home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
USA Bestseller
/
USA BESTSELLER Vol 1-95 (Hepp-Computer)(1995).iso
/
e141
/
new.217
< prev
next >
Wrap
Text File
|
1995-03-31
|
14KB
|
588 lines
Version 2.17 - major changes:
The names of very many viruses have been changed, and new names assigned
to viruses that previously only had a temporary name, starting with an
underscore. Some of those changes were made because of changes in
classification or in order to make the naming system more regular.
A few renamings deserve a special note - the Jerusalem.Vtech viruses have
been renamed to Jerusalem.HK, as the viruses have nothing whatsoever to
do with the Vtech computers. For a similar reason, the Prodigy virus
was renamed to Glupak and Coke was renamed to Coker.
Our definition for "invalid file" has been changed a bit. Previously
we used the same method as DEBUG - if DEBUG displayed "Error ine EXE or
HEX file" when attempting to load a file, F-PROT would display "Invalid
file". However, some of those "invalid" files would actullly run, at
least under some versions of DOS, and the this has now been taken into
consideration.
Version 2.17 - the following problems were found and corrected:
EXE files infected with Astra.1010 used to be reported as infected with
a "new or modified variant of Astra".
Zero_Hunter.415-infected files were not disinfected correctly.
Some Leprosy.591 and Emmie.2620-infected files were not identified
correctly, but reported as "New or modified variant of ..."
Sometimes when reporting "companion" viruses, F-PROT would incorrectly
add a message like "truncated - 5273 bytes missing".
Version 2.17 - the following false alarms were fixed:
CDBENCH.EXE \
DGKEY.COM > F-PROT /ANALYSE false positives
L2D.EXE /
PS7_IDC.DLL Possibly a variant of Aurea
FFRAMRPL.BST Possibly a a Cruel-dropper
NOGUARD.EXE Possibly a variant of PCBB
CATCH.EXE Possibly a variant of Doubleheart
Version 2.16d reported several files as "Possibly a new variant of
AntiCad". Those false alarms should now have been fixed.
Version 2.17 - minor improvements and changes:
Testing has revealed a problem on some machines, involving random
memory errors, not detected by parity checking. This is generally
either caused by too few wait states or faulty cache memory. So
far this problem has only been found on 486/66 and Pentium/90 machines.
This problem can have unpredictable effects on various programs,
including F-PROT. It may cause the message "checksum error in SIGN.DEF"
to be displayed, or a random corruption of a search pattern, possibly
causing false positives or false negatives. F-PROT will now attempt to
detect this situation, by checksumming the search patterns before and
after scanning. If the checksums are not identical, a warning message
will be displayed.
Version 2.17 - new viruses:
The following 77 viruses are now identified, but can not be removed as
they overwrite or corrupt infected files. Some of them were detected by
earlier versions of F-PROT, but not identified accurately.
_1792
Anarchy
Assassin (952 and959)
Belorussia
Burger (441.C, 560.AW, 560.AX, 560.AY, 560.AZ and 560.BA)
Burma (442.C and 442.D)
Consumed
Demand (666.B and 789.B)
DS
HLLO (4240, 8608, Hepatitus, Joker.B, Number_1.E, Tyst and Virms)
IVP (200, 365, 374 and 478)
Leprosy (573, 666.I, 666.L, 666.N, 1306, 47857, Lubec and Skism.808.E)
Lseek (a small flaw in this virus prevents disinfection)
Material
Milan.WWT.125.D
Mr_Twister
Necropolis.D
Ooops
Over1644
Radish (8444 and 8466)
SillyOR.131
Simple_Minded (123 and 207)
Sum (cirus corrupts .COM files, but .EXE files can be cleaned)
TheDraw
Trivial (27.E, 30.I, 32.C, 33.B, 42.H, 45.F, 46.B, 75, 82, 92, 99,
157, 346, 579 and Tom)
VCL (288, 302, 457, 1297, Fire, Mindless.423.D, Mindless.423.E,
Mindless.423.F, Mindless.423.G, Monet.267, Monet.466 and
Viral_Messiah.705)
Zero-to-O.C
The following 372 new viruses can now be removed. Many of them were
detected by earlier versions, but are now identified accurately.
_376
_490
_535
_1054
_1125
Alex_II
Alex&Solo
Andreew
AntiCad.4096.K
Anticheck
AntiPascal_II.400.B
ARCV.Ice-9.639.B
Arjworm
Armagedon.1079.F
Austr_Parasite.543
Ash.280.B
Baba.350
Better_World.F
Blue_Nine (A and B)
BootExe (203 and 204
Breaking.B
BW.371
Cascade (1701.AC, 1701.AE, 1701.AF, 1704.AA and 1704.AB)
Catscratch
Cavaco
Chaos.1181.L
Charm
Cholera (A and B)
CLME.1952
Clonewar.923.D
Cpxk.B
CSF
Danish_Tiny.263
Dark_Avenger (1800.N, 1800.O and 2000.Satan)
Deathboy.640
Dead.1374
Deaf.1119
Dei.1948
Demand
Dennis.689
Diamond.1024.C
Digress
Drunk
DSU (1414 and 1422)
Eader
Ear (Ear.1024.C and Ear.1026)
Easy
Emmie.2702
Este
Exp (1617 and 1619)
F-soft (633 and 656)
Faerie (286.A and 286.B)
Faillure
Father_Mac.269
Father_Christmas
Fewster
Firewalk
Five_days
Flip (2153.F and 2153.I)
Form.F
Galya
Gambler
Gidra.502
Ginger.2624
Gippo.Stunning.B
Glitch.449
Good_Doctor
Gotcha (828 and 1778)
Grazie (859 and 1361.C)
Grog (216 and 926)
Grunt.344
Gysium
H_Andromeda.725
Helloween.1160
Hellspawn.1071
Hermanos.2015
HLL (3779, 4075, 4568, 4984, 8304, Birthday.5824, Birthday.7808,
Linda, RSW and Rust)
HLLC (8736, 14880, 1769.B, Enrico, Unvisible.A and Unvisible.B)
HS.903
Hypervisor
Icelandic.1600
Intruder (1336 and 1353)
Inv-evil.769
Int78.B
IT.462
IVP (705, 803, 927, Bad_Friday, Silo and Thursday)
J&M.B
Jaat
Jerusalem (1808.Blank.D, 1808.Zeros, 2000, 2465, 2472,
AntiCad.2900.ABT.B, Fu_Manchu.C, Maroccan, PSQR.D and
Sunday.O)
John
Jtemp
Kaos.C
Keyboard-bug.1568
Keypress (935, 995, 1232.O, 1232.P and 1266)
Kela (1171, 1735, 1904, 2520 and 2530)
Keybug.1268
Khiznjak (692.B, 719, 731, 749, 765, 823, 846 and 1269)
Kid.434
Kiwi.512
Klubb
Krad
Kyokushinkai (2048.A and 3072)
Leath
Lehigh.B
Lemming.2151
Lesson_I.300
Letter_H
Little.B
Loki.1228
Lubek
Lyceum (944 and 1800)
Magda
MegaS
Metal.400
Micro.B
Mirea (925, 950, 1953 and 1962)
MMIR (279 and 421.B)
Mooc
Mr_Gu.545
Multiflu.791
Multiplex.815
Murphy (Pest.B and Tormentor.1072.C)
My_Child.B
Natas.4774
New_Year
Ng (706, 914 and 1036)
Night_knight
Ninety_two
Nr
Ohm
Orchid.351
Overdoze (470 and 472)
P&C
Patoruzu
Peep
PDV
Pixel.850.B
Polonaise
Powertrip
Press.B
Prodigy
Proto-T (599.B, 602 and 654)
PS-MPC (310, 311.B, 388, 430, 441, 487, 480, 504, 510, 517, 564.C,
564.D, 565.I, 574.F, 578.N, 578.O, 578.P, 578.Q, 598.D,
598.E, 598.F, 606.G, 1295, DemoExe.32947, Dork, G2.Puppet,
G2.Stargate, HD, Mema.1187, Mema.1201, Mema.1203, Mema.1217,
Mercenary, Payrise.874, Shrimp, Snort and Weak)
Pure.440
Quarry
Rajaat (287, 443, 679 and 700)
Realize
Red_October
Reedcat
Republic
Rescue
Retix
Rodolf
Sandy.1107
Satyricon.355
Sauron_II
Scratch.374
Shirley.C
Shizol
SillyC (96, 128, 144, 169.B, 179, 190, 215.B, 264, 302, 331, 343,
498, 563 and 626)
SillyCR (76, 80, 125, 130, 131, 200, 239, 240, 261, 264, 330, 357,
563)
SillyCER.307
SillyER.323
Simplex (504 and 507)
Sink
Siskin.763
Sistor.2605
Slava
Small_comp.89
Sofia_Term.899
Soldier
Sql
SRP.2264
Stinkfoot (1283.A and 1283.B)
Sylvia.1332.F
Syslock.Syslock.F
Tai-Pan.434
Tamsui.19033
Tokyo.1068
Traceback.2930.B
Trakia.653
Trash
Trash_soft
Try
Tver.532
Twisted (239 and 461)
Union
Ussr-414
UTA
Uucckk
Uvjan
V-160.164
VBasic.G
VCL (208, 279, 315, 316, 342, Anston.B, Bev.516.B, Catholic,
Code_Zero.652.B, Genesis.738, Grail, Heevahava.520, Lobo
and Pleasure)
VCM
Vcode
Vienna (486, 620, 648.AF, BNB.K, BNB.L and Violator.5305)
Viv
Vor (1536.A, 1536.B, 1536.C and 1584)
Wally.981
Wart
WMA
Write
XAM_II
Yankee-Doodle.TP.44.E
YB.402
Zero_Hunter (415.B, 415.C and 415.D)
Zielona
The following 171 new viruses are now detected and identified but can not
yet be removed.
_1685
2-up
4On
AC
Annihilator (272, 304, 357, 379, 390, 412 and 711)
Anston.1782
Antipode
Attitude.827
Australian_Parasite (Split.1033 and Split.1035)
Backform (A and B)
Badcommand
Ball
Beer.3192.B
Bettle
Blackhack
BoxBox
Bug
BW.474
Cannibal
CHCC.1428
CLI&HLT
Congrats.918
CorpLife
Cybertech.552
D-K
Daemaen.2041
Dalian
DBF (990 and 1115)
Deathboy (893, 912, 931 and 937)
Dementia
DIR-II (1024.E, 1024.J and 2048)
DIS
Dodger
Drug
E-Morph
Emmie (2604, 2823 and 3097)
Eternity (410, 411, 562 and 599)
Exterminator
Father_Mac (289, 303, 789, 836, 1360, 1455, 1470, 1495 and 1496)
FF_char
Fraud (600 and 666)
Girls
Ha!.1224
Halka
Hello (615, 640 and 720)
Hellspawn.Gif.681
Hermanos.27773
HLL (3677.B, 4942, 5000 and LouLou)
Hnyslov
Honey.1029
I_am
Ieronim_III
Inquis
IVP (510, 665, 766, 811, 827, 874, 886, 939, 974 and 2316)
Kela.823
Keyboard_bug.2262
Keypress.1000
Khai
Khiznjak (515, 565 and 1011)
Konkoor.1933
KSV
Leech (1025 and 1026)
Legozz
Loren.1374
Megabug
Mirror_II
Miss_D
Monte_Carlo (1483 and 1541)
Mut-int.694
No_of_the_Beast.Z
Nocopy.3685
NRLG (666, 755, 813, 824, 853, 865, 901, 964, 985, 1001, 1007 and 1009)
Orchid.311
Ostap
Otti
PCBB (1679, 3072.A and 3072.B)
PD
Pfeifer
Phyton
Pinky.1124
Poison
Pollution.822
Predator.1072.B
Prime.1164
PS-MPC.DK.693
Psychosis.1195
Pyramid
Renegade
Rest
RMNS.736.B
Robal
Ryazan.B
Sabados
Scramble (1203, 1253 and 1256)
Screaming_Fist.512
Sentinel.4636.B
Shatin
Skater.673
Tina
TS (1200, 1235 and 1418)
Tver.776
VCL (511, 2037, Genocide.952 and Genocide.981)
Verb
Vic.793
Vinchuca
Vinnitsa (1620 and 1658)
Vodka
VVF.1868
Wasp (623 and 903)
Wormsign
Zherkov.2269
Zipper
The following 12 new viruses are now detected, but not identified.
F-PROT will just report the family name with a (?), as it is not yet
able to determine which variant it is dealing with. Disinfection of
these viruses is not yes possible.
DSME (Apex, Connie.B, Demo and Teacher)
Minosse
Mombasa
Mutagen (0_90.Agent, 0_95.Agent, 1_00.Agent, 1_00.Secret,
1_10.Agent.A, 1_10.Agent.B, 1_10.Hitek)
S-bug.Fruitfly
Scacchi (Bishop and Rook)
The following 1 virus which was identified by earlier versions can
now be removed.
Singapore
The following viruses have been renamed:
_81 -> Trivial.81
_132 -> Foxy
_257 -> No_Hope
_286 -> Bell
_317 -> Urfin
_343 -> Quinine
_386 -> Tique
_391 -> Kak
_422 -> Quasar
_468 -> Mango
_494 -> NoPM
_500 -> Qaver
_524 -> Quell
_571 -> Quibble
_592 -> ManOWar
_593 -> Quash
_604 -> Div0
_635 -> Five_Eights
_641 -> Quiche
_656 -> Quid
_736 -> Infec
_779 -> Technomaniac
_797 -> Kwz
_804 -> Psyco
_872 -> Quod
_894 -> Katielou
_908 -> Line
_928 -> JVW
_934 -> Vidmess
_1395 -> Quartz
_1403 -> F4
_1491 -> Cascade.1491
_1689 -> Quiff
_1987 -> Benito
_2828 -> Marawi
_2878 -> Lost
2153 -> JMPflag
4-days -> Alien.1356
Akuku.889.Metal_Thunder -> Akuku.889.D
Alpha -> Arcv.Alpha
Anarchy -> Grob
Atomic.166 -> SillyC.166.B
Atomic.Toxic -> Toxic
Australian_Parasite: two groups of viruses were removed from the
family and put in the Middle and APlittle families.
Austr_Term -> Austerm
BA -> SillyC.181
Bad_Brains.* -> Leprosy.Bad_Brains.*
Black_Monday.Borderline -> Black_Monday.781
Bombtrack -> Offspring
BootEXE: Some of the Bootexe variants have been moved into the VVM
family.
Brisbane_Mummy -> Incest
Bug -> Bug-2
Cacophony.* -> Gippo.Cacophony.*
Careful -> Shizu
Cheeba.1_0 -> Cheeba.1683
Cheeba.1_1 -> Cheeba.1691
Civil_War.444 -> Trivial.Civil_War
Coke -> Coker
Curse_IV -> Curse
Daemaen -> Talon
EMF.* -> Screaming_Fist.*
EVCZ -> EVC
F1-337 -> F1
Galeo -> Galeocerdo
GameF -> Game
Gusano -> BuenDia
Ignorant -> Ignorance
Infector.* -> Khizhnjak.*
Inoculation -> Mei_Hua
IVP.Sonic -> IVP.Black_Belt
IVP.Stress -> IVP.Anxiety
Jerusalem.5120 -> Jerusalem.Cvex3
Jerusalem.AntiCad.* -> AntiCad.*
Jerusalem.Vespa -> Jerusalem.Viajero
Jerusalem_II -> Quorum
KeyKap.* -> Hellspawn.*
La_la -> Oohlala
Leprosy.Plague -> Leprosy.591
Luca -> Thule
Lyceum -> Mirea
Maaike -> Rauser
Mag -> Magic
Manic -> Anston
March_25th -> Hideous
Mark_II -> Mark
MH-757 -> MH
Mich -> Mickey
Milano -> Bresci
Mohova.659 -> Arcv.Ice.659
Mohova.734 -> Arcv.Ice.734
MP1024 -> Quiz
Nice -> Nice_Boy
Nigh -> Night
Nipple -> Nip
Peach -> Keypress.887
Phantasm -> Phantasmagoria
Phantom -> Phant
Phunnie -> Ha_loop
Prodigy -> Glupak
PS-MPC.Flex -> IVP.Flex
Rape.Basilisk -> Rape.1639
Satanic_Warrior -> SatWar
School_Suck -> School
Shoo -> MacGyver
SI-492 -> SI
SIC -> RMNS
Sidewinder -> Kyokushinkai.2048.B
SMEGdemo -> Trivia
SNA -> Kid
SSI -> Wasp
Sybille -> Sibylle
Taiwan_Over -> SSH
Tash -> Tashkent
Tchantches -> Mine
Terminator-B -> Terminator_III
Totoro.* -> Jerusalem.Totoro.*
Uruk-Hai -> Uruk
USSR-414 -> Quail
USSR-707 -> Quark
V-1391 -> Quatrain
V2221 -> CCCB
V-3000 -> Quango
Vienna.Feliz -> ITV.517
Vienna.IT.* -> ITV.*
Yesterday -> Pepper