home *** CD-ROM | disk | FTP | other *** search
- Version 2.20 - major changes:
-
- Very many virus names have been changed, in order to make the
- naming scheme more logical. Most new viruses now receive names of
- the form "family.xxxx", where xxxx is the infective length of the
- virus, and most old virus names have been changed accordingly.
-
- Version 2.20 - the following problems were found and corrected:
-
- The Antibase virus was only detected in COM files, not EXE.
-
- The Ginger.2774 virus was only detected in boot sectors, but not
- identified properly.
-
- The PH33R virus was not detected in Windows applications, just DOS files.
-
- Version 2.20 - the following false alarms were fixed:
-
- EMPRL03.COM: MtE
- NC.EXE: Possibly a new variant of Civil_Defense
- NGBOOT.EXE: Possibly a new variant of AntiCAD
- POSCRN.QPP: MtE
- ROMSHELL.COM:Possibly a new variant of PS-MPC
- TSRCHK.COM: Possibly a new variant of Taz
- VEIJO.EXE: Possibly a new variant of Urfydus
-
- Also, VIRSTOP flagged some ProPack compressed files as containing
- the Over1644 virus.
-
- Version 2.20 - minor improvements and changes:
-
- Previously, if a small file was created which contained nothing but a
- short byte sequence, which happened to match one of the search strings
- F-PROT used, it would report "possibly a new variant of ...". This has
- been changed so that if the file is too short to contain a virus, nothing
- is reported.
-
- F-PROT now recognizes four new packers/wrappers (Hybrid, JD3, Teus
- and Ucexe), which used to trigger the heuristic scanner, but are
- now reported properly.
-
- F-PROT now detects programs that have been Trojanized by the Exebug virus.
-
- Invalid files (for example .EXE files with the entry point outside
- the loadable part) do not count as "suspicious" files any more.
-
- Version 2.20 - new viruses:
-
- The following 43 viruses are now identified, but can not be removed as
- they overwrite or corrupt infected files. Some of them were detected by
- earlier versions of F-PROT, but not identified accurately.
-
- _548
- Bane
- Burgar.560.BB
- Darth_Vader.411
- Itti.99.C
- Leprosy (534, 666.R, 666.S, 666.T and 792)
- Linda
- Marked-X.304
- MSK (272.B, 272.C and 284.B)
- Orce (67 and 71)
- PS-MPC (343 and 604)
- Quasar.422
- SillyOR (49, 66.B, 70, 76 and 83)
- Springs
- Terra
- Trelew
- Trivial (26.D, 29.F, 31.D, 34.B, 40.H, 41, 42.I, 53 and 119)
- VCL (341, 355, 407, 427, 645, Mindless.423.I)
-
- In addition, 2.21 detects the AOLGold Trojan
-
- The following 290 new viruses can now be removed. Many of them were
- detected by earlier versions, but are now identified accurately.
-
- _205
- _291
- _351
- _386
- _505
- _553
- _612
- _658
- _724
- _745
- _759
- _807
- _1314
- _1315
- _1647
- _1972
- Ahav
- Alex.818
- Antipascal.604
- Anthrax.B
- Armagedon (1065 and 1066
- Asahi (1045 and 1061)
- Australian_Parasite (231 and 279.B)
- Avalon
- Badsectors.3627
- Barrotes (1310.H and 1463)
- Beda.1530
- Bengal.1170
- Bero.1000
- Black_Jec.231.B
- Blink.495
- BootExe (453.A, 453.B and 453.C)
- BW.410
- Cascade (1701.AL, 1701.AM, 1701.AN, 1701.AO, 1701.AP and 1704.AC)
- Catherine
- CED
- Chomik
- Claws.569
- Clonewar (194, 200, 207, 220, 229, 235, 242 and 252)
- Clouds.705
- Combi.1106
- Conjurer (181, 265, 270, 277, 353 and 550)
- Continua.B
- Cor
- Coyote
- CPW.1457
- Creeper.482
- Dackness.1125
- Dagger
- Danish_Tiny (253, 263.B and 312)
- Dark_Avenger.2000.GoGo
- Dark_Revenge
- Darth_Vader.344.E
- Deicide_II (2403 and 2568)
- Dex
- Diablo
- Diamond.1024.D
- Drunk.527
- EM
- Fis
- Flame.B
- Flying.633
- Freedom.2448
- Genvir (1504 and 1808)
- Ginger.2620
- Gippo.Bumpy.B
- Gidra.506
- Golgi.608
- Green_Caterpillar (1575.K and 1618)
- Gynx
- H8
- Hates.190
- Heja (511.B and 511.C)
- Helloween (1376.B, 1376.C, 1376.D, 1376.E and 1376.F)
- Hellspawn.1075
- HLL.10217
- HLLC.12573
- Ibqqz
- Intruder (2050 and 2051)
- IVP (336, 568, 585, 592, 594, 652, 668.B, 694, 724, Hot_Zone.539
- and Hot_Zone.642)
- Jerusalem (679, 880, 1013, 1024, 1234, 1478, 1548, 1587, 1624,
- 1653.A, 1653.B, 1653.C, 1653.D, 1747.B, 1808.Frere.K,
- 1808.sUMsDos.AS, 1808.sUMsDos.AT, 1808.sUMsDos.AU,
- 1808.sUMsDos.AV, 1805.sUMsDos.AW, 2368, Sunday.P and
- Sunday.T)
- Katvir
- Keeling
- Kode_4 (399.B and 412)
- Kolumna.1100
- Leda
- Leech.1008
- Little_Brother (276 and 398)
- Lordzero (370 and 374)
- Malaise.D
- Mario.661
- MDS.331
- Megas.932
- Mephisto.510
- Minnie
- Mixture.1000
- MR
- MSU.297
- Murphy (HIV.D and HIV.E)
- Natas.4740
- No_Frills.1358
- NotStoned
- November_17th.768.E
- Ntmy
- Odo (816 and 930)
- Opal
- Open (1569 and 1581)
- Overboot
- Peligro.1208
- PH33R
- Phi
- Pihenj
- Pixel
- Platov
- PS-MPC (G2.312, 306, 331.C, 465, 475, 603.D, 696, 697, 719, 1242,
- G2.585.C, Joshua.985 and Skeleton.598.G)
- Pure.439
- Quell
- Quick
- Quish.303
- Reverse.C
- Riihi.258
- Riot (1299, 1305 and 1415)
- Rip.3214
- RMC
- Rocket
- Rodolf.4096.B
- Salamander
- Scotch
- Serve.905
- Seventh_son.334
- SillyC (101, 109, 110, 162, 184, 186, 226, 254.A, 254.B and 559)
- SillyCR (125.B, 303 and 3152)
- SillyER.168
- Sofia_term (1393 and 1487)
- Solar (100, 102 and 122)
- Span.1127
- Src.65
- Stat
- Stoned (Dinamo.B and Dinamo.C)
- Suriv_1 (941 and 1000.B)
- Swiss_boot.B
- Tai-Pan.438.C
- Tankar.212
- Teh
- Three_Months.509
- Tib
- Timid (245, 289 and 302.B)
- Titanium
- Undershove
- VCL (229, 331, 339, 343.A, 343.B, 395, 401, 432, 453, 485, 513,
- 517, 570, 606.B, 609.B, 659, 708, 715, 851.B, 909, Spam, VCC.343 and VCC.353)
- Vienna (595, 648.AG, 648.AH, 895, Iraqui_Warrior.C, Violator.716.B
- and W-13.600)
- Virdem.1336.German.C
- Won't_Last
- WSI
- WZ (436.A and 465.B)
- Xiv
- YB.8588
-
- The following 108 new viruses are now detected and identified but can not
- yet be removed.
-
- _732
- _2158
- Air_Raid.330
- Andris
- Annihilator (208, 272.B, 276, 298, 299, 305, 308, 314, 361, 383,
- 394, 416, 453, 510, 548, 596, 603, 673, 733 and 739)
- Attitude.823
- Caos
- Conjurer (300, 312, 377, 408, 433, 506, 510, 586 and 886)
- Crazy_Frog
- Dan (1092 and 1871)
- Digdeath (1062 and 1153)
- Entity.1997
- Explorer.3037
- Father_Mac.1382
- Grace
- Hello.430
- Int13.B
- IVP (421, 534, 632, 653, 673, 674, 677, 682, 683, 693, 703,
- 786, 967, 999, 1017 and Insomnio)
- Kato.1536
- Lapidario (768 and 787)
- Lost_Friend (881 and 882)
- Lucifer
- Marbas.1303
- M01
- MPTI.1536
- Nightfall.5764
- NRLG (575, 587, 624, 654, 655, 656, 719, 727, 834, 899 and 982)
- No_of_the_beast.AC
- Pizelun.3599
- PS-MPC.583
- Psychosis.991
- Qtiny.162
- Quish.398)
- Red_October.584
- Red_Zar (461 and 467)
- Rider.575
- Riot.Carpe_Diem.1012
- Rubbit.1274
- Spec
- Split_Second.1120
- St_R
- Thirty_First
- Tigre.1800.B
- Valid.821
- Vampiro.1623
- VCL (VCC.367, VCC.438 and VCC.571)
- WordMacro/Colors
- Zmia
-
- The following 5 new viruses are now detected, but not identified.
- F-PROT will just report the family name with a (?) or report the
- virus as "New or modified variant", as it is not yet able to determine
- which variant it is dealing with. Disinfection of these viruses is not
- yet possible.
-
- Avispa (C, D, E and F)
- FinnPoly
-
- The following 3 viruses which were identified by earlier versions can
- now be removed.
-
- Boot-437
- Com2S
- LV
-
- The following viruses have been renamed:
-
- _1798 -> Com2S.1798
- Espejo -> Fifteen_Years
- TheDraw -> Draw
- Vienna.IWG -> Vienna.Iraqui_Warrior.B
-
-