Pentagon Circle 2 Bootblock Virus - Amiga Virus Encyclopedia


     Amiga Virus Encyclopedia    
     Pentagon Circle 2 Bootblock Virus 

     Name         : Pentagon Circle 2

     Aliases      : Pentagon Circle 2 & Dynamix

     Type         : Bootblock
     Size         : 1024 bytes

     Symptoms     : No Sypmtoms

     Discovered   : -

     Way to infect: Boot infection

     Rating       : Harmless

     Kickstarts   : 2.0

     Damage       : Overwrites Bootblock
     Vectors      : Kicktag, Kickchecksum, DOIO und Coolcapture     

     Removal      : Kickstart 1.2 & 1.3 : VT-Schutz v3.17
                    Kickstart all others: VirusZ III v1.04ß or higher, and also Xvs.library v33.47 or higher

     Visible text : The Pentagon Circle VirusSlayer by Mr.Mountainlake!
                    Thanks to Onsala Sector for there help!
                    There is a VIRUS / Old AntiVirus on your disk!
                    Make it write-enabled & press RIGHT buttom
                    LEFT: Give control to it (NOO)   RIGHT: Kill it!
                    swapping: Onsala Sector,Ljungliden 21,43900 Onsala,Sweden
     Comments     : This bootblock pretend to be a viruskiller for several viruses
                    like the old Northstar and Byte Bandit viruses.

                    It will copy its code to $7fb00 (direct without allocating it)
                    and tests its existence in memory only by checking a longword
                    at $7fbXX.

                    If a bootblock access was detected, it will search for some
                    longwords (very unsecure) and if a virus was found, it will
                    be tried to overwrite the bootblock with the own code.

                    No tricky stuff, no crapted routine. A "virus" from the old

     Test made by : Markus Schmall & Jan Andersen, Virus Help Team  
     Screenshot of Pentagon Circle 2 Bootblock virus:

     Ascii of Pentagon Circle 2 virus:


Virum Help Team
Denmark & Canada
Copyright © All rights reserved