home *** CD-ROM | disk | FTP | other *** search
- name: Safe
- short: Safe v13.3 - virus dicovering system
- author: Zbigniew `Zeeball` Trzcionkowski (zeeball@interia.pl)
- uploader: Tomasz Wiszkowski (error@alpha.net.pl)
- version: 13.3 (05.06.2000)
- requires: Amiga with OS 2.04+ (xvs.library strongly recommended)
- type: util/virus
-
- STATUS: FreeWare
-
- FEATURES:
- - system friendly, non resident, can discover new link viruses
- - TCP newshell guard option
- - ANTISTEALTH abilities and HEURISTIC vector check option
- - can clear VBR
- - added memory removals for NeuroticDeath1&2 viruses
- (Thanks to Jan Andersen)
- - added SAVEMEM option (for advanced users)
- - can find and disable in memory PolishPower
- (Thanks to Jan Andersen)
- - tested with lot of viruses
- (Thanks to Jan Andersen)
- - not crashes with PatchControl!
- (Thanks to Tomasz Wiszkowski for the show :)
- - `Safe VECS` allows You to REMOVE ANY patches from
- LoadSeg and NewLoadSeg vectors!
- - added primitive memory check for rexxfunc trojan (more info below)
- - added kit to discover unknown Vaginitis Clones
- like TCP:2421 (more info below)
-
- *************************************************************************
- - added QUICKTEST tool to detect and remove new TCP: trojans!
- *************************************************************************
-
-
- NOTE THAT THIS IS VIRUS DETECTOR - NOT FILE CHECKER OR CLEANER!
- IT ONLY INFORMS ABOUT ATTACK AND REMOVES VIRUS FROM MEMORY
- IF POSSIBLE!
-
-
-
- There are TCP trojans on wild!
-
- BIG THANKS TO PAUL FOR FINDING THEM!
-
-
-
- Use new tool added to Safe`s package - QUICKTEST.
- It is able to find and remove the rexxfifo and rexxfunc trojans.
-
-
-
- *******************************************************************
- Rexxfifo.library trojan TCP:4097 remote shell
-
- Installer: (faked YAM?)
-
- QUICKTEST can seek and destroy this one. Then please reboot.
-
-
-
- *******************************************************************
- Rexxfunc.library trojan TCP: 2001 remote shell
-
- Installer: `miamispoof` size: 8468
- (The file is StoneCracked and then modified to
- prevent decrunching)
-
- QUICKTEST can seek and destroy this one. Then please reboot.
-
-
-
- *******************************************************************
- bigger c:mount TCP:2421 remote shell
-
-
- Yes. There is another link-virus. The memory patch is detected as
- STD Vaginitis #1 and removed correctly by xvs.library.
- Yes I`ve decoded it and now I know that author just used
- Vaginitis to have cool TCP shell opener :-)
- This mutation is designed to infect C:mount,
- so just if You have Vaginitis message then just
- replace Your mount with the original one.
-
- Installer: `jizzer` size: 15368
- attacks C:mount (adds 700 bytes with virus)
-
-
- So if You have such TCP:2421 shell then please replace c:mount with
- the original one.
-
- Look into AntiVag directory of Safe`s package to find
- temporary solution to detect such mutations if there are more.
-
-
- ...and look for newest xvs.library from Alex van Niel.
-