Pentagon Circle 3 Bootblock Virus - Amiga Virus Encyclopedia


     Amiga Virus Encyclopedia    
     Pentagon Circle 3 Bootblock Virus 

     Name         : Pentagon Circle 3

     Aliases      : Pentagon Circle 2

     Type         : Bootblock
     Size         : 1024 bytes

     Symptoms     : No Sypmtoms

     Discovered   : -

     Way to infect: Boot infection

     Rating       : Harmless

     Kickstarts   : 2.0

     Damage       : Overwrites Bootblock
     Vectors      : Kicktag, Kickchecksum, DOIO und Coolcapture     

     Removal      : Kickstart 1.2 & 1.3 : VT-Schutz v3.17
                    Kickstart all others: VirusZ III v1.04ß or higher, and also Xvs.library v33.47 or higher

     Visible text : Contact: DAC-CPS, Vildrosg.23, 44254 Kungalv, SWEDEN
                    BOOT FROM MENORY:   LEFT: Yes please!    RIGHT: No thanks!
                    The Pentagon VirusSlayer 2 by Mr.Mountainlake
                    UNKNOWN bootblock!  Might be a virus!!!
                    LEFT: Leave it      RIGHT: Replace it
     Comments     : This bootblock pretend to be a viruskiller for several viruses
                    like the old Northstar and Byte Bandit viruses.

                    It will copy its code to $7fb00 (direct without allocating it)
                    and tests its existence in memory only by  checking a longword
                    at $7fbXX.

                    If a  bootblock access was detected,  it will  search for some
                    longwords (very unsecure) and if a virus was found, it will be
                    tried to overwrite the bootblock with the own code.

                    No tricky stuff, no crapted routine. A virus from the old time 

     Test made by : Markus Schmall & Jan Andersen, Virus Help Team  

     Ascii of Pentagon Circle 3 virus:


Virum Help Team
Denmark & Canada
Copyright © All rights reserved