amiga.org
     
iconAll times are GMT -6. The time now is 07:28 AM. | Welcome to Forum, please register to access all of our features.

» Amiga.org » Amiga computer related discussion » Amiga Software Issues and Discussion » The Ebola Link Virus

Amiga Software Issues and Discussion This forum exists for the discussion of the use, issues with, and fun brought about by classic and next generation Amiga software.

Reply
 
Thread Tools Display Modes
Old 07-01-2012, 12:02 PM   #1
paul1981
Cult Member
Points: 4,167, Level: 41 Points: 4,167, Level: 41 Points: 4,167, Level: 41
Activity: 31% Activity: 31% Activity: 31%
 
paul1981's Avatar
 
Join Date: Nov 2009
Location: England
Posts: 610
Exclamation The Ebola Link Virus

Just a bit of advise to all Amiga users out there...

On my A600 I noticed things were sometimes crashing when before I had no crashes. Even trying to run the "Format" program to format a disk wouldn't work (came up with a recoverable software failure). And then in other cases, programs would work but then crash on exit (recoverable software failure).
I noticed something odd...in my '.deldir' on my PFS partition ('.recycled' if you run SFS) there were things in there which shouldn't be in there...things that I had not deleted... So there'd be my C command Assign in the .deldir, and another one in my C drawer (also a bit larger file size).
It confused me for a day or two, but eventually I installed VirusZ. It immediately found and removed the Ebola virus from memory....It then found around 40 infected files, mostly C commands, and also some Libs and handlers in L:. Clock, Format, some Commodities etc which it then continued to repair all files successfully. The virus made some other programs crash, despite those programs being uninfected. It even re-infected some XAD libs whilst doing the check if I remember correctly, so I had to run the check a few times to make sure the Virus had been totally killed.

I traced the source of the virus to something I downloaded last year from "Zeb's Amiga Downloads" website. It was Magic Workbench. I have a fully registered MagicWB disk, but I was setting up the harddrive in my A600 via WinUAE so it should have been easier this way. I then ran the Virus check on my WinUAE AmigaSYS 4 (what I had used to set up my A600 hard drive) and it found even more cases of the Ebola virus. Now I know why HDInst tools and HDtoolbox were crashing etc.

Fortunately, my main Amiga (1200) remained virus-free, despite all the stuff I have downloaded for it from similar sites over the years. Basically, everything I download now gets checked from within Voodoo-X (it uses the xvs.library) before I actually unarchive it to RAM or my hard drive. I've been lucky up to yet, but only just. If people have instability issues with their Amiga, the first thing I would advise now is to run a Virus scan.

I hope one day the xvs.library will be updated as it's now 8 years out of date. There's every possibility that new viruses are around right now, undetected by the out of date xvs.library. I seem to remember reading about a recent virus that attacks Emulated Amiga's (real Amiga's are safe!). So make sure you remain safe....virus check your adf's and your lha's etc before giving them residence on your system.
paul1981 is offline   Reply With Quote
Old 07-01-2012, 01:35 PM   #2
vox
Banned
Points: 3,344, Level: 35 Points: 3,344, Level: 35 Points: 3,344, Level: 35
Activity: 99% Activity: 99% Activity: 99%
 
Join Date: Feb 2011
Location: Belgrade, Serbia
Posts: 510
Blog Entries: 2
Send a message via Skype™ to vox
Default Re: The Ebola Link Virus

Quote:
Originally Posted by paul1981 View Post
Just a bit of advise to all Amiga users out there...

On my A600 I noticed things were sometimes crashing when before I had no crashes. Even trying to run the "Format" program to format a disk wouldn't work (came up with a recoverable software failure). And then in other cases, programs would work but then crash on exit (recoverable software failure).
I noticed something odd...in my '.deldir' on my PFS partition ('.recycled' if you run SFS) there were things in there which shouldn't be in there...things that I had not deleted... So there'd be my C command Assign in the .deldir, and another one in my C drawer (also a bit larger file size).
It confused me for a day or two, but eventually I installed VirusZ. It immediately found and removed the Ebola virus from memory....It then found around 40 infected files, mostly C commands, and also some Libs and handlers in L:. Clock, Format, some Commodities etc which it then continued to repair all files successfully. The virus made some other programs crash, despite those programs being uninfected. It even re-infected some XAD libs whilst doing the check if I remember correctly, so I had to run the check a few times to make sure the Virus had been totally killed.

I traced the source of the virus to something I downloaded last year from "Zeb's Amiga Downloads" website. It was Magic Workbench. I have a fully registered MagicWB disk, but I was setting up the harddrive in my A600 via WinUAE so it should have been easier this way. I then ran the Virus check on my WinUAE AmigaSYS 4 (what I had used to set up my A600 hard drive) and it found even more cases of the Ebola virus. Now I know why HDInst tools and HDtoolbox were crashing etc.

Fortunately, my main Amiga (1200) remained virus-free, despite all the stuff I have downloaded for it from similar sites over the years. Basically, everything I download now gets checked from within Voodoo-X (it uses the xvs.library) before I actually unarchive it to RAM or my hard drive. I've been lucky up to yet, but only just. If people have instability issues with their Amiga, the first thing I would advise now is to run a Virus scan.

I hope one day the xvs.library will be updated as it's now 8 years out of date. There's every possibility that new viruses are around right now, undetected by the out of date xvs.library. I seem to remember reading about a recent virus that attacks Emulated Amiga's (real Amiga's are safe!). So make sure you remain safe....virus check your adf's and your lha's etc before giving them residence on your system.
Interesting experience, I throught that XVS.library covers almost everything out there on Classics. Sadly, its no longer maintained and under OS4,MOS and AROS it has no purpose.
vox is offline   Reply With Quote
Old 07-01-2012, 02:45 PM   #3
k4lmp
Technoid
Points: 2,327, Level: 29 Points: 2,327, Level: 29 Points: 2,327, Level: 29
Activity: 14% Activity: 14% Activity: 14%
 
k4lmp's Avatar
 
Join Date: Apr 2012
Location: Church Hill, TN
Posts: 237
Default Re: The Ebola Link Virus

Thanks for the heads up. I recently installed MagicWB from the same site, and will be checking my A2000. Many thanks.

Jeff
__________________
A2000HD 6.2, 2 Mb Chip RAM, 3.1 KS
GVP GForce 030 SCSI Card 13Mb RAM
A2058 8Mb Fast RAM
SCSI CD-RW
Indivision ECS, MegaChip A2000
MultiFaceCard III, Alfa Data External Floppy & Trackball
MechWare Reader, WB3.1 w/ClassicWB Lite

A2000 6.2, 1 Mb Chip, 3.1 KS
A2630 2Mb RAM, SupraRAM 8Mb
GVP Impact A2000-HC SCSI Controller
A2232 Serial Card
MechWare Reader, WB3.1

A500+, 1.5 Mb Chip, 3.1 KS, 68010 CPU
GVP A500 HD+8 w/8Mb RAM
GBS-8200 RGB-VGA Converter
MechWare Reader, ClassicWB 68K
k4lmp is offline   Reply With Quote
Old 07-01-2012, 03:06 PM   #4
Piru
' union select name,pwd--
Points: 30,457, Level: 100 Points: 30,457, Level: 100 Points: 30,457, Level: 100
Activity: 69% Activity: 69% Activity: 69%
 
Piru's Avatar
 
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
Default Re: The Ebola Link Virus

Quote:
Originally Posted by vox View Post
XVS.library... under OS4,MOS and AROS it has no purpose.
Not quite true. At least MorphOS is compatible enough for link viruses to function just fine, and I early on made sure that xvs.library was fixed to function correctly under MorphOS.

Of course the scope of the potential 68k virus infection is quite limited, but at least you can run VirusZ and xvs.library under MorphOS.. which is nice if you're scanning amiga archives for viruses.

Last edited by Piru; 07-01-2012 at 03:08 PM..
Piru is offline   Reply With Quote
Old 07-01-2012, 03:43 PM   #5
vox
Banned
Points: 3,344, Level: 35 Points: 3,344, Level: 35 Points: 3,344, Level: 35
Activity: 99% Activity: 99% Activity: 99%
 
Join Date: Feb 2011
Location: Belgrade, Serbia
Posts: 510
Blog Entries: 2
Send a message via Skype™ to vox
Default Re: The Ebola Link Virus

Quote:
Originally Posted by Piru View Post
Not quite true. At least MorphOS is compatible enough for link viruses to function just fine, and I early on made sure that xvs.library was fixed to function correctly under MorphOS.

Of course the scope of the potential 68k virus infection is quite limited, but at least you can run VirusZ and xvs.library under MorphOS.. which is nice if you're scanning amiga archives for viruses.
OK but how they can infect MOS?

I wasn`t speaking of MOS 68k compatibility, but of need for the library. Surely, you could copy library and run VirusZ on OS4 also.
vox is offline   Reply With Quote
Old 07-01-2012, 06:56 PM   #6
Piru
' union select name,pwd--
Points: 30,457, Level: 100 Points: 30,457, Level: 100 Points: 30,457, Level: 100
Activity: 69% Activity: 69% Activity: 69%
 
Piru's Avatar
 
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
Default Re: The Ebola Link Virus

Quote:
Originally Posted by vox View Post
OK but how they can infect MOS?
Um, execute the infected binary?

Quote:
I wasn`t speaking of MOS 68k compatibility, but of need for the library.
Well not many other packages allow scanning for amiga viruses on other platforms so I can see use for it.

Quote:
Surely, you could copy library and run VirusZ on OS4 also.
Assuming the library and VirusZ works under OS4. xvs.library has some extreme measures to verify the integrity of the library itself. It isn't taken that it works under OS4. Maybe it does.

What I know is that xvs.library does work under MorphOS, along with VirusZ.

Last edited by Piru; 07-01-2012 at 06:59 PM..
Piru is offline   Reply With Quote
Reply

Bookmarks

Tags
ebola , link , virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump