home *** CD-ROM | disk | FTP | other *** search
Text File | 1994-02-03 | 36.1 KB | 1,182 lines |
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- ::::::::::::: B O O T X R E C O G V E R S I O N 1.8 9 ::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
-
- 32.216 bytes
-
-
- MADE BY SAFE HEX INTERNATIONAL
- Programmer Michael Nielsen
-
-
-
- Release date 19-11-93
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
-
-
-
- THE BOOTX RECOG VERSION 1.89 KNOWS THESE NEW VIRUSES:
-
- Fred Choen bootvirus
- Digital Dream virus installer
- Digital Dream boot virus
- Sentinel bootvirus
- Leviathan file + bootvirus
- Creeping Eel bootvirus bug corrected
-
- The german BootX locale is now "finished". A very excellent work thanks to
- Steffen Salzmann, Germany!
-
-
-
- THE BOOTX RECOG VERSION 1.85 KNOWS THESE NEW VIRUSES:
-
- Descriptor 3.0 Trojan
- Cascade ID92 bootvirus
- Creeping Eel bootvirus
- Detlef bootvirus
-
- Our thanks are going the following excellent guys for the support of these
- new viruses. Without these excellent guys there have not been a new update:
-
-
-
- THE FORMER BOOTX RECOG VERSION 1.80 HAVE ADD THESE NEW VIRUSES TOO:
-
- Access Forbidden bootvirus.
- Dum II Dum bootvirus.
- The European Disaster bootvirus
- TTK Virus bootvirus
- Message Acid Link Virus
- Thaho8 2.0 Virus bootvirus
- The Fuck infector (ModemCheck).
-
-
-
- Our thanks are going the following excellent guys for the support of these
- new viruses. Without these excellent guys there have not been a new update:
-
- Rune Goksør, Norway. Ulrik Nielsen, Denmark. Gert Lamers, Holland. David
- Elmquest Denmark. Jim Maciorowski, USA. Martin, Austria. Sten Andersen,
- Denmark. Torben Danø, Denmark. Kosta Angelis, Greece. Alex Dimitriadis
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
- THE NEW VIRUSES IN THIS UPDATE:
-
- Fred Choen A ordinary bootvirus, which only infects Kickstart
- 1.3 Amigas. In the bootblock you can read: "Fred
- Cohen the university of California"
-
-
-
-
- Digital Dream trojan This virus is original spreaden as a powerpacked
- file 6496 bytes. Unpacked 9960 bytes. DigitalDreams
- pretend to be a virus killer for the Jeff viruses,
- but false don't trust it, it installs a bootvirus.
-
- 1. When the Digital Dream is executed you gett a big red
- cross on a black background and below at the screen
- you can read:
-
- This is the: Jeff-Viruskiller V2.67 press left mouse-
- button to continue.
-
- 2. Then you get a blue/black text on a grey background
- in the next screen and the following text:
-
- Jeff-Viruskiller V.2.67
-
- Please inset a disk in drive 0. Then press left
- mouse-button to kill Jeff on it.
-
- 3. If you don't have an unprotected in this drive you
- will be asked to remove the write-protection!
-
- But if your disk isn't write-protected, the disk will
- be infected with the virus long time before you press
- the left mouse-button!
-
-
-
-
- Digital Dream virus This is the bootvirus, which is installed by the
- DigitalDream trojan. The bootvirus is spreading at
- kickstart 2.0 and it is a mutation virus. That means
- the virus is changing it's code every time the virus
- infects a new disk.
-
-
-
- Sentinel This virus is called USSR 492 too. It is a ordinany
- bootblock virus which writes itself to $7f400 in
- memory without allocating memory. The Sentinel virus
- is a "Excrement" virus clone only the text is changed.
-
- The only destructive thing it does is to overwrite
- any bootblock, which hasn't been infected yet. This
- virus is quite harmless, and don't infects disks, if
- you run kickstart 2.0-3.0.
-
-
- Leviathan This virus is a multihead virus, that means the virus
- is both a bootblock and a file virus (1056 bytes)
- like the "good" old CCCP virus and the later Starcom
- 1, and Irak 3 CCCP clones.
-
- The above means, that the file virus part is able to
- infect a bootblock with the bootvirus part of this
- virus and - the bootvirus part can of course infect a
- new file virus part. By kickstart 1.3 -2.0 the virus
- will guru and can't infect.
-
-
- ATTENTION
- The virus file-part is changing in the first line of
- the startup-sequence:
-
-
- Original startup-sequence: setpatch
- Infected startup-sequence: s/..setpatch
-
- (Remark you have to correct this line by yourself).
-
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
- THE FORMER RECOG 1.85 VIRUSES:
-
- Descriptor 3.0 This virus is original spreaden as descr4.0.lha or
- -z-speed.lha = 3484 bytes, from some pirate BBS'es:
-
- descr4.0.lha 3484 bytes. The new DescriptorV4.0 with
- new POWER Snap.... Run without Snap in background and
- you will see the new Powersnap 120 % faster in copy
- Descriptions.
-
-
- Or renamed to the following:
-
- -z-speed.lha 3484 bytes ZENITH MODEM SPEEDER
-
-
- When unpacked you got a file: descr4.0.exe 7016 bytes
- (When spread as descr4.0.lha file. I dont't know
- anything about the -z-speed.lha yet)
-
-
- SOME FACTS:
-
- . There is no docs with this file, but the program looks
- like a kind of scene-utility or like.
-
- . The unpacked "Descriptor 3.0" bomb is 7016 bytes.
- Please remark IT ISN'T .....the 4.0 version, but a 3.0
- version!
-
- . The "Discriptor 3.0" needs a file named "descriptions.
- txt" placed in the S/Dir, if not the descriptor will
- guru.
-
- . If executed the "Discriptor bomb" will tell, that it
- need a file called "Snap" in memory or tries to load
- it from the C/Dir., Don't trust this...
-
- . In fact you Amiga will get the following command:
- "Delete :#? all"
-
- . And OH, NO GUESS WHAT......your whole harddisk or disk
- will be deleted! (Not formatted)
-
- . This trojan can't infect and be spreaden. It can ONLY
- DAMAGE IF EXECUTED - A REAL TROJAN!
-
-
-
-
- Cascade 2.1 This bootvirus does not need the trackdisk.device. In
- the bootblock you can read the following ASCII text:
- "Cascade V2.1CCount".
-
- . By using Kickstart 2.0 and later versions you will
- probably get a guru.
-
- . By using Kickstart 1.3 your mousepointer will be
- transformed into a penis.
-
-
-
-
- Creeping Eel This bootvirus does not need the trackdisk.device. As
- soon as the counter reaches the value $14 you will get
- the German flag colors on the screen. In the bootblock
- you can read the following ASCII text: :
-
- "Hello Computerfreak. You've got now your first virus.
- The Creeping Eel. Many disks are infected ! Written by
- Max of Starlight 29.04.1992 <<MAX>>".
-
- . Damage: Over writes bootblock. But even worse.... this
- virus can damage your disks or harddisk too. The virus
- writes garbage in a cylinder on your disks or harddisk
- On disks the root-Cylinder will be damaged.
-
-
-
- Detlef This bootvirus does not need the trackdisk.device.
- When the virus is active you will get the following
- message:
- Guten Tag.
- » Ich heiße DETLEF «
- Ich werde Sie in der nächsten Zeit etwas nerven.
- Gemacht wurde ich von · M A X .
-
- (You can see again...... an other german lame virus
- programmer, who are working in the night with the holy
- spirit and flame, until the police a day will come and
- catch him)
-
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
- THE FORMER RECOG 1.80 VIRUSES:
-
- Access forbidden: This one display a picture at boot time. It then
- modifies the disk boot sector. And then it makes the
- disk to a "not a DOS disk". The picture shows an
- access forbidden logo. This is the reaction of Access
- forbidden being run with Kickstart 3.0.
-
-
- Dum II Dum: This virus is not a link virus nor a filevirus,
- it is not even a true boot virus. It fills about
- the first 4 sectors of the disk included the 2 boot
- sectors. The thing it does on boottime is that it will
- Allocate memory as low as possible. and then load the
- sectors 2-4 into that area, from there the virus will
- infect your other disks.
-
-
- European Disaster: It's a ordinary bootblock virus, which can't infect
- Amiga with Kickstart >1.3, but will guru if you boot
- infected disks at kickstart 2.0.
-
-
- TTK Virus: It's a ordinary bootblock virus, which can't infect
- Amiga with Kickstart >1.3, but guru if you boot the
- disk at kickstart 2.0.
-
-
- Message Acid Virus: A very nasty easy spreaden linkvirus, which can
- affect a lot of damaged files on your harddisk. Take
- care fellows.
-
-
- Thaho8 2.0 Virus: It's a very nasty bootblock virus.
-
-
- The Fuck Infector: This virus is original spreaden in a file named
- MCheck.lha 16.772 bytes, which should pretend to
- be a modem checker program: "MODEMCHECK V1.1 (07.05.
- 93) Copyright 1993 by Mario Zeltik". But false the
- Modemcheck program is a trojan, which install a new
- "LoadWB" the virus itself 3604 bytes.
-
- BootX will recognize the unpacked version (but still
- CrunchMania packed) 15516 bytes, the unpacked Modem-
- Checker 22252 bytes and the "LoadWB" containing the
- virus part, which cause all the damage.
-
- It's very nasty one. The fuck virus, will not activate
- itself if SnoopDos is active. This trojan "loadwb"
- will start the horrible damage, if you don't use your
- keyboard 10 minutes. After that time your harddisk
- will be low level formated filling casually all the
- tracks with: FUCKFUCKFUCK.. and so on.
-
- The only way to get rid of the Fuck virus, is to
- delete the ModemCheck program.
-
- * REMEMBER to delete the loadwb i the c directory too!
- Here you have a screen dump:
-
- MODEMCHECK V1.1 (07.05.93)
- Copyright 1993 by Mario Zeltik. All Rights Reserved
-
-
- Checking CTS Line.....................Ok!
- Checking CD Line.....................Ok!
- Checking DTR Line.....................Ok!
- Checking RI Line.....................Ok!
- Checking TXD Line.....................Ok!
- Checking RXD Line.....................Ok!
- Checking RTS Line.....................Ok!
-
- (Yes excellent inded?, "Fuck me", but my modem wasn't
- connected !!!!!!!)
-
- BootX will recognize the unpacked version (but still
- CrunchMania packed) 15516 bytes, the unpacked Modem-
- Checker 22252 bytes, and Loadwb 3604 bytes.
-
-
- I have got this excellent analyse from Bjørn Rese from
- the University of Odense, thank you Bjørn!:
-
- Type: File (Trojan)
- Alias: MODEMCHECK
- Origin: Modemchecker in MCheck.lha
- Infect: C:LoadWB
-
- SHORT: Destroys contents of harddisks
-
-
- LONG:
- MCheck.lha (size: 16772 bytes) contains
- Modemcheck.doc (size: 2227)
- Modemchecker (size: 15516, version: V1.1 (07.05.93))
-
- Modemchecker is packed with CrunchMania. Unpacked size
- is 22252 bytes.
-
- Modemchecker is a phony. It pretends to check various
- modem lines (CTS, CD, DTR, RT, TXD, RXD, RTS), but it
- reports success no matter what (even if no modem is
- attached.) When Modemchecker is started it will write
- the virus to C:LoadWB (new size is 3604 bytes.) Next
- time C:LoadWB is started (typical at startup) the
- virus will become active.
-
- The virus in LoadWB launches a new task using
- CreateProc. The new task is called Diskdriver.proc
- (stack = 4096, priority = 0). Afterwards it proceeds
- with the original LoadWB ("$VER loadwb 38.9
- (30.3.92)",10,13,0).
-
- The Diskdriver.proc task is the malicious part. It
- waits for 30000 ticks (ticks/50 seconds for PAL,
- equals 10 minutes, ticks/60 for NTSC), when it fills
- an internal buffer of 150000 bytes (allocated by a BSS
- section (HUNK_BSS)) with FUCKFUCKFUCK... It tries to
- open a file called S:HORSE. If it was successful the
- virus will gracefully exit, if not it will cause
- havoc. It will examine all physical devices (dn_Type
- = DLT_DEVICE), and pick out all where (de_numheads >
- 2) OR (de_uppercyl >= 90) OR (de_blkspertrack > 22)
-
- Then it will write the content of the internal buffer
- (FUCKFUCK...) on all track from the lowest cylinder
- (de_lowcyl) to the highest cylinder (de_yppercyl) of
- all selected devices (typical harddisks). When it
- exits.
-
-
- Observations:
-
- The programming style is pretty clean which indicates
- a rather experienced programmer. He's probably from
- Europe (30000 ticks yields exactly 10 minutes by 50Hz
- powersupplies.)
-
- S:HORSE seems to be a safety line for the programmer
- (and his friends (if he has any :-))
-
- It doesn't destroy ordinary floppy disks.
-
- Destruction is performed at exec.library level (using
- DoIO)
-
-
- Notes:
-
- Some uncorrect things have been said about the FUCK
- virus.
-
- [1] "The 'LoadWB' that contains the virus is the 2.1
- version, so the virus isn't danger for any machine
- with 1.2 or 1.3."
-
- [2] "Before the infection begins a couple of tests is run:
- - execversion = 37.132 = KS2.04 . If no there's NO
- infection. The program just stops. This means no
- danger to owners of A600, A600HD and so on."
-
- Deadly wrong! Even though LoadWB will fail because it
- requires at least V36 (dos.library) it has already at
- this point launched the virus, which doesn't require
- any particular version of the OS. I tested this on
- 1.2, and the Diskdriver.proc was running.
-
- [1] "Once installed at the boot Fuck Virus will wait
- patiently and if not IDCMP message of any type is
- registered [...] 10 minutes, it will proceed...""7.
-
- [3] This trojan "loadwb" will start the horrible damage,
- if you don't use your keyboard 10 minutes."
-
- The havoc start (provided S:HORSE wasn't found) after
- approx. 10 minutes (30000 ticks) no matter what IDCMP
- messages is registered. It doesn't care about user
- interaction.
-
- [4] Casual filling of the tracks
-
- Data isn't destroyed randomly, but very
- systematically. From the lowest cylinder to the
- highest. The reason why it seems random is probably
- due to the fragmentation of the harddisk.
-
-
- [1] FuckVirus.doc by Gabriele Greco, author of
- FuckChecker (Fuckchck.lha).
-
- [2] VT.Knows by Heiner Schneegold, author of VT.
-
- [3] VirWarn-1b by Erik Loevendahl Soerensen.
-
- [4] Everybody, except me ;-)
-
- Analysed by
-
- Bjorn Reese.
- SAFE HEX INTERNATIONAL
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
- WHY THIS NEW SHI UPDATE
- Concerning the serious lack of new viruses and the absence of support from
- the users Peter Stuer have send the following 2 messages explaining, why he
- have stopped to make future updates:
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
- MESSAGE 1:
-
- Area: BOOTX
- From: Peter Stuer (2:292/603.7)
- To: All
- Subj: End of BootX
-
- Dear users,
-
- after nearly 4 years of virus hunting I have decided to leave the challenge
- to other programmers. During the last year a few of nice competitors have
- emerged in the anti-virus scene (I will not mention any names). It is up
- to their programmers to fill the possible void that BootX leaves.
-
- The last BootX version released was BootX 5.23a Recog 1.75. This version
- has apparently rapidly aged. At the time 60 and 90 days seemed extremely
- long times between updates. However, during the last 2 months I have not
- received any new viruses, which explains the aging of BootX.
-
- I hope all BootX users find another viruskiller to replace it. Thanks for
- all your support.
-
- Peter.
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
- MESSAGE 2:
-
- Dear user,
-
- Ever since I stopped the BootX development, SHI has been pressing me to
- either continue BootX or to release the source to them. The first is
- impossible and the latter not appealing.
-
- However, to make the transition more smoothly, I have released this patch
- to BootX 5.23a. It will no longer bug you with the date requesters.
-
- Also in this archive you will find BootX.Recog library 1.75a which also has
- the date check removed.
-
- NOTE: These are patches done by me, Peter Stuer. This is a one of a kind
- event. I am sending the source of the Recog library to SHI in Denmark.
- They will decide if anyone of their programmers is going to pick up the
- release of new BootX Recog libraries.
-
- If you doubt the authentity of this patch, feel free to drop me a Netmail
- at Fido 2:292/603.7.
-
- Peter.
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
-
- SHI NEED YOUR HELP FOR FURTHER UPDATES!
- --------------------------------------
-
- First I would like to thank Peter Stuer for the excellent job he did with
- BootX. Thanks Peter from all of us.
-
- As you can see of the above, the development of BootX was stopped for some
- time. I am doing my best to keep BootX up-to-date with all the latest
- viruses. BUT I need YOUR....support too. Please send all new vira to me,
- or to the nearest SHI virus center.
-
-
-
- SHI NEED YOUR HELP FOR FUTHER LOCALE SUPPORT!
- -------------------------------------------
- For futher locale support I need help to get the BootX menu localized for
- the following countries: Spanish, Turkish, Portuguese, Polish, Finnish,
- Greek and of course every country, which isn't localized yet. Please send
- your locale translation direct to me:
-
-
- Programmer: Michael Nielsen
- Østeralle 44
- 6500 Vojens
- Dk. Denmark
-
- Phone: +45 74-540416
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
- VIRUSES WANTED FOR NEW BOOTX UPDATE
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
- IF you find new viruses , please send them TO DAY..........! I am currently
- searching for the following viruses :
-
- A.H.C.virus.BB
- Aibon (776) Infiltrate or damage BBS
- Aibon2 (784) Infiltrate or damage BBS
- Aibon-ACP.ctrl
- A.I.S.F. Virus (8708)
- Amida.BB
- AmiPatch virus 1.0a (8288) Infiltrate or damage BBS
- Angel.BB
- Anti-Knacken.BB.(Sca clone)
- Antichrist.Link.(Jeff.clone)
- Antivirus.BB
- Australian.Paradise-BB
- BB-Prot.BB
- Beethoven.(2608)
- Bestial-Devastation Link (7876)
- BGS-9.III.(File.2608)
- Black.Knight.BB
- Blockchain.Virus
- Boot-Aids.BB
- Cascade 2.1.BB
- Butonic 4.55
- Charlie.Brown.(Hireling).BB
- Check.Filevirus.(18644)File
- Christmas.Violator.(1060).Link
- Clock.1.1.(setmap.&.S.Install)
- Clockvirus.(Back-running)
- Clockvirus.(Fast running)
- Commodore.BB
- CompuPhagozyte 7 File
- CopyLock-Virus.BB block 0-3
- Cracker Exterminator.BB
- Creeping-EEL.BB
- Dailer.BBS.v2.8g.(33908) Infiltrate or damage BBS
- Datacrime-killer.BB (ASV clone)
- Detlef.BB
- Devil.11.B.Door.(3 files, 23452, 2342, 17884) Infiltrate or damage BBS
- Devil.V8.B.Door-Swiftware-(44224) Infiltrate or damage BBS
- Dialer.2.8g.(33908) Infiltrate or damage BBS
- Disgust.BB
- Disgust.BB
- Disk-killer.v1.0.(File1368)
- DiskRepair V.1.2 BBS virus (49336) Infiltrate or damage BBS
- DiskRepair V.2.6 (37740)
- DiskRepair BBS-Link (xxx)
- Disk.Speed.Check.1.01 (DSC101)
- Disktest virus (1368)
- Disktroyer v2 (812)
- Dlog V1.8 Messagetop BBS Infiltrate or damage BBS
- DOpus.(6408). Infiltrate or damage BBS
- DwEdit v1.62 infected with aibon2 (43700) Infiltrate or damage BBS
- Excrement-Installer
- Executors.BB
- Freshmaker virus.BB
- Fuck.device.virus.BB
- G-Zus Packer (15016)
- Gandalf.BB
- GCA.BB.(Forpip.clone)
- Genetic.Protector.2.0 BB.(Dotty clone)
- Guardian.DMS Infiltrate or damage BBS
- Guardians Boot Aids.BB
- Hackers.Etic
- Happy.New.Year.BB
- Hardex.Saddam.Clone.(1848)
- Hill.BB
- HNA.Virus.BB
- Hunk-Lab.link
- Indiana.Jones.BB
- Infector.BB (Fast Eddie clone)
- Influenza.BB
- Ingo's.Return.BB
- Jeff-Butonic.3.10(2916)File
- Jeff-Butonic.3.20.(2900)File
- Jismtro.exe Infiltrate or damage BBS
- KaKo.BB
- Kefrens.I.BB
- Kefrens.II.BB
- Killed.virus.BB
- Killkim.exe Infiltrate or damage BBS
- Kobold.II
- Lame.Saddam.Clone.(1848)
- Laurin.Saddam.Clone.(1848)
- Leviathan.BB
- Leviathan file (1056)
- Lupo (1484)
- MAD.IIa.BB
- Message link virus
- MegaMon.PP-Bomb (26856) Infiltrate or damage BBS
- MemSearcher virus.BB
- Monkey-Killer.BB
- Mount.Virus.(1072)
- Mutilator.BB
- MVK.(1052)File
- MWB.BB virus (Julie clone)
- Ninja.file.virus
- Noname.2.BB
- Nano2
- Ohio.BB
- Overkill.BB.(block.1-3)
- P-Cracks.BB
- PayDay.BB
- Phatasmic.Force
- PowerTeam.BB
- PStats.(19784)File Infiltrate or damage BBS
- Rimednac.BB
- Saddam clone Lame (1848)
- Saddam clone Hard (1848)
- Saddam clone Laurin (1848)
- Saddam clone Animal (1848)
- Saddam clone Kick (1848)
- Saddam clone Nato (1848)
- Saddam clone Affe (1848)
- Saddam clone Iran (1848)
- Saddam clone Gral (1848)
- Saddam clone 1.29 (1848)
- Saksen.no.2.BB
- Sao.Paulo.BB
- Satan.BB
- Schwartznegger
- SCSI-Virus (1560) file
- Sepultura. (1876) file
- Sentinel.BB
- Shit.Virus.(Nuked.007).BB
- SMBX-Mount.Installer.(64488)
- SnoopDos 1.9 Trojan (sd-tv)
- Swiftware 0.98 (44224) Infiltrate or damage BBS
- Suicide.BB
- Sysinfo 1.1 (5680) Infiltrate or damage BBS
- Sysinfo 2.2 (5656) Infiltrate or damage BBS
- Suntron.BB
- T.ET.E BB.Zombi.Clone
- T.ET.E-BB.Zombi.Clone
- Telecom.(756).File
- TimeDate
- TimeDate.Setmap
- Timer.virus.setmap(1712) Infiltrate or damage BBS
- Thaho8 2.0
- Tomates Gentechnic Service 2
- Topdog.1.0 / TopUtil (2260) Infiltrate or damage BBS
- Tristar.Viruskiller-1.0.Virus.BB
- Trojan.Killer Infiltrate or damage BBS
- TTK.virus.BB
- UCA.BB
- UcAIDS.BB
- Uhr 492 virus.BB
- UInfo (13048) Infiltrate or damage BBS
- Ulog V1.8 Messeagetop BBS Infiltrate or damage BBS
- Umyj.Dupe.virus BB
- USSR 492.BB (excrement clone)
- VirConSet virus 1 BB
- VirconSet virus 2 BB
- Virkill.2.BB
- Virus.II
- Virus Construktion Set File virus
- Virus.Terminator.6.0 (Trojan 1880)
- Virusmaker.1
- Wahnfried.BB
- Warhawk 2 BB
- Witebox v 8.0 Trojan (34896) Infiltrate or damage BBS
- WiteBox BBS-Link (xxx)
- XaCa virus (1368)
- XLink.3.0
- XprSpeed.3.2 (9556) Infiltrate or damage BBS
- X-Copy2.BB
- X-Ripper 1.1 (41360) Infiltrate or damage BBS
- Zenker.BB (4 sectors)
- Zorro/Willow.BB
- ZSpeed (9556) Infiltrate or damage BBS
- Zviruskiller.1.5.BB
-
-
- And......infected disks with "French Kiss virus" and "ABC virus" containing
- the whole viruses (Block 0-3- or 4). I ONLY..have the first 1024 bytes!!!!!
-
-
-
- And of course I will be very happy for any NEW.... virus you might find !
-
-
-
- Please..mark the disk "Attention Virus"(please take care of my hard disk)
- Remember to state your address and phone number if you want a reply, but
- isn't necessary if you want to be anonymous, only the VIRUS counts. (I
- don't care, what "KIND" of disk you send me). After the disk is analyzed
- the disk is formatted and your name, will be 100 % arcivated in my
- trashcan. I.... ALWAYS keep my promise!!, (no more questions then!)
-
-
-
-
- SEND A LETTER PLEASE:
- An EASY..way is to send the viruses to your regional center, who will then
- send them along to me:
-
-
-
- SHI REGIONAL VIRUS CENTRE HOLLAND:
- ---------------------------------
- Marco van den Hout
- Doornboomplein 9
- NL-5081 GR Hilvarenbeek
- The Netherlands
-
- Phone + 31 04255 3513
-
-
-
- SHI REGIONAL VIRUS CENTRE AUSTRALIA:
- -----------------------------------
- Amiga Quarantine
- Brian & Rick Logan
- P.O. Box 533
- Engadine
- N.S.W 2233
- Australia
-
- (No phone)
-
-
-
- SHI REGIONAL VIRUS CENTRE SLOVAKIA:
- ----------------------------------
- Ondrej Krebs
- SNP 4
- 908 51 Holic
- Slovakia Republic
-
- Phone: + 0801 3764
-
-
-
- SHI REGIONAL VIRUS CENTRE CZECH:
- -------------------------------
- MB Soft
- Dalimilova 6
- 130 00 Praha 3
- Czech Pepublic
-
-
-
- SHI REGIONAL VIRUS CENTRE DENMARK:
- ---------------------------------
- Jan Andersen
- Veronikavej 33 I tv.
- 2610 Rødovre
-
- Phone + 31 41 68 67
-
-
-
- SHI REGIONAL VIRUS CENTRE ITALY :
- -------------------------------
- Massimo Gais
- V. Vittorio Veneto 31
- 80029 S. Antimo (NA)
- Italy
-
- Phone + 39 81 5052256
-
-
-
- SHI REGIONAL VIRUS CENTRE ENGLAND:
- ---------------------------------
- Paul Browne
- 304 Leeds Road
- Eccleshill
- Bradford
- W.Yorks
- BD2 3LQ
- England
-
- Phone + 44 274 631 041
- Fidonet 2:256/301.2@
-
-
-
- SHI REGIONAL VIRUS CENTRE GREECE:
- --------------------------------
- Konstantinos Angelis
- 29 Sokratus Str.
- GR-42100 Trikala
- Greece
-
- Phone: +30 431 29207
- Fax : +30 431 38214
- BBS : +30 431 72171
-
-
-
- SHI REGIONAL VIRUS CENTRE BELGIUM:
- ---------------------------------
- Dutch Language:
-
- Koen Peetermans
- Vrijheersstraat 8
- B-3891 Gingelom
- Belgium
-
- Phone: + 32 11 48 58 19
-
-
-
- SHI REGIONAL VIRUS CENTRE BELGIUM:
- ---------------------------------
- French Language:
-
- Gregoire Jean-Christophe
- 64 Franstimmermansstraat
- 1600 Sint Pieters Leeuw
- Belgium
-
- Phone: + 02 377 76 78
-
-
-
- SHI REGIONAL VIRUS CENTRE SPAIN:
- -------------------------------
- John Lohmeyer
- Parque Guell 7
- 08338 Premia de Dalt
- Barcelona
- Spain
-
- Phone: + 03 752 38 85
- Fax : + 03 752 30 79
- BBS : + 03 892 39 83
-
-
-
- SHI REGIONAL VIRUS CENTRE GERMANY:
- ---------------------------------
- Dirk Rose
- Amalien Str. 75
- D-46537 Dinslaken
- Germany
-
- Phone: + 49 20 64 78 56
-
-
-
- SHI REGIONAL VIRUS CENTRE SWEDEN:
- --------------------------------
- SHI SVERIGE
- Box 1220
- 501 12 Borås
- Sweden
-
- Phone : + 033 121118
- BBS 1 : + 033 291812
- BBS 2 : + 033 200249
- BBS 3 : + 033 200949
-
-
-
- SHI REGIONAL VIRUS CENTRE POLAND:
- --------------------------------
- Wojtek Gorzkowski
- UL. Rewolucji Pazd 95/102
- 01-242 Warsaw
- Poland
-
- Phone : + 48 22 367 443 (18.00-20.00)
- Phone : + 48 26 252 994 (10.00-17.00)
- BBS : + 48 22 367 443 (20.00-08.00)
-
-
-
- SHI REGIONAL VIRUS CENTRE FRANCE:
- --------------------------------
- Brun Stephane
- 255 Chemin Fontisson
- F-84470 Chateaneuf de Gadagne
- France
-
- Phone : + 90 22 54 22
-
-
-
- SHI REGIONAL VIRUS CENTRE NORWAY:
- --------------------------------
- Kurt Hansen
- Langøyveien 13
- N-4026 Stavanger
- Norway
-
- Phone : + 47 4 520420
-
-
-
- SHI REGIONAL VIRUS CENTRE EAST ASIA:
- -----------------------------------
- Javed Islam
- P. O. Box 10119
- Feroze Pur Road
- Lahore 54600
- Pakistan
-
-
-
- SHI REGIONAL VIRUS CENTRE YUGOSLAVIA:
- ------------------------------------
- Nikolic Tomislav
- Vase Stajica 3
- Sombor 25000
- Yugoslavia-Serbia
-
- Phone: + 382 520 189
- BBS : + 813 849 4034
-
-
-
- SHI REGIONAL VIRUS CENTRE ARGENTINA:
- -----------------------------------
- Pablo A. Trincavelli
- Dorrego 459 1 er. piso
- 2000 Rosario
- Santa Fe
- Argentina
-
- Phone: +54 41 252906
-
-
-
- SHI REGIONAL VIRUS CENTRE FINLAND:
- ---------------------------------
- Johannes Verwijnen
- Hiihtomäentie 33 B 16
- SF-00800 Helsinki
- Finland
-
- Phone: 358 0 759 1263
- Phone: 358 0 787 449
-
-
-
-
- SHI REGIONAL VIRUS CENTRE PORTUGAL:
- ----------------------------------
- Alexandre Manuel Reis
- Casal de Sào Bràs
- Rua Antònio Nobre, Lote 5, R/C DTO
- 2700 Amadora
- Portugal
-
- Phone: + 351 01 494 8932
- Fax : + 351 01 494 4662
-
-
-
- SHI REGIONAL VIRUS CENTRE SWITZERLAND:
- -------------------------------------
- Meier Remy
- Hardstrasse 111
- CH-4052 Basel
- Switzerland
-
- Phone: + 41 61 312 63 95
- Fax : + 41 61 312 63 95
-
-
-
- SHI REGIONAL VIRUS CENTRE SOUTH AFRICA:
- --------------------------------------
- Richard Harris
- P.O.Box 3147
- 1610 Edenvale
- South Africa
-
- Phone: + 27 011 453 6327
-
-
-
- SHI REGIONAL VIRUS CENTRE TURKEY:
- --------------------------------
- Volkan Uçmak
- Sakiz Sok. Berkel Ap. 6/2
- 81300 Kadiköy Istanbul
- Turkey
-
- Phone: + (1) 346 86 48
- Fax : + (1) 349 96 35
-
-
-
- SHI REGIONAL VIRUS CENTRE AUSTRIA:
- ---------------------------------
- David Van Assche
- Sieveringer Strasse 126, 4
- Vienna 1190
- Austria
-
- Phone: + 222 44 39 91
- Fax : + 222 44 42 51
-
-
-
- SHI REGIONAL VIRUS CENTRE IRELAND:
- ---------------------------------
- Anthony Melia
- 4 Seagrange Drive
- Baldoyle
- Dublin 13
- Ireland
-
- Phone + 01 39 31 23
-
-
-
- SHI REGIONAL VIRUS CENTRE IRAN:
- ------------------------------
- Soroush Khalatbari
- 3floor 32, Mehraban
- Eskandari-Jonobi street.
- 13116 Tehran
- Iran
-
-
-
- SHI REGIONAL VIRUS CENTRE ROMANIA:
- ---------------------------------
- Prundeanu Cristian
- Str. Rodnei nr. 6
- 1900 Timisoara
- Romania
-
-
-
- SHI REGIONAL VIRUS CENTRE HUNGARIA:
- ----------------------------------
- Pista Palacy
- Szechenyi U. 55 II/1
- 7100 Szekszard
- Hungaria
-
- Phone: +36 74 3130 913
- Fax : +36 74 3130 913
-
-
-
- SHI REGIONAL VIRUS CENTRE CANADA:
- --------------------------------
- Ray J. Morrell
- 45 Salisbury Ave.
- Toronto, ON
- M4X1C5 Canada
-
- Phone: + (416) 324 9513
- BBS : + (416) 324 9439
-
-
-
- SHI MAIN CENTRAL VIRUS CENTRE:
- -----------------------------
- Erik Loevendahl Soerensen
- Snaphanevej 10
- DK-4720 Praestoe
- Denmark
-
- Phone: +45 55 992512
- Fax : +45 55 993498
-
-
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
- N E W V I R U S U P D A T E S F O R M O D E M U S E R S:
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
-
- IF YOU HAVE A MODEM. PLEASE SEND NEW VIRUSES DIRECT TO:
- ------------------------------------------------------
-
-
- . SAFE HEX INTERNATIONAL BBS - REGIONALE VIRUS CENTER DENMARK EAST
- BBS phone (+45) 3672 6867 - modem 14.400 V32 bis. Open 00-24:00
-
-
-
-
- Remember only the new virus count. We don't care,
- what kind of infected programs you send to us be quite sure.
-
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
-
- THANK YOU VERY MUCH FOR YOUR HELP TO IMPROVE BOOTX TO KNOW
-
- * EVEN MORE VIRUSES *
-
- WITHOUT YOUR HELP THERE HAVE BEEN NO BOOTX VIRUS KILLER TO-DAY
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
-
-
-
- THANK YOU VERY MUCH FOR YOUR HELP TO IMPROVE BOOTX TO KNOW
-
- * EVEN MORE VIRUSES *
-
-
-
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::