English Amiga Board


Go Back   English Amiga Board > Support > support.Other

 
 
Thread Tools
Old 13 December 2008, 20:36   #1
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Virus on disk?

Can somebody tell me, if the message in the attached screenshot is a clearly sign for a virus?
Unfortunately i have no other proggy to check it closer.
Is there a recommended tool and where to get?
Maybe such a tool is istalled with Amikit, but i am not able to find this.
Tell me please.

Last edited by mai; 05 February 2009 at 14:42.
mai is offline  
Old 13 December 2008, 23:55   #2
hit
Registered User
 
Join Date: Jun 2008
Location: planet earth
Posts: 1,115
never used this, but here you can read about it: http://www.psi5.com/~silva/afilter/#afilter

this plugin invokes a virusscanner, i guess AmiKit is installed this way.
back in the days i always used: http://aminet.net/package/util/virus/VT_Binary
hit is offline  
Old 14 December 2008, 01:40   #3
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Is this a real virus?

Last edited by mai; 05 February 2009 at 14:49.
mai is offline  
Old 14 December 2008, 07:43   #4
OddbOd
Registered User
 
Join Date: Jul 2005
Location: Australia
Age: 47
Posts: 666
Yes this disk is definitely infected with Liberator 5.01, all of the pv#? files in C: are copies of the virus and the startup-seuence has been changed.

Confirmed using Virus Checker II and by disassembling c/pvl.
OddbOd is offline  
Old 14 December 2008, 11:36   #5
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Thank you for the info,----bad info?
Is there any danger for Amikit startup, or is this a floppydisk virus only?
mai is offline  
Old 14 December 2008, 13:51   #6
hit
Registered User
 
Join Date: Jun 2008
Location: planet earth
Posts: 1,115
from the description site above, it replace "copy" with "delete" on your harddrive. scan the whole disk. let the virusscanner remove the infected files. and look at s:shell-startup and remove the lines, as described in the virus-description:
Quote:
;liberatorV - controlling me!
alias copy delete
alias delete "echo *"No file to delete, cant find*""
have a look at: http://aminet.net/package/util/virus/VT_DocFiles
VTTest3/Schutz/VT.Dokumente/VT.kennt_L-Z - describes what has to change back, after the machine got infected (s:startup-sequence and s:shell-startup).

Last edited by hit; 14 December 2008 at 14:04.
hit is offline  
Old 14 December 2008, 15:27   #7
OddbOd
Registered User
 
Join Date: Jul 2005
Location: Australia
Age: 47
Posts: 666
Quote:
Originally Posted by mai View Post
Thank you for the info,----bad info?
Is there any danger for Amikit startup, or is this a floppydisk virus only?
If the virus has been run while your Amikit volume was mounted then, yes, it could have been infected, assume it is and follow the instructions in the VT documentation from a cold boot. All of the files that get overwritten or modified can easily be replaced with clean copies once you are sure your system is disinfected.
OddbOd is offline  
Old 14 December 2008, 15:34   #8
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
I use "VirusZ III 1.02" and this tool dont recognize any virus in Amikit.
My system can only be infected, if i execute the virus, while Amikit is running, right?
mai is offline  
Old 14 December 2008, 16:53   #9
hit
Registered User
 
Join Date: Jun 2008
Location: planet earth
Posts: 1,115
thats correct. you have to start it, or the file has to be started during boot, from within startup-sequence (for example).
open s:shell-startup with a texteditor and look for these lines:
Quote:
;liberatorV - controlling me!
alias copy delete
alias delete "echo *"No file to delete, cant find*""
if you can't find them, then you are not infected. but it cant be wrong, to use a second virusscanner.
hit is offline  
Old 14 December 2008, 16:59   #10
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Quote:
Originally Posted by hit View Post
thats correct. you have to start it, or the file has to be started during boot, from within startup-sequence (for example).
open s:shell-startup with a texteditor and look for these lines:

if you can't find them, then you are not infected. but it cant be wrong, to use a second virusscanner.
Ah, thank you very much for the efforts, hit.
My system seems to be clean, i have never executed the virus.
mai is offline  
Old 14 December 2008, 20:06   #11
hit
Registered User
 
Join Date: Jun 2008
Location: planet earth
Posts: 1,115
you're welcome
hit is offline  
Old 27 December 2008, 12:56   #12
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Next virus

Antivirus software detects another virus, but i am not sure, if this is a real one.
I am not able to find any documetation about this virus.
This time its "SystemZ 6.5" bootblockvirus.
...adding screenshot, please tell me.

Last edited by mai; 29 October 2010 at 19:44.
mai is offline  
Old 27 December 2008, 13:30   #13
OddbOd
Registered User
 
Join Date: Jul 2005
Location: Australia
Age: 47
Posts: 666
Yes it's genuinely infected with both SystemZ and Saddam.
OddbOd is offline  
Old 27 December 2008, 15:39   #14
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Quote:
Originally Posted by OddbOd View Post
Yes it's genuinely infected with both SystemZ and Saddam.
Thank you for the information, OddbOd.
It was a little bit confusing, because in the bootblock i can read
something like "Boot Protector".
mai is offline  
Old 04 December 2009, 11:22   #15
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Suicide Machine amiga virus

It sounds very dangerouse!
I have seen the alert for this virus the first time, seems to be a rare one.
Maybe its not a real virus, something known about this virus?

screen:

Last edited by mai; 09 September 2019 at 23:13.
mai is offline  
Old 04 December 2009, 11:33   #16
Retro-Nerd
Missile Command Champion
 
Retro-Nerd's Avatar
 
Join Date: Aug 2005
Location: Germany
Age: 52
Posts: 12,460
http://www.vht-dk.dk/vhtdk/amiga/des...ax-suicide.htm
Retro-Nerd is offline  
Old 04 December 2009, 12:39   #17
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Quote:
Originally Posted by Retro-Nerd View Post
Thanks for the link, so its not very dangerouse.
mai is offline  
Old 11 August 2010, 19:19   #18
mai
Registered User
 
Join Date: Feb 2008
Location: Federativnaya Respublika Germaniya
Posts: 4,994
Maybe another rare one, but seems to be very dangerouse.
My AV program detects the TimeBomb v0.9 virus.
If you load the disk write enabled, the disk will be formated and you get this message:


Quote:
Hey Looser ! I hate you !
a real bad one.

Last edited by mai; 11 August 2010 at 21:08.
mai is offline  
Old 18 August 2010, 03:14   #19
sun68
Banned
 
Join Date: Dec 2008
Location: Germany
Posts: 68
What? The Time Bomb is not dangerous!

I have found LSD LinkVirus`s in one or more Files.

Is High Infected. The Virus is equal with Happy New Year Virus.

The HD at once (sofort) and fast with Virus Infected all EXE-Files on HD.

Mfg
sun68

P. S. Is on Deluxe Pacman (Version is Crap). Find Now!

Last edited by sun68; 18 August 2010 at 03:23.
sun68 is offline  
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Similar Threads
Thread Thread Starter Forum Replies Last Post
Possible new virus Crashdisk News 5 23 August 2012 20:25
Virus Stab Master support.Games 14 21 January 2011 18:07
T-Zero virus DDNI support.Games 11 30 March 2007 04:06
Virus Checker 8.03 Avanze request.Apps 1 02 October 2003 20:36
Possible Virus on WB Tonycrew Retrogaming General Discussion 4 13 June 2002 14:03

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 12:46.

Top

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Page generated in 0.09504 seconds with 13 queries