Saddam Virus (31-January-1992) Entry...............: Saddam Virus Alias(es)...........: Irak = Saddam Hussein = Disk-Validator Virus Virus Strain........: --- Virus detected when.: March 1991 where.: Australia Classification......: System virus (replacing), resident Length of Virus.....: 1. Length on storage medium: 1,848 byte 2. Length in RAM : 1,936 byte --------------------- Preconditions ----------------------------------- Operating System(s).: AMIGA-DOS Version/Release.....: 1.2/33.166, 1.2/33.180, 1.3/34.5 Computer model(s)...: AMIGA 500, AMIGA 1000, AMIGA 2000A, AMIGA 2000B --------------------- Attributes -------------------------------------- Easy Identification.: --- Type of infection...: Self-identification method: searches floppy disk for an encryption-byte in system program Disk-Validator that fits with its own System infection: replaces Disk-Validator in L: directory on floppy disk system routines: - BeginIO(trackdisk.device) - Close(trackdisk.device) - InitResident(exec.library) - OpenWindow(intuition.library) system vectors: - ColdCapture(execbase) - CoolCapture(execbase) - KickTagptr(resident-struct.) Infection Trigger...: Restart validator starts Disk-Validator when Bitmap on disk is not valid. This will not work with Amiga OS Version 2.0, because there is no Disk-Validator use (no restart validator process in AmigaOS V2.0 anymore). Media affected......: Any floppy disk (every trackdisk.device) Interrupts hooked...: Vertikal Blank interrupt works like a watchdog, which guarantees that virus remains in memory. Damage..............: Permanent damage: 1) If no Disk-Validator is found on floppy disk or no L: directory, it builds both of it (replacing Disk-Validator on disk). 2) Destroys block by overwriting data with "IRAK". 3) Sets Bitmap NOT VALID (so running Disk- Validator next time will infect system) 4) Starts diskhead stepping in all floppy drives and writing on disk (if writeable) thereby producing in trackdisk errors. Transient damage: 5) Mouse pointer disappears and displays an alert with text "SADDAM VIRUS". On pressing mouse button, cold reset will be started. Damage Trigger......: Permanent damage: 1) any newly inserted diskette 2) reading datablock 3) accessing rootblock 4) Transient damage: 5) reading bootblock after certain time Particularities.....: - No infection will occur when using FastFiling- Systems or running AmigaOS Version 2.0 - Virus uses direct Dos.Library Jumps. Decrypts itself with pseudo random number every new in- fection and installs a message port named "mycon.write" Similarities........: --- --------------------- Agents ------------------------------------------ Countermeasures.....: Names of tested products of Category 1-6: Category 1: .2 Monitoring System Vectors: CHECKVECTORS 2.2, BootX V4.10, VT V2.32 .3 Monitoring System Areas: CHECKVECTORS 2.2, BootX V4.10, VT V2.32, VIRUSX 4.0 Category 2: Alteration Detection: BootX V4.10, VT V2.32 Category 3: Eradication: BootX V4.10, VT V2.32 Category 4: Vaccine: --- Category 5: Hardware Methods: --- Category 6: Cryptographic Methods: --- Countermeasures successful: BootX V4.10, VT V2.32 Standard means......: BootX V4.10, VT V2.32 --------------------- Acknowledgement --------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Oliver Meng Documentation by....: Oliver Meng Date................: 27th NOVEMBER 1991 Information Source..: --- .