms. Don't worry, nothing is damaged, but keep in mind the protection! And always think about the other side of THE LORD OF DARKNESS ... Virus generation is (Source: Richard K. Lloyd) --------------------------------------------------------------------------- Virus name : Extend Aliases : Origin : United Kingdom Isolation date : October 1990 Effective length : 940 bytes Virus type : Resident Task. Stores code as separate file. Symptoms : File "MonitorRM", "CheckMod", "ExtendRM", "OSextend", "ColourRM", "Fastmod", "CodeRM" or "MemRM" in application directory. Each time the code is executed it grabs 1k of RMA - this will eventually lead to a system crash. Detection methods Media : Hunter 1.00+, Killer 1.17+, VKiller 1.00+, VProtect 1.06+ Memory : Interferon 2.00+, Killer 1.17+, VKiller 1.10+ Removal instructions Media : Killer 1.17+, VKiller 1.00+, delete named file, remove extra instructions from !Boot. Memory : Killer 1.17+, VKiller 1.10+ General comments It's a module which can go under 8 different filenames (the name is picked at random using the current time as a seed): MonitorRM, CheckMod, ExtendRM, OSextend, ColourRM, Fastmod, CodeRM or MemRM. Nowever, the module itself has the following title string: Extend 1.56 (08 Jul 1989) hence is always known as "Extend" in the module list. For reference purposes, I shall refer to it as the "Extend Virus". It is 940 (&3AC) bytes long and initialises itself as a nameless Wimp task which then looks for Wimp Message 5 (double-click). It attempts to either create an !Boot in the application directory or append to an already existing one with the following lines: IconSprites .!Sprites [0D] RMEnsure Extend 0 RMRun .ModName [0D] ||[FF] The "IconSprites" line is omitted if it is appended to an existing !Boot. "ModName" is one of the 8 possible filenames. The Extend Virus uses the &FF (i.e. decimal 255) byte at the end as a self-check to see if has infected the !Boot file already. Of course, it copies itself to the new name inside the application directory as you would expect. Note the incorrect use of &0D (decimal 13) to terminate the lines, rather than the more correct &0A (decimal 10). A shift-double-click does NOT cause an infection, but it DOES claim yet another 1K of never-to-be-released RMA. There is no damage apart from the claiming of RMA (which will eventually lead to a system crash). (Source: Richard K. Lloyd) --------------------------------------------------------------------------- Virus name : Icon Aliases : Icon-A, Filer, Poison, NewVirus Origin : United Kingdom Isolation date : 1990? Effective length : 2096, 2616, 5498, 5574, 5737 or 5742 in known variants Virus type : Task. Stores code as separate file. Symptoms : Nameless wimp task on the Task Manager. Silly error messages MAY appear without reason. The files "Icon", "Poison" or "NewVirus" in application directories. Detection methods Media : Hunter 1.00+ (note 1), IVSearch 2.05+ (note 2), Killer 1.17+, VKiller 2.30+, VProtect 1.06+ Memory : Killer 1.17+ Removal instructions Media : Killer 1.17+, VKiller 2.30+, delete named file, remove extra instructions from !Boot. Memory : Killer 1.17+ Note 1: Will not detect the 2096 and 5737 byte variants Note 2: Will not detect the 2096 and 5737 byte variants General comments The Icon virus family is a type of very contagious viruses. They are harmless in that extent that they do not destroy files. However, they are annoying (although I must admit some of the messages were quite amusing!). Common for all the viruses in the Icon family is that the virus is an un- named wimp task written in BASIC. It spreads by adding a few lines to the !Boot file of an application (without checking for multiple infections), and then saving the code as a spritefile. BASIC -quit . The original virus displayed a stupid error message on start-up, and then every so often after that. Commonly also called the Filer virus as the error message header claims that it's from the Filer. Here are a few examples of what type of error messages which might appear: ".desreveR maertS tuptuO" "This error should not occur." "Previous error did not occur." "Could not reach top of stack." Known variant(s) of the Icon virus are: 2096 (filename: Poison) Random error code replaced with a *I am stuck - which might log the user on to a network if they're very unfortunate! 2616 (filename: Icon) No silly messages from this version - also has the name of the person who modified it (yes, the UK Computer Crimes Unit have acted on this!). 5498 (filename: Icon) (Though the in-core name is 'Extra') Does have silly messages. 5574 (filename: Icon) As 5498 with missing Hourglass_On call added. Silly message less likely to appear when it is loaded. 5737 (filename: NewVirus) As 5574, but with a three-key sequence to exit the program. High liklihood of a silly error at startup. Insignificant changes to !Boot save routine. 5742 (filename: Icon) Bugfix of 5737. Less likely to give silly errors when loaded. (Source: Alan Glover) --------------------------------------------------------------------------- Virus name : Image Aliases : Origin : Northern Ireland? Isolation date : January 1992 Effective length : 512 bytes Virus type : Resident, although not in RMA. Symptoms : Files "Image" and "!Spr" in application directories. The file "Image" has no filetype, but "!Spr" has the type Obey. Detection methods Media : Killer 1.26+, Scanner 1.13+, VProtect 1.07+ Memory : Killer 1.26+ Removal instructions Media : Killer 1.26+, Scanner 1.15+, delete "Image". If there is a "!Spr" file, delete !Run and rename "!Spr" to !Run - otherwise delete !Boot. Memory : Killer 1.26+ General comments This virus has no payload, but spreads VERY fast, to the extent that you can delete the file, only to see it instantly re-appear again if it is in memory! It loads in OS workspace, at &5500, it is therefore liable to crash the machine should the OS use that area of workspace. The !Run or !Boot file looks like this: LOAD .IMAGE 5500[0d]GO 5500[0d] It's action on infection is to save .Image, and then either to create a !Boot file if one does not exist, or if it does, rename the !Run file to !Spr and then create a new !Run file. (Sources: Alan Glover, Svlad Cjelli) --------------------------------------------------------------------------- Virus name : Link Aliases : Origin : United Kingdom Isolation date : January 10, 1992 Effective length : 1416 bytes Virus type : Resident Absolute file infector. A Trojan Horse. Symptoms : Module 'BSToDel' in module list. Detection methods Media : Killer 1.27+, Scanner 1.03+ Memory : Killer 1.27+ Removal instructions Media : Killer 1.27+, Scanner 1.06+ Memory : Killer 1.27+ General comments The reason why I found the Link virus was because of the module "BSToDel" appearing in the module list. As I already have made my own "backspace to delete" utility as a module, I wondered where that module came from! (It certainly wasn't as a separate module on the disc.) As far as I can tell, here's what the virus does: Before installing itself as a module, it infects %.Squeeze (if there is a library directory, and if Squeeze is indeed in it) - just in case there wasn't enough room in the RMA. Then it hooks onto the FSControlV and InsV vectors. The latter so that it can do what the module title expects it to do: convert backspace (&08) to delete (&7F) (the reason why I also typed it as a Trojan Horse). The FSControl vector is used so that it can look for certain actions - namely *Run and *Copy. When it detects one of these, it does the following: Replaces the first three instructions in the file with its own, making an absolute branch to the end of the file. The rest of the module is then stored here, with the original three instructions too. To make detection a bit more difficult, it encrypts itself with an EOR variant (different key each time). On any Friday the 13th, it will display the message Message from LINK: Active since 30-Nov-91 every time it infects a program. [As Alan pointed out, this date is fixed, so meaning that it bears no releationship to the time which a system became infected.] The virus does no damage apart from attaching itself to files. Also, at the end of the module (and effectively each file - although encrypted) the word 'LINK' appears. I thought maybe this was used as an 'already infected' flag, but this is not so. What it does is check the second instruction in the file, and if this is 'MOV PC,R0' (probably reckons that few programs have this as their second instruction) it recognizes it as infected. If not, the file is infected. This method of checking the file might add to the difficulty of making an innoculator. Why didn't Interferon detect this virus? At first, I thought that there might be a bug in Interferon, but as I found out, the Link virus checks to see if Interferon is in memory by using OS_Module 18 (look-up module name). By doing this, it also finds where the module code is. Then, it changes a CMP instruction within the code so that Interferon never detects OS_GBPB. After the infection is finished, the Link virus changes the code back to what it was. [I'm working on a CRC routine for a future version of Interferon at the moment, so Interferon should be 100% operational 'real soon now'.] --------------------------------------------------------------------------- Virus name : Module Aliases : Illegal, ModVir Origin : United Kingdom, most possibly. Isolation date : October 1991 Effective length : 956 bytes Virus type : Resident module infector. Symptoms : Modules grow by approx. 1k, and are date re-stamped. Might cause system crashes when accessing files (load, save, etc.). Detection methods Media : Hunter 1.00+, Killer 1.26+, Scanner 1.14+, VProtect 1.10+ Memory : Hunter 1.00+, Interferon 2.00+, Killer 1.26+ Removal instructions Media : Hunter 1.00+, Killer 1.26+ Memory : Hunter 1.00+, Killer 1.26+ General comments This is a very nicely written virus which appends itself to modules, redirecting three module entry points to pass through itself before being handed on to the module's original entry point. It spreads by infecting a module as it is loaded, and then the newly loaded module infects the next one loaded, and so on... This virus is likely to be very widespread, since it was distributed on the Archimedes World February 1992 cover disc in the MicroDrive demo (in it, several modules were infected). It does nothing until 6th September 1992, when it will display the message: Your computer has been virus infected. This is intended to be a friendly virus, and hasn't done any damage to your disc as is possible now, but it isn't active anymore from now on. Be more careful with illegal software next time! [Along with a generation counter. Another interresting observation is that it does not infect locked modules. Infects whenever it notices a RUN or LOAD action on a module. THIS VIRUS IS EXTREMELY CONTAGIOUS.] The message that it isn't active anymore is not true! It ALWAYS (even after 06-Sep-1992) attaches itself to the OS_File (FileV) vector. If you load a module (filetype &FFA) with OS_File,255 the virus does the following: First calls the previous owner of the OS_File vector (FileSwitch I think). This means that the module will be loaded and initialised. If the length of the module minus the initialise word of the module is equal to 956 (i.e. the length of the virus), then the module is already infected and the virus deactivates itself (the newly loaded module has already attached itself to the OS_File vector). If the module isn't infected, the virus attaches itself at the end of the module, overwriting the init/finit/service words in the module header (the original 3 words are preserved). (Source: Alan Glover, Michel Fasen) --------------------------------------------------------------------------- Virus name : MyMod Aliases : Silicon Herpes Origin : United Kingdom Isolation date : June-August 1991 Effective length : 2948 Bytes Virus type : Resident Symptoms : Additional files "SSLM" (filetype Module) and "SSLF" in application directories. Message on every Friday the 13th. Detection methods Media : Killer 1.17+, Scanner 1.15+, VProtect 1.10+ Memory : Interferon 2.00+, Killer 1.17+ Removal instructions Media : Killer 1.17+, Scanner 1.16+, delete "SSLM", rename "SSLF" to !Boot. Memory : Killer 1.17+ General comments This works by redirecting the Alias$@RunType for Obey files, so spreads very fast. Once on each Friday 13th you'll get this message: Hi there. It's me, with my latest addition to the ARCHIMEDIES range of computer programs. This one's called silicon herpes. It's annoying but DOES NO REAL DAMAGE!!! Anyway, it's Friday the 13th, and what can you expect. Acorn state that RISC OS has high protection against programs of this nature. I can't call it a virus, as a virus does damage With Acorn making these bold statements about RISC OS I decided to write a demonstration to disprove their theories. I must admit though, it was quite difficult. Anyway, I don't want to keep you so I'd like to say, have a very happy Christmas, Easter, Summer or what ever, and hang kickin There's a likelihood of various spurious errors from one of the variants (both are the same length) since it addresses application memory directly! (Source: Alan Glover) --------------------------------------------------------------------------- Virus name : NetManager (close relative to TrapHandler) Aliases : Origin : United Kingdom Isolation date : June-August 1991 Effective length : 900 Bytes Virus type : Resident !Boot file infector. Symptoms : Module 'NetManager' in module list. Detection methods Media : Killer 1.17+, VProtect 1.10+ Memory : Interferon 2.00+, Killer 1.17+ Removal instructions Media : Killer 1.17+, delete !Boot. Memory : Killer 1.17+, RMKill NetManager. General comments I (Alan Glover, Acorn) believe this to be the prototype for, or maybe the inspiration for, the TrapHandler virus. Although the coding is quite different in places, there's quite a similarity in the design. There are a number of coding errors in this, most notably around the time bomb area, making it harmless in this form. The intention of the code is to check for Friday 13th, and display a message, however it will never detonate (... unless there's a fixed version in circulation ... though that's what I believe TrapHandler is). It's fortunate that it never displays the message, because there's another coding error and the message isn't actually there! (Source: Alan Glover) --------------------------------------------------------------------------- Virus name : NetStatus Aliases : Boot Origin : Either Norway or Belgium. Isolation date : October 1991 Effective length : 2072 bytes Virus type : Resident !Boot file infector. Symptoms : !Boot filelength increase. Detection methods Media : Killer 1.27+, Scanner 1.02+, VirusKill 1.00+, VProtect 1.10+ Memory : Interferon 1.10+, Killer 1.27+ Removal instructions Media : Killer 1.27+, Scanner 1.02+, VirusKill 1.00+ Memory : Interferon 1.10+, Killer 1.27+, RMKill NetStatus. General comments NetStatus is written as a module, and in many ways it functions exactly the same way as the TrapHandler virus, as it saves all of its code in an application's !Boot file. It differs strongly from TrapHandler, however, as it does not overwrite the !Boot file. The original !Boot instructions are executed after the virus has been loaded, making it more difficult to spot than TrapHandler. Some times a message will appear (the screen goes black first): [This message is encrypted, and will neither show up in memory nor in the infected !Boot file.] Hello, there. Just a little message. The infection count is: This program is harmless 10 Jun 1991 And disassembly proves the program right - it does not do anything harmful. One might think that NetStatus should be placed as a 'variant' of TrapHandler, as the way the two viruses work are so similar (both viruses work by loading the !Boot file into memory below &8000 and then jumping to the code). However, seeing that the code itself was so different, I chose to let it have it's own entry. Also, NetStatus infects the !Boot file instead of overwriting it! If you think you might have been infected by this virus, do *Help NetStatus to see if it is version 2.00, and if it is, do a *Modules to check where it resides. If the address is 018xxxxx then you are infected, if not, the address should be 038xxxxx. This virus has the potential to cause chaos on Econet (tm) networks, where it will replace the real NetStatus module - causing anything that relies on it to fail. --------------------------------------------------------------------------- Virus name : Parasite Aliases : Origin : UK, Cheshire ? Isolation date : February 1992 Effective length : 6435 (strain 1), 7252 (strain 2) Virus type : Resident !Boot/!Run file infector, stores code as separate file. Symptoms : Additional modules appearing within applications Detection methods Media : Killer 1.27+, VProtect 1.12+ Memory : Killer 1.27+ Removal Instructions Media : Killer 1.27+ Memory : Killer 1.27+ General comments This is a **very** nasty virus. Handle any infections with care! The two strains are identical, except that the first always uses the same name for it's module, and the second has a random choice of 20 (twenty) filenames. It will only activate on machines whose network station number is <80 - which will include non-networked machines, which typically have 0 or 1 in the CMOS. Do NOT try to RMKill the module - a delayed action machine crash will result. It will *wipe any of the following file/directory names - !vkiller, vir, shield, prot and !guardian - this points at a UK origin since it is not aware of !Scanner. It has a whole repertoire of dirty tricks, which are time triggered: - Corruption of the net printer name (it uses this as workspace) - Midnight, and xx:13: crash the computer - Before 07:00: crash the computer 300-900 seconds later - 00:00 to 00:59 on 1st Jan: crash the computer - 1st of any month: claim 16K of RMA (not used) - 21st June: set MouseStep to 1 - 21st December: set MouseStep to 127 (fast!) - 29th February: Set MouseStep to -5 (fast, and reversed) - If there is a 0 in the time, and the virus loaded from SCSI: *unplug the Podule Manager (disabling the SCSI disc) - At 0x and x0 seconds, if the module came from IDEFS: alias the IconSprites command so no further sprites are cached Furthermore, there are some which can be fired at any time: 1 in 50: Change sound settings 1 in 25: Redefine character set to all spaces after 60-240 seconds 1 in 60: Corrupt the disc in drive 0 Lastly, there are a group of serious actions (which are limited so only a certain number occur within a given period) - Before 08:00 (14:00 Sundays): configure number of hard and floppy drives to zero. - Mondays: Configure Fontsize 0K, SpriteSize 512K, which will cripple a 1Mb machine! - 25th December: Configure MonitorType 3, Sync 0 - A 7 in the time: Configure Country to Greece - 1 in 4: Configure ADFS, Harddiscs 2, Drive 5 (very tricky if you don't happen to have two ST506 drives) The module names which it can use are: FontLibrary, CodeLibrary, ScreenObjct, PromptsPick, HPIBIntMngr, PRomModules, BasicCryptr, ChrSelecter, WimpModMake, PaletteUtl2, ModeUtility, FontUtility, TempManager, ColourConvt, IndexReader, ArthurImage, SyncUtility, VIDCManager, FontPalette, HugoFiennes. (The first strain always uses the name FontLibrary) (Note that Hugo Fiennes, whose name appears at several points in the code, as well as being one of the module filenames, has much better things to do than write viruses, and has no known connection with this virus!) (Source: Alan Glover, with thanks to Geoff Riley for much of the decoding) --------------------------------------------------------------------------- Virus name : Sprite Aliases : 'Really Annoying Sprite Virus' Origin : Germany ? Ireland ? Isolation date : February 1992 Effective length : 720 bytes Virus type : Resident !Boot/!Run file infector, stores code as separate file. Symptoms : File "Sprite" and maybe !Str in applications Detection method Media : Killer 1.27+ Memory : Killer 1.27+ Removal instructions Media : Killer 1.27+, delete Sprite, delete !Boot *OR* delete !Run and rename !Str to !Run (depending whether !Str is present) Memory : Killer 1.17+ General comments This has got some similarities with Image, but until I've (Alan) had a chance to do a code comparison, I'm not going to class them as members of the same virus family In months which begin with an F it will change the pointer settings. As far as I can tell, the parameter block is junk, and it's hard to tell whether the call will return! If it does, a delayed routine is programmed, which when entered will do FX200,3, zero all the CMOS RAM, and display a message. The message is: Piracy IS theft - Your SYSTEM is DOOMED - Deutschland Uber Alles! For people like me who don't know any German, a liberal translation is 'Germany is best'. This is encrypted, so is not usually visible. Important note: Initial reports about this virus suggested that it could cause disc corruption. Aside from possible errors during attempted infections, it does not have any maliciously targetted code for filing systems. Infection is by saving the virus code as 'Sprite' (filetyped as such), and either creating a !Boot, or renaming !Run to !Str and saving a new !Run which runs !Str. (Source: Alan Glover, with thanks to Svlad Cjelli) --------------------------------------------------------------------------- Virus name : Thanatos Aliases : RISCOSext, RISCOS Extentions Origin : United Kingdom Isolation date : May 1991 Effective length : 11756 bytes Virus type : Task. Stores code as separate file. Symptoms : Files "RISCOSext" and "TaskAlloc" in application directories. Wimp task "Thanatos" visible in the Task Manager. Detection method Media : Killer 1.17+, VKiller 2.30+, VProtect 1.10+ Memory : Killer 1.17+ Removal instructions Media : Killer 1.17+, VKiller 2.30+, delete named files. Memory : Killer 1.17+ General comments This is an encrypted (simple EOR with &7A, lower-case "z") BASIC program (crypted = 11756 (&2DEC) bytes long, TOP-PAGE of BASIC program = 7660 (&1DEC) bytes) called "RISCOSext" with a filetype of Absolute (yes, a very poor piece of ARM code decrypts and runs it and wastes nearly 4K of space between &8100 and &9000 !). Associated with it is a Sprite file (actually of filetype Module) called "TaskAlloc", which is 344 bytes long containing a rude sprite to replace the mouse pointer.. When run, it installs itself as a Wimp task named "Thanatos" and then looks for double-clicks to infect application directories (copies the RISCOSext and TaskAlloc files into there and then appends the 'usual' string to the !Boot file (to run RISCOSext). The nasty section of the Thanatos Virus REALLY IS nasty, so I urge you to study this carefully. Here's a list of things that can happen: Rough once every 100000 times around the Wimp_Poll loop, Thanatos can: * 2 out of 13 chances: Shut down icon bar application at random (whilst displaying its own icon bar icon during the shutdown). * 1 out of 13 chances: Cause a Desktop Quit. * 3 out of 13 chances: Reverse the mouse pointer step (sets it -2). * 1 out of 13 chances: Crash the machine by poking a duff instr at the start of memory. * 1 out of 13 chances: Randomise the 240 bytes of CMOS. * 4 out of 13 chances: Randomly display one of 8 very rude messages - one of which also changes the mouse pointer shape to a rude graphic and another will also shutdown an icon bar application (the same routine as above). * 1 out of 13 chances: Wipe the contents of . It also has a "special date" section as follows: Any Friday 13th: Advertises its own "virus killer" (from Armen Software). April 1st: 10 Address exception errors, followed by coloured rectangles and a 'stuck' mouse pointer for 10 seconds. An "April Fool" message is then displayed. December 25th: Destroys the disk map of ADFS drives 0, 4 and 5 followed by a "Merry Chrimble" message. October 31st: Formats the floppy in drive 0, followed by a "Spooky" message. January 1st: As December 25th, but followed by a New Year's Resolution message (to keep your disks write-protected :-( ). [Trying to kill it from the Desktop does *not* work, however VKiller and Killer can remove it from memory. Also, Thanatos will not initialise if Sys$Path is defined - which is useful for keeping it out of memory if an infection is discovered.] (Source: Richard K. Lloyd, Alan Glover) --------------------------------------------------------------------------- Virus name : TrapHandler Aliases : Origin : United Kingdom Isolation date : September, 1991 Effective length : 924 bytes Virus type : Resident !Boot file infector. Overwrites original !Boot file completely (or creates a new one if it doesn't find one) and stores own code here. Symptoms : Applications which depend on a !Boot file fail to run (i.e. if the !System !Boot file was overwritten, !Edit would fail to run due to the fact that the !System folder hasn't been seen. The same applies if the !Boot file in the !Fonts directory is overwritten. The module 'TrapHandler' is present in the module list. Detection method Media : Killer 1.17+, Scanner 1.03+, VProtect 1.10+ Memory : Interferon 2.00+, Killer 1.17+ Removal instructions Media : Killer 1.17+, Scanner 1.03+, delete !Boot file. Memory : Killer 1.17+, RMKill TrapHandler. General comments The TrapHandler virus is written as a module which infects application directories by overwriting the !Boot file with its own code. By hooking onto the FSControl vector, it looks for a *Run action, and on finding one (eg. the user opens a directory with applications, and if any of these contain a !Boot file (which RISC OS automatically executes)), TrapHandler overwrites the application's !Boot file with its own code. This code is loaded into memory by using a simple *LOAD .!Boot
and then executing the code from there using a *GO
command. On any Friday after the 20th of any month it will open a regular message box (i.e. using Wimp_ReportError) with the number of infections in the header, and an 'Ignorance will be your undoing.' This message is rather misleading, as the only destructive thing it does is overwrite your !Boot files (although it could - as all viruses can - be modified to do much nastier things). I might sound a bit trivial here - if your $.!Boot on the harddisc was overwritten, you might be a bit more than annoyed. However, as this !Boot file only gets run when you reset your machine, it is not very likely to get infected by this virus. --------------------------------------------------------------------------- Virus name : Vigay virus Aliases : DataDQM, Shakes Origin : United Kingdom Isolation date : Probably April 1991. Effective length : 2311 or 2432 bytes Virus type : Task. Stores code in separate file. Symptoms : File "DataDQM" in application directories. The Task "TaskManager" in the Task Manager window. Detection method Media : Killer 1.17+, VKiller 2.20+, VProtect 1.10+ Memory : Killer 1.17+, VKiller 2.20+ Removal instructions Media : Killer 1.17+, VKiller 2.20+, delete !Boot and file. Memory : Killer 1.17+, VKiller 2.20+ General comments This is a 2311-byte BASIC program called "datadqm" with an associated 97-byte !Boot file. The REMs at the start of the program are as follows: REM (C)1989 PAUL VIGAY REM REM A nasty little Archie Virus !! REM ... or is something up with your monitor ??? REM REM version 1.1a (24th October 1989) Hence you now know why it's called the "Vigay Virus" - the author's name appears as a comment at the start! When first run, it initialises as an application task called "TaskManager" [unlike the real "Task Manager" wich is a module task] and then waits for either: 1) a chance of (500 * hours left of a Thursday) to 1 to crop up to spark off a silly "wobble" demo (wobbles the screen and mouse pointer). Yes, this demo only appears on a Thursday and more frequently as the day wears on. or: 2) a file/directory double-click, in which case it attempts to replicate itself to the first application directory at that level that doesn't already have either an !Boot or a datadqm file. (Source: Richard K. Lloyd) [Apparently there are several versions existing (but apparently not circulating), some activating on Fridays, others on Friday the 13th. There are also version compiled with the Archimedes Basic Compiler by Dabbs Press.] --------------------------------------------------------------------------- NOTE: This document is mainly distributed along with the utilities Scanner and Killer, although updates will appear separately if no new versions of these two utilities is released.