MAD III
Introduction
MAD III is a computer virus written for the Commodore Amiga. It is a bootvirus and a simple clone of the Byte Warrior virus.
Summary
- Overwrites the bootblock of an unprotected floppy disk when inserted in the disk drive.
- It is not encrypted
- Uses DoIO() of the exec.library for infection
- Works only with Kickstart 1.2
- Resident by using KickTag
Details
The virus behaves exactly like its original Byte Warrior except that the author has overwritten the text DASA visible in the bootblock with MAD III:
00c0h: 4D 41 44 00 49 49 49 3C 00 08 13 FC 00 02 00 BF ; MAD.III<...ü...¿
This text however is actually the ASCII-representation of following code:
dasa:
neg.w d1
subq.w #1,d1
Now that it is overwritten this routine will crash the Amiga when executed!! Obviously the author of this virus had no programming abilities.
At the end of the bootblock you can read the following text:
0300h: 41 00 53 74 61 6D 6D 6C 65 72 00 70 6C 65 61 73 ; A.Stammler.pleas
0310h: 65 00 64 69 65 00 21 21 00 69 63 6F 6E 00 6C 69 ; e.die.!!.icon.li
0320h: 62 72 61 72 79 00 05 47 49 83 99 38 57 65 76 99 ; brary..GIƒ™8Wev™
and
03b0h: 87 77 D7 74 00 0F D8 74 77 47 43 00 00 06 62 79 ; ‡w×t..ØtwGC...by
03c0h: 00 48 61 63 6B 65 72 00 26 00 43 72 61 63 6B 65 ; .Hacker.&.Cracke
03d0h: 72 00 47 6D 62 68 00 00 00 00 00 00 00 00 00 00 ; r.Gmbh..........
Also even the typical Byte Warrior text, which is decryted in the bootblock it still the same.
Clones and variants
None





