------------------------
Amiga Virus Encyclopedia
JITR Virus
------------------------
====== Computer Virus Catalog 1.2: JITR Virus (10-February-1991) =====
Entry...............: JITR Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: AUGUST 1990 (when VTC received virus copy)
where.: North Germany
Classification......: system virus (bootblock), resident
Length of Virus.....: 1. length on storage medium: 1024 byte
2. length in RAM : 1024 byte
--------------------- Preconditions ----------------------------------
Operating System(s).: AMIGA-DOS
Version/Release.....: 1.2/33.166, 1.2/33.180 and 1.3/34.20
Computer model(s)...: AMIGA 500, AMIGA 1000, AMIGA 2000A, AMIGA 2000B
--------------------- Attributes -------------------------------------
Easy Identification.: typical text: "JITR" at 3rd bootblock longword,
and "Copy count :", "I'm a safe virus! Dont
kill me! I want to travel! And now a joke :
ATARI ST This virus is a product of JITR"
at the end of bootblock
Type of infection...: self-identification method: testing 2nd longword
(=>bootblock checksum for matching own one);
system infection: RAM resident, reset resident,
bootblock
Infection Trigger...: every access to unprotected disks
Storage media affected: only floppy disks (3.5" and 5.25")
Interrupts hooked...: ---
Damage..............: permanent damage: overwriting bootblock
transient damage: ---
Damage Trigger......: permanent damage: every access to unprotected
disks
Particularities.....: a resident program using the CoolCaptureVector
is shutdown, DoIO is modified and points to
virus DoIO routine first;
JITR seems to be shortest AMIGA virus, occupying
only 498 byte of bootblock, though 1024 bytes
are allocated in RAM;
copy counter at offset $017A
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Names of tested products of Category 1-6:
Category 1: .2 Monitoring System Vectors:
CHECKVECTORS 2.3
.3 Monitoring System Areas:
CHECKVECTORS 2.3, GUARDIAN 1.2,
VIRUS-KILLER 1.1
Category 2: Alteration Detection: ---
Category 3: Eradication: CHECKVECTORS 2.2,
VIRUS-DETEKTOR 1.1
Category 4: Vaccine: ---
Category 5: Hardware Methods: ---
Category 6: Cryptographic Methods: ---
Countermeasures successful: CHECKVECTORS 2.2, GUARDIAN 1.2,
VIRUS-DETEKTOR 1.1
Standard means......: CHECKVECTORS 2.3
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Alfred Manthey Rojas
Documentation by....: Alfred Manthey Rojas
Date................: 10-February-1991
Information Source..: ---
===================== End of JITR Virus ==============================
Antivirus...........: Kickstart 1.2 & 1.3 : VT-Schutz v3.17
Kickstart all others: VirusZ III v1.04B or higher, and also Xvs.library v33.47 or higher
Ascii of JITR virus: