-------------------------
Amiga Virus Encyclopedia
Lamer 3.0 Virus
-------------------------
====== Computer Virus Catalog 1.2: LAMER 3.0 Virus (5-June-1990) ======
Entry...............: LAMER 3.0 Virus
Alias(es)...........: LAMER EXTERMINATOR 3.0 Virus
Virus Strain........: LAMER EXTERMINATOR Virus
Virus detected when.: October 1989
where.: Elmshorn, FRG
Classification......: system virus (bootblock), resident
Length of Virus.....: 1. length on storage medium: 1024 byte
2. length in RAM : 1024 byte
--------------------- Preconditions -----------------------------------
Operating System(s).: AMIGA-DOS
Version/Release.....: 1.2/33.166, 1.2/33.180, 1.3/34.5
Computer model(s)...: AMIGA 500, AMIGA 1000, AMIGA 2000A, AMIGA 2000B
--------------------- Attributes --------------------------------------
Easy Identification.: typical text: bootblock: ---
in memory: 'The LAMER Exterminator !!!'
Type of infection...: self-identification method: unknown yet
system infection: RAM resident, reset resident,
bootblock
Infection Trigger...: reset (CONTROL + Left-AMIGA + Right-AMIGA)
operation: any disk access
Storage media affected: floppy disks (3.5" and 5.25")
Interrupts hooked...: ---
Damage..............: permanent damage: overwrites bootblock;
overwrites blocks 2 and 3 where the old boot-
block is stored now, so uninstalled disks can
be infected; standard bootblock is shown when
examined with any tool by manipulating the
disk read pointer; fast formatting disks
transient damage: ---
Damage Trigger......: permanent damage: reset
operation: any disk access
transient damage: ---
Particularities.....: uses StartIOVector; other resident programs using
the system resident list (KickTagPointer,
KickMemPointer) are shut down;
virus has been posted in various trojan horse
programs (told by the author);
virus encodes itself every new infection.
Similarities........: LAMER EXTERMINATOR viruses
--------------------- Agents ------------------------------------------
Countermeasures.....: Names of tested products of Category 1-6:
Category 1: .2 Monitoring System Vectors:
'CHECKVECTORS 2.2'
.3 Monitoring System Areas:
'CHECKVECTORS 2.2','GUARDIAN 1.2',
'VIRUSX 4.0'
Category 2: Alteration Detection: ---
Category 3: Eradication: 'CHECKVECTORS 2.2',
'VIRUSX 4.0'
Category 4: Vaccine: ---
Category 5: Hardware Methods: ---
Category 6: Cryptographic Methods: ---
Countermeasures successful: without restrictions: 'CHECKVECTORS 2.2',
'VIRUSX 4.0'
with restrictions: 'GUARDIAN 1.2'
Standard means......: 'CHECKVECTORS 2.2'
--------------------- Acknowledgement ---------------------------------
Location............: Virus Test Center, University Hamburg, FRG
Classification by...: Alfred Manthey Rojas
Documentation by....: Alfred Manthey Rojas
Date................: 5-June-1990
Information Source..: ---
===================== End of LAMER (EXTERMINATOR) 3.0 Virus ===========
Antivirus...........: Kickstart 1.2 & 1.3 : VT-Schutz v3.17
Kickstart all others: VirusZ III v1.04B or higher, and also Xvs.library v33.47 or higher
Ascii of Lamer 3 Bootblock virus:
☣ |
Virum Help Team Denmark & Canada Copyright © All rights reserved www.vht.dk |
☣ |
| |