home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Gold Medal Software 3
/
Gold Medal Software - Volume 3 (Gold Medal) (1994).iso
/
virus
/
fp_212.arj
/
NEW.212
< prev
next >
Wrap
Text File
|
1994-04-21
|
10KB
|
337 lines
Version 2.12 - major changes:
The identification of boot sector viruses has been improved significantly.
F-PROT does exact identification for most boot sector viruses it detects,
and previously it would refuse to remove variants that differed by as
little as one bit from the original virus. Other programs which did not
do as good identification would happily remove the virus. F-PROT now
attempts to determine if a new boot sector virus is sufficiently similar
to a known variant to attempt disinfection.
Some improvements have been made to VIRSTOP. It is now more Windows-
friendly than before - it will now beep instead of asking the user to
press ENTER when intercepting a boot virus. It is now also possible to
specify which drive to use for the "swap" files when using the /DISK
switch. Finally, the /REHOOK switch allows VIRSTOP to be re-enabled,
it was loaded before NETWARE or another program that took over the
"load-and-execute" function.
Version 2.12 - the following problems were found and corrected:
Several false positives were fixed. The "Tamanna" false positive appeared
in 2.11. The others were older, but had not been reported to us before.
"Possibly a new variant of Tamanna" in PWLICLMT.EXE (part of a beta
release of DEC Pathworks)
"Possibly a new variant of Cysta" in KBDF.COM (Turkish keyboard driver)
"Possibly a new variant of SillyOR" in a program named TRAPKEY.EXE
"Leprosy" (VIRSTOP/Quick Scan) in a program named OPENPORT.COM
F-PROT 2.11 and earlier would not detect all Cysta.8045-infected .SYS
files.
The Stoned.Angelina virus was not identified properly on 3.5" diskettes.
Some Voronezh.1600 and Liberty-infected files were not disinfected
correctly.
Version 2.12 - minor improvements and changes:
When using the /ANALYSE option, F-PROT will now not report "Invalid
entry point", unless the file has a .COM or .EXE extension - not .OVL
for example.
If a virus is damaged, by shortening the file by a few bytes, F-PROT will
now report "- truncated (xxx bytes missing)", instead of reporting just
"New or modified variant of ...". This should never happen under normal
circumstances and is of most interest to researchers that may have
corrupted samples in their collections.
Version 2.12 - new viruses:
The following 58 viruses are now identified, but can not be removed as
they overwrite or destroy infected files. Some of them were detected by
earlier versions of F-PROT, but only reported as "New or modified
variant of..."
AB
Abraxas (1214, 1304 and 1508)
Burger (405.D, 405.E, 405.F, 441, 505.G, 505.H, 505.I, 505.J,
560.AK, 560.AL, 560.AM and 560.AN)
Como.1786
Doubleheart.452.B
Genvir.1376
Grog (Enmity, Sempre and Trumpery)
HBT
HLLO (4505, 5760, Mission, Novademo.A and Novademo.B)
Hot
Milan (AntiNazi, Naziskin.270, Naziskin.903, Sabrina and Verbatim)
Silly_Willy-trojanized .EXE files
Slugger
Trivial (23, 24, 25.B, 25.C, 27.D, 31.C, 36.A, 36.B, 36.C, 37, 38,
39, 42.F, 42.G, 42.H, 43.B, 43.C, 59, 66, 89, 342, Ansibomb
and Vootie.B)
VCL (526, Mindless.423 and Muu)
ZigZag.232
The following 449 new viruses can now be detected and removed. Many of
these viruses were detected by earlier versions, but are now identified
accurately.
_241
_451
_494
_635
_638
_779
_804
_1987
_2717
Accept (3619 and 3773)
Aiw
Alexander (1843 and 2104)
AntiCMOS
AntiMIT.764
Arcv (Jo.912 and Ice-9.642)
Armageddon.1079.E
Ash (712 and 1586)
Australian_Parasite (152, 153, 155, 187, 215, AMSV, 635, Feeble,
Vga_Demo, Comic, Lipo, Gotter and 306)
B1
Baba
Badsectors.3422
Baron
Behaviour.Herb
Berlusconi
Betaboys.615
Big_Bang
Billy
Black_Jec (230, 246 and Sad.300)
Blood_Sugar
BUPT.1261
Butterfly.FJM
Cascade (1699.B, 1701.Jojo.G, 1701.M, 1701.N, 1701.O, 1701.P and
1704.S)
Changsha
Civil_War.281
Civil IV (568 and 586)
Cybercide (1321 and 2256)
Danish_Tiny (NC.284, NC.286 and Wild_Thing.287)
Dark_Avenger (1797, 1799, 1800.Eugen, 1800.L, 1800.Platina, 1813 and Major)
Datalock (828.B and 828.C)
Deicide_II.622
Dementia
Dutch_Tiny.111
Ear (Job and Homecoming)
Fax_Free (608.A, 608.B, 622, 623, 1024.C, 1024.D, 1024.E, 1536.Lamer,
1536.Pinniz.A, 1536.Pinniz.B, 1536.Pinniz.C, 1536.Pinniz.D
and 1536.Pisello2)
Flip (2153.G and 2153.H)
Friday_the_13th (416.C and 416.D)
Frodo.Fish_6.D
Ginger
Gippo.JumpingJack
Gotcha.605
Green_Caterpillar.1575.G
Grog (1089, Gonfie, IlCuoce, Noncemale and Ovile)
Grunt.529
Hates.212
Helloween (1228, 1401 and 1430)
HH&H.4087
Hiperion.249
HLLC.Sauna
Hungarian (1409 and Kiss.1006)
Hungarian_Andromeda (1024 and 1536.B)
Icelandic.656.C
Ienez
Industrial
Intruder.1555
Ionkin.195
IVP (351, 644, Crystal, Stress, Taselhoff, Wild_Thing.555 and
Wild_Thing.557)
Japanese_Christmas.722
Jerusalem (2389, 1808.CT.SubZero.B, 1808.SuMsDos.AN, Sunday.K,
Tarapa and Zerotime.Australian.C)
Jimi
Keypress (1232.L and 1600)
KMIT
Kolumna
Kommuna
Kuang
Lyceum.1901
March_25th (B and C)
Marzia (D, E, F, G, H, I, J and K)
Metallica.2620
Michelangelo (C, G and J)
Mirage
MMIR.278
Murphy (1477, 1521.B, 1650, 1659, 1752, Delyrium.1788 and Napalm)
Nipple
NoFrills.840
November_17th (900.B, 900.C and 998)
Npox.1015
PCBB.1845
Phantasm
PHX.1360
Ping-Pong (Standard.G, Standard.H and Standard.I)
Pirate
Pixel.761
Prague (604 and Pizza)
Praying (579 and 587)
Predator.1063
Proto-T (Ritzen, Ritzen.1087 and 1050)
PS-MPC (150.A, 150.B, 338.A, 338.B, 338.C, 339.A, 339.B, 339.C,
339.D, 339,E, 343.A, 343.B, 343.C, 344.B, 344.C, 344.D,
344.E, 344.F, 346.B, 347.A, 347.B, 347.C, 347.D, 347.E,
347.F, 347.G, 347.H, 347.I, 347.J, 348.B, 348.C, 351.A,
351.B, 352.B, 352.C, 352.D, 352.E, 352.F, 352.G, 352.H,
352.I, 352.J, 352.K, 352.L, 353.A, 353.B, 357, 425, 565.B,
565.C, 565.D, 569.A, 569.B, 569.C, 570.B, 570.C, 570.D,
572.B, 573.C, 573.D, 573.E, 573.F, 573.G, 573.H, 573.I,
574.C, 574.D, 577.C, 578.D, 578.E, 578.F, 578.G, 579.A,
579.B, 579.C, 594, 597.B, 597.C, 597.D, 598.B, 598.C,
602.A, 602.B, 602.C, 602.D, 603.A, 603.B, 603.C, 605.B,
606.B, 606.C, 607.B, 607.C, 610.A, 610.B, 610.C, 611.C,
611.D, 611.E, 611.F, 611.G, 611.H, 611.I, 611.J, 611.K,
612.A, 612.B, 612.C, 612.D, 612.E, 615, 639, 691, 739,
749, 2668, Abominog, Actifed, Alchemy, Argent, Blender,
Birthday, Doggy, Fred, G2.572, G2.573.A, G2.573.B, G2.574,
G2.575.A, G2.575.B, G2.576, G2.578, G2.582, G2.584.A,
G2.584.B, G2.584.C, G2.585.A, G2.585.B, G2.588, G2.Mudshark,
Greetings, Joana.942, Justice, Love, McWhale.1023,
McWhale.1124, Mojave, Projekt.897, Projekt.918, Quest,
Ranger, School, Schrunch.442, Seven_Percent.918, Shock,
Silent, Skeleton.542, Skeleton.550, Skeleton.570,
Skeleton.616, Skeleton.617, Sorlec.597, Sorlec.639,
Steeve.672, Steeve.686, SwanSong.1714, SwanSong.1772,
Swansong.1773, SwanSong.2062, Walt.311, Walt.355, Warez.1805,
Weakley, Z10.683 and Z10.687)
PSV.B
Pysk
Raptor
Russian_Tiny.127
Sandy
Satan.602
Shake.C
Sidewinder
SillyC (92, 100, 158 and 207)
Sparkle
Steryd
Stoned (Bunny.A, Bunny.B, Bunny.C, Standard.F, Standard.I, Standard.J,
Standard.L, Standard.M, Standard.O, Standard.P, Standard.Q,
Standard.R, Standard.S, Standard.Good, Standard.Pervert,
Standard.Space.B and Standard.Udos)
Sybille.1200
Sze.314
Taiwan (677 and 743.C)
Timid (298, 299, 301 and 303)
Tiny_GM
Tiny_family.Fred
Trakia
Trident (444 and Nolimit2)
Troi (C and D)
Unhandled
VCL (379, Angel.436, Angel.1681, Assassin, Dial, Julian, Olympic.B,
Sorlec and Suck)
VCS (Standard.Darkside and Standard.Test)
Vienna (533, 608, 610, 660, 680, 700.A, 700.C, 709, 814, Choinka.C,
Feliz, Parasite.861, Violator.716.B, Violator.716.C,
Violator.803, Violator.821, Violator.843.B, Violator.843.C,
Violator.909, Violator.957, Violator.5286, W-13.318 and
W-13.507.E)
Virdem.1336.Locked.B
Wrzod
Yam.3596
Yankee_Doodle.Login.3045.C
YB.426
Yesterday
The following 58 new viruses are now detected but can not yet be removed.
_592
Antitrace
Appelscha
Arcv.Anna.745
Austr_Term
Backform
Carpe_Diem
Code_Zero.735
Czech_Happy
Daemaen
Dark_Avenger.2829
Dillinger
DIR-II (M, O, Q, S, T, W)
Doomsday.715
Doubleheart.649
Gippo.Blow
Glith
Grog (Dream, Inc, NTA, Outwit-C, Outwit-E, Public, Razor and Wildcard)
Hallow
Jerusalem.Vtech
Konkoor
LM
M5-VP2
Mystic.379
PCBB (833, 1680 and 1683)
PHB.B
Pit
Predator.1154
Proto-T.694
Raubkopie.1888.B
Sayha
Screaming_Fist (839, 846, 855 and 862)
Sluknov
Split_Second (1135 and 1149)
SVC.3122
Sze.351
Topa
V2221
Veronika
Wally
X-1.571
X-3A
Yog
The following 15 viruses which were detected by earlier versions can
now be removed.
CIS
Ein_Volk
Jerusalem.986
PS-MPC (ARCV.2.692, ARCV.2.693 and ARCV.8)
Satanbug
VCL (Chuang, Diarrhea.933, Diarrhea.1222, Diogenes and Mimic)
Warrior
Weak
Yeke (1076 and 1204)
The following viruses have been renamed, in order to make F-PROT follow
the CARO naming standard as closely as possible.
_1068 -> Spinner
_1417 -> Spanish_Fool
_1441 -> Sum
_1588 -> Distrust
_1784 -> Three_Tunes
_2000 -> Alphastrike
Anticlr -> Anti-Clerical
Commonwealth -> CIS
Dos1 -> Dos_1
Error_412 -> Runtime
Groz -> Grozny
Inoc -> Inoculation
Krusha -> Khrusha
Micro-128 -> Micro
NGV -> Genvir
QMU.1513 -> QMU
Quit-1992 -> Quit
Satwar -> Satanic_Warrior
Simple -> Simple_Minded
Talking_Heads -> No_Party
Tula.419 -> Tula
V-1920 -> Dostepu
The _758 and Gemand viruses have been moved into the Hungarian_Andromeda
virus family