Relay-Version: version B 2.10 5/3/83; site utzoo.UUCP Path: utzoo!mnetor!uunet!mcvax!unido!altger!boxdiger From: boxdiger@altger.UUCP Newsgroups: comp.sys.amiga Subject: Re: IMPORTANT WARNING ... Amiga Virus Lo - (nf) Message-ID: <15000002@altger.UUCP> Date: Mon, 19-Oct-87 17:42:00 EDT Article-I.D.: altger.15000002 Posted: Mon Oct 19 17:42:00 1987 Date-Received: Fri, 23-Oct-87 01:07:21 EDT References: <15589@amdahl.UUCP> Lines: 50 Nf-ID: #R:amdahl:15589:altger:15000002:000:2658 Nf-From: altger!boxdiger Oct 19 22:42:00 1987 How to handle with the SCA Virus -------------------------------- Ok guys, i'm living in Switzerland, where the Virus was programmed by a very honourable Amiga Wizard of the Swiss Cracking Association (I'm not a member of it....). Don't panic the Virus is very harmless and don't damage your Computer. Now, i will try to explain how it works. First, when the Bootblock is loaded into Ram the Virus is copied to $7ec00 (end of Chip Memory). Once there it changes the WarmCapture Pointer in the ExecBase so it will be called by hitting CTRL-AMIGA-AMIGA. Ok now the Virus resides in ur Amiga and waits for someone to reset. RESET: The Virus changes the Pointer of SendIO and returns to the originial Bootroutine. This Routine loads block 0 and 1 in memory using SendIO. Now the Virus writes himself to the Bootblock, destroying the old one (That's the only damage that it will do). After this the Virus increments a counter inside himself and after 15 infections it will come up with a nice message of the form: "Something wonderfull happened.. your Amiga is alive !!!.. and even better... some of your Disk are infected by a Virus... another masterpiece of the Megamighty SCA !!!". After this nice Text appearing sourrounded by a red border in the black screen the bootblock (the old one) will be executed (for his last time, if the this wasn't write protected.). That's all the Virus can do. The Virus is only dangerous in case of disks which needs the bootblock to load a programm without using Dos. Ok, i hope u don't be afraid of it any longer. But how to throw it out of our machine while running. This is very simple. Just hold the left mousebutton down while resetting. If then the screen became green for a half second the Virus was in your computer and even better; is now desactivated. (by him- self of course..). The programmer of the Virus don't like to have it on every Disk .... ok that's all... I hope that nobody will use this idea to create a bad virus. <^_^> Patrick Guelat...... /\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\ \ French Name, living in Switzerland, using a german system / / \ \ Replies, questions and money to : / / \ \ ..mcvax!unido!altger!boxdiger or / / ..mcvax!unido!altger!althh!boxdiger \ \ ..altmail!altger!boxdiger / / \ \/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/