Following is a short listing of all the known ST viruses and any information known about them. For a comprehensive Virus Killer which deals with all of these (and more), check out Sewer Utilities Disk Number 3, which will be released very soon. ------------THE KNOWN VIRUSES AND THEIR SYMPTOMS-------------- This is a systematic description of all viruses that are recognized by the Atari Virus Killer. The 'discovery date' that is mentioned is the actual date on which the virus was first documented to be seen as far as I know. Between brackets, the person who discovered it is mentioned - when known. BOOTSECTOR VIRUSES Virus #1 Name: Signum/BPL Virus Discovery date: November 22nd 1987 (Klaus Seligmann) Symptoms: Copies itself to other disks. Checks for code; when this is found the bootcode in that disk is executed. This has not yet been seen. Remark: This is the most widely spread virus; an approximate estimate brings it to 1.5 million copies worldwide! Virus #2 Name: Mad Virus Discovery date: March 26th 1988 (Eerk Hofmeester) Symptoms: Copies itself to other disks. When this is done five times, it starts fooling around with the screen or bleeping with the soundchip. Remark: A relatively harmless virus, therefore also sometimes referred to as 'FUN Virus'. Virus #3 Name: Mutant Signum/BPL virus Discovery date: Summer 1988 (Anton Raves) Symptoms: Disk on which the virus is present is unreadable due to a damaged BPB. Remark: This is no actual virus, but a virus that was corrupted while active in the system. Virus #4 Name: ACA Virus Discovery date: June 29th 1988 (Little Joe) Symptoms: Copies itself to other disks. When this is done 10 times, the virus clears track 0 (BPB and FATs) of the disk. Data is then unrecoverably lost. Remark: This virus is made by the ACA crew from Sweden (telephone number (Sweden) 0300/63350). Virus #5 Name: Freeze Virus Discovery date: July 12th 1988 (Carsten Frischkorn) Symptoms: Copies itself to other disks each time the directory (logical sector 11) is accessed. Right from loading on, it starts slowing down your system more and more, until it freezes. Virus #6 Name: Screen Virus Discovery date: July 12th 1988 (Carsten Frischkorn) Symptoms: Copies itself to other disks, but not to executable ones. Blackens the screen after a specific time. Remark: Only works on 02.06.1986 ROMs (German pre-blitter TOS). Virus #7 Name: C'T Virus Discovery date: Summer 1988 (Wim Nottroth) Symptoms: Can also copy itself to harddisk due to an undocumented value of the Bios Rwabs call. Resetproof. When it gets active (date stamp is 1987), it deletes the FATs of both your floppy-and harddisk - all data is then irretrievably lost! Remark: This virus was featured in a German magazine called "Computer & Technik". The author claims he 'found it' on one of his disks. A listing was included, so that people could reproduce and adapt the virus with ease. It writes the message "ARRRGGGHHH Diskvirus hat wieder zugeschlagen" on the screen when it is activated. Virus #8 Name: Maulwurf I Virus, English TOS version Discovery date: September 3rd 1988 (Joerg Kruse) Symptoms: Copies itself to other disks. When the VBL or Get_bpb system variables are changed it becomes active. It then puts the message "Maulwurf I - SSG (Subversive Software Group)" on the screen and locks up your system. It's reset-proof. Remark: This virus was made by the Subversive Software Group in Germany. Virus #9 Name: Bayerische Hacker Post (BHP) Virus Discovery date: September 10th 1988 (Henrik Alt) Symptoms: Multiplies itself to other disks. No other effects. Remark: Made by the Bayerische Hacker Post. This is a small computer user's group in Germany that also publishes a small club magazine. In that magazine, the virus was said to reset- proof, and that it would write through the write-protect notch (haha!). None if this is true. Virus #10 Name: Lab-Virus Discovery date: September 10th 1988 (Henrik Alt) Symptoms: Multiplies itself to other disks. When this is done 10 times, everything goes on as usual but the screen is blackened. Remark: This virus is an adapted version of the BHP virus. Virus #11 Name: FAT-Virus Discovery date: May 1st 1988 (George Woodside) Symptoms: Multiplies itself to other disks, except when they're already executable. It uses time delays to make it more difficult to detect. After a while, it starts to randomly access memory - this can create memory errors and bombs, or memory contents to be corrupted. A typical symptom: Blots appearing on your screen randomly. It only works on 02-06-1986 ROMs (German pre-blitter TOS). Remark: This virus spreads easily and rapidly. It is bigger than just one bootsector and also uses the last FAT sector to write itself on. It is probably made in Switserland, and is also called "Swiss"-or "Blot"-virus. Virus #12 Name: Ghost Virus Discovery date: November 20th 1988 (Carmen Brunner) Symptoms: Copies itself to other disks. After copying itself 10 times, this virus inverts the mouse Y directions. Supposed to be made by someone called Pash in Doncaster, England. Probably reset-proof. Remark: This virus is very widely spread (England, Sweden, Holland, West Germany). It is also called "Mouse" virus. Virus #13 Name: 5th Generation Virus Discovery date: December 6th 1988 Symptoms: Copies itself to other disks whenever the Bios Rwabs function is called (watch it: The Xbios functions Flop_rd and Flop_wr also use this!), but only on drive A, and when the disk is not already executable. When the virus has reached its fifth generation, it writes trash in the first 34 sectors of the disk, lethally corrupting FAT-, bootsector- and directory- sectors. Virus #14 Name: Oli Virus Discovery date: December 10th 1988 Symptoms: Copies itself to other disks. It stops doing that after having done that 20 times. It also installs itself on harddisk! Remark: It is not exactly known what the virus does! It is reset- proof. Virus #15 Name: Maulwurf I Virus, German TOS version Discovery date: January 1st 1989 Symptoms and remark: See virus #8 Virus #16 Name: Kobold #2 Virus Discovery date: January 2nd 1989 Symptoms: Copies itself to other disk (?). This virus is programmed in a VERY DIFFICULT way (let's put the guy who did it in boiling lead!), and it is therefore not really known what it does. From Yugoslavia, a message reached me that this virus formats your harddisk... Actually, it only seems to copy to drive A. It only gets active after a second reset after having been installed. Remark: This virus is thought to be coming from Germany (it says "Kobold #2 Aktiv", which is German). It is reset-proof. Virus #17 Name: Mutant MAD Virus Discovery date: January 1989 (Frits Couwenberg) Symptoms: See virus #2 Remark: Some of the last screen fiddle/sound routines in this virus have been corrupted by alien code. It will therefore crash when these routines are executed. Virus #18 Name: First Mutant Antivirus #1 Discovery date: January 28th 1989 Symptoms: Copies itself to other disks (except when they're executable). Some of the latter half of its code is corrupted by alien code, however, and may/will result in a system crash. Remark: Read further for more info about anti-viruses. Virus #19 Name: Goblin Virus Discovery date: April 3rd 1989 (Clive Duberley) Symptoms: Copies itself to other disks. It does something with the disk buffer and the screen, so may corrupt random disk data. Contains the screen message "The Green Goblins Strike Again". Remark: Not exactly analyzed so far. Probably made in England. Virus #20 Name: Second Mutant Antivirus #1 Discovery Date: March 6th 1989 (Thomas Gathen) Symptoms: System crashes, mainly. This is just a gigantically busted antivirus #1, and really can't do anything decent. Most probably doesn't even multiply... Virus #21 Name: Counter Virus Discovery Date: May 1989 Symptoms: Copies itself to drive A and B. Keeps a generation counter, but doesn't do anything more. Virus #22 Name: Help Virus Discovery date: September 1988 Symptoms: This is no real virus, because it cannot multiply itself without help. During booting, the screen is filled with bombs. Remark: No real virus, but it remains in the bootsector and does something that users don't like. Virus #23 Name: Random Virus Discovery date: September 1988 Symptoms: A virus that is not resetproof and that copies itself to A and B. Sometimes (when harddisk/RAMdisk installe) it doesn't work at all. After a couple of disk changes, some random values are written into memory at random locations. This causes crashes to occur. Virus #24 Name: Gauweiler Virus Discovery date: May 1989 Symptoms: Installs itself in memory. It is resetproof and gets active after the first reset. Writes the text "AIDS - Gauweilers Rache" on the screen of your monitor. LINK VIRUSES Virus #1 Name: Milzbrand Discovery date: Spring 1988 (Wim Nottroth) Symptoms: When the date stamp is set to 1987, it clears track 0 of your floppy disk, destroying all FAT data and filling the bootsector with a message "Dies ist ein Virus!" ("This is a virus!"). Symptoms can vary because the virus was offered as a, fully documented, type-in-listing (!) in the German mag "Computer & Technik" and the reader could easily adapt the routines himself. Remark: This virus was written by Eckhard Krabel, who lives in Berlin, Germany. Virus #2 Name: Virus Construction Set Part II Discovery date: October 1988 (Frank Lemmen) Symptoms: These vary from the message "You have ten seconds to find out how to prevent a reset" (after which a countdown follows and a reset) to routines that can be written by the user himself - the "Virus Construction Set" is a program with which the user can create his own viruses! Symptoms are therefore without limit! Remark: The "Virus Construction Set Part II" was published by a company in Bad Soden, Germany. It is now not sold anymore. Virus #3 Name: Uluru Discovery date: November 1988 Symptoms: Not precisely known, but it is said to attach itself to "1st Word"/"1st Word Plus" and randomly corrupt documents when working with an infected version of the program. It is not even known when it exactly multiplies itself. Virus #4 Name: Papa & Garfield Discovery date: November 1988 Symptoms: This is a reset-proof virus, that installs itself in memory when an infected program is loaded. After that, every other program that is loaded into memory is infected. It can be recognized by a flashing pixel in the left top corner of the screen and the message "Garfield and Papa was here", preceeded by a bleep sound. Remark: Probably only works on one megabyte machines (or higher) since it uses the absolute screen address $F8000. Virus #5 Name: Crash Discovery Date: March 20th 1989 (Claus-Peter Moeller) Symptoms: A reset-proof virus, that also installs itself in your system and then infects every program you load in afterwards. It is not exactly known what it does, but it probably crashed your system after a specific number of copies made. Remark: Probably programmed in Germany.