SCA.D&A.Dropper (31-July-1993) Entry...............: SCA.D&A_dropper Virus Alias(es)...........: SCA Dos kill = D&A File Virus Virus Strain........: SCA Virus Strain Virus detected when.: --- where.: --- Classification......: Boot Virus dropper, memory resident Length of Virus.....: 1.Length on storage medium: 1052 byte 2.Length in RAM: 1024 byte --------------------- Preconditions ------------------------------------ Operating System(s).: AMIGA-DOS Version/Release.....: 1.2/all, 1.3/all, 2.0/all, 3.0/all Computer model(s)...: All models --------------------- Attributes --------------------------------------- Easy Identification.: Typical text in virus and displayed: "Something wonderful has happened Your Amiga is fucked !! and, even better... Some of your disks are infected by a Virus !!! Another masterpiece of The Mega-Mighty D&A !!" Type of infection...: Self-identification method: virus test whether 4th longword matches string "CHW!" (this isnot done properly) System infection : RAM resident, reset resident Infection Trigger...: Reset Storage media affected: Only floppy disks (3.5" and 5.25") Interrupts hooked...: --- Damage..............: Permanent damage: Overwriting bootblock with a Non-Dos bootblock Transient damage: Screen buffer manipulation: screen becomes black, message (see typical text) is shown by fading in and out peaces of it Damage Trigger......: Permanent damage: Reset Transient damage: 15th infection Particularities.....: A resident program using the CoolCaptureVector is shut down by virus' suicide function. Similarities........: SCA virus strain --------------------- Agents ------------------------------------------- Countermeasures.....: VirusZ 3.06, VT 2.54, VirusChecker 6.28 Countermeasures successful: VirusZ 3.06, VT 2.54 Standard means......: VT 2.54 --------------------- Acknowledgement ---------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Jens Vogler / Karim Senoucci Documentation by....: Jens Vogler / Karim Senoucci Date................: 01. VII. 1993 Information Source..: Virus disassembly / Erik Loevendahl, Praestoe,DK .