[comp.sys.amiga.programmer] Help -- Lamar Exterminator Virus -- coolcapture vector

chucks@pnet51.orb.mn.org (Erik Funkenbusch) (01/30/91)

dale@sparky.IMD.Sterling.COM (Dale Miller) writes:
>A student in my wife's 3rd grade classroom brought in an Amiga game to use
>on our Amiga 1000.
This is why all software that comes from unknown sources should be examined
closely.
>
>  The disk had the "lamar exterminator" virus on it.
>
>However, my wife brought home one of the disk and I loaded it into our 
>Amiga 3000.  I have used VirusX_4.01 with  workbench 2.0 and it says that
>everything is clean.  However, when I load VirusX_4.01 with workbench 1.3
>it gives me a warning about the coolcapture vector saying that there may
>be a virus in RAM.
Hmm this is a weird one.  Never heard of that problem.  
>
>My questions: 
>
>  1.  How serious is the lamar exterminator virus?
Any virus is serious.  The Lamer can destroy a floppy disk if left long
enough.
>  2.  Can it affect a hard drive?
Nope, The Lamer is a bootblock virus and only effects data blocks on floppy
drives.
>  3.  Does VirusX_4.01 with workbench 1.3 normally give the coolcapture
I've never had the problem on a 1.3 system.
>      vector message?
>  4.  Is there a newer release of VirusX?
As far as i know, 4.01 is the latest.
>  5.  Does VirusX check the hard drive?
No, but it does come with some programs which check for certain virii on the
hard drive.
>
>My wife now knows how and why to use VirusX.  I expect a phone call tonight
>from the father of the student who still has the virus.
Or perhaps you should call him, since he might not take it seriously.
>
>Thank You,  Dale Miller

e

UUCP: {amdahl!bungia, crash}!orbit!pnet51!chucks
ARPA: crash!orbit!pnet51!chucks@nosc.mil
INET: chucks@pnet51.orb.mn.org

DXB132@psuvm.psu.edu (01/31/91)

In article <3930@orbit.cts.com>, chucks@pnet51.orb.mn.org (Erik Funkenbusch)
says:

>>  2.  Can it affect a hard drive?
>Nope, The Lamer is a bootblock virus and only effects data blocks on floppy
>drives.

I would be careful. Most viruses patch DoIO and they don't care what driver
the message is being sent to, i.e. they don't distinguish between HDs and
floppies (or console IO, for that matter :-))

-- Dan Babcock