English Amiga Board

English Amiga Board (https://eab.abime.net/index.php)
-   AMR data problems (https://eab.abime.net/forumdisplay.php?f=83)
-   -   cu_1990_12_d008 has a virus? (https://eab.abime.net/showthread.php?t=29760)

musashi9 14 May 2007 02:21

cu_1990_12_d008 has a virus?
 
I downloaded this cover disk yesterday
cu_1990_12_d008.zip
and when looking at the sine intro at the start of the disk i popped into AR and seen this

pic
it only comes up when you have 512k chip only (no slow)

Galaxy 01 October 2008 14:32

Can anyone confirm that this is infected?

If so I'll remove the download.

redblade 03 October 2008 03:36

boot block seems clean, only seems to show up when the intro is run? could it be a saddam virus?

I think the "go" file or the intro is a virus.

A quick look under resource seems that the start code copies some memory to the end of chip ram(lost 1k on a 512k system), and plays with Kicktagptr, and Kickchecksum, that type of code doesn't seem normal in a demo.

Mind you I'm not a demo coder, VirusChecker 4.5 didn't pick up anything tho. It seems dodgy.

amitrev 03 October 2008 17:26

If my memory serves me correctly, I remember buying a CU Amiga magazine around this time and the cover disk was infected with a virus. They even printed an apology in the mag the next issue (and the funny thing was, I recall them putting a virus killer on the same disk as the virus itself).

Ok, curiosity got the better of me :-)

The issue I'm thinking of is CU Amiga August 1991. The coverdisk has a virus on the bootblock (RevBootLoad according to KDVIII). The virus scanner on the disk itself ironically doesn't detect the presence of a virus, just a non-standard bootblock :-) The September issue has KDVIII on there which detects it.

http://amr.abime.net/issue_73_coverdisks < The label on the Sept coverdisk specifically states "Wipe out the RevBoot virus and many more" :-)

For those of you with big juicy TOSEC collections and want to check it out for yourself, the disk is:

CU Amiga - Disk 016 (1991-08)(EMAP Images)(GB)[a].zip

Ahh good memories of this little fiasco :-)

OddbOd 04 October 2008 11:11

Quote:

Originally Posted by Galaxy (Post 463894)
Can anyone confirm that this is infected?

Yup, according to Virus Checker II (using the 03.10.1999 brainfile) it appears to be infected with something called Centurions, I took a memory snapshot while the intro was running and found this inside it:
Code:

????????>>>>>>>>>>@HI@THERE;;;@A@NEW@AGE@IN@VIRUS@MAKING@HAS@BEGUN;;;@THANX@TO@US>>>@THANX@TO:@===@CENTURIONS@===@@@AND@WE@HAVE@THE@PLEASURE@TO@INFORM@YOU@THAT@SOME@OF@YOUR@DISKS@ARE@INFECTED@BY@OUR@FIRST@MASTERPIECE@CALLED:@<@THE@SMILY@CANCER@<@@@HAVE@FUN@LOOKING@FOR@IT>>>@AND@STAY@TUNED@FOR@OUR@NEXT@PRODUCTIONS>@@@CENTURIONS:@THE@FUTURE@IS@NEAR;@@@@@@@@@@@@@@@@@@@@@@@......................................................................................................................................................................HELLO HACKERS OUT THERE!! A NEW FORCE HAS BORN IN ITALY:--- CENTURIONS ---. OUR TEAM IS COMPOSED OF 2 GUYZ: ME & HIM.(AHAHHA!) THE AIM OF -- CENTURIONS -- IS JUST VIRUS MAKING.. WE HAVE LOTTA FUN DOING THIS AND WE ALSO HOPE TO GIVE FUN TO THE KILLERS MAKERS (HI STEVE TIBBETT!) HAW! HAW! HAW! SIGNED: ME & HIM / CENTURIONS

kriz 04 October 2008 11:13

heheeh :)

Galaxy 04 October 2008 15:05

Ok the download has been removed. Does anyone have a clean copy of this disk?

OddbOd 04 October 2008 20:57

If nobody comes to the party with a fresh copy you might want to consider asking one of the experienced coders on here to clean up the existing executable, I have a feeling someone like Codetapper/Photon/Galahad/etc. could do it in their sleep.

Galaxy 04 October 2008 23:47

Yeah true, but I would rather post a clean unmodified copy if possible.

redblade 05 October 2008 04:03

Yep another viri to add to the collection.


All times are GMT +2. The time now is 05:30.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.

Page generated in 0.04349 seconds with 11 queries