home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
MAG.E 4
/
MAG.E 4 (Disk 1 of 2).adf
/
35
/
35
Wrap
Text File
|
1977-12-31
|
3KB
|
67 lines
@7RED DWARF VIRUS ALERT!
======================
@1
VIRUS ALERT: SMEG.Pathogen and SMEG.Queeg
New highly polymorphic viruses in wild in UK.
S&S International, developers of Dr. Solomon's Anti-Virus Toolkit, have
discovered two dangerous new viruses running wild on British computers.
The two new viruses, Pathogen and Queeg, have both been written using
what the virus author, The Black Baron, calls the Simulated Metamorphic
Encryption Generator (SMEG).
The viruses are highly polymorphic, using an intensely variable and
large encryption loop. This means that each infection of the virus looks
completely different to those seen before, making the job of writing a
reliable detector extremely difficult.
One of the anti-virus researchers at S&S International described the two
new viruses as the most complicated he had ever seen "..by a long, long
way"
Pathogen and Queeg are memory-resident, polymorphic infectors of COM and EXE
files. If Pathogen triggers its payload (between the hours of
17:00 and 18:00 on a Monday evening) BIOS level writes are made to the first
256 cylinders on heads 0-3 of the hard disk, and the following message is
displayed:
Your hard-disk is being corrupted, courtesy of PATHOGEN!
Programmed in the U.K. (Yes, NOT Bulgaria!) [C] The Black Baron 1993-4.
Featuring SMEG v0.1: Simulated Metamorphic Encryption Generator!
'Smoke me a kipper, I`ll be back for breakfast.....'
Unfortunately some of your data won`t!!!!!
The line and other messages contained within the viruses suggest
the author is British and a fan of the cult science-fiction television comedy
series, Red Dwarf.
Dr Solomon's Anti-Virus Toolkit has the ability to find both viruses
using an "Extra driver": SMEG.DRV
If you find any instances of the viruses using the SMEG.DRV you
should then use another driver in its place. This driver is not
intended for use, unless a Pathogen or Queeg infection
has already been detected: SMEGSLOW.DRV
At the time of writing S&S International know of no anti-virus product
(including Dr Solomon's Anti-Virus Toolkit) which detects SMEG.Pathogen
and SMEG.Queeg. However, using the extra drivers Dr Solomon's
Anti-Virus Toolkit has this capability.
The extra drivers are available for download from the following
areas:
1. The Secure Computing area of the UK Computing conference on CIS.
2. S&S International's BBS for registered users: +44 (0)442 877883.
3. The a_v_toolkit/drivers conference on CIX.
If you require further information on the SMEG virus please contact
S&S International:
Internet email: sands@cix.compulink.co.uk
Telephone : +44 (0)442 877877
Steve Quarella