F-PROT Professional 2.26 Update Bulletin
========================================
Data Fellows Ltd, Paivantaite 8, FIN-02210 ESPOO, Finland
Tel. +358-9-478 444, Fax +358-9-478 44 599
E-mail: F-PROT-Support@datafellows.com, WWW: http://www.datafellows.com/

This material can be freely quoted when the source, F-PROT Professional
Update Bulletin 2.26 is mentioned. Copyright (c) 1997 Data Fellows Ltd.
------------------------------------------------------------------------------

Contents 1/97
=============

Editorial: NT - New Technology
The Global Virus Situation
        The Word Macro Virus Situation
        ShareFun - a mix of macro virus and a chain letter
        WordMacro/Kompu
        WordMacro/Showoff
        Latest Hoax: NaughtyRobot
        The Cruel Virus Shipped on CD-ROM Driver Floppies
        Linux Viruses Are Here
        Linux/Staog
        Linux/Bliss
        HLLP.3263
        Spanska
Common Questions and Answers
Changes in F-PROT Professional Version 2.26
New Viruses Detected by F-PROT


Editorial: NT - New Technology
------------------------------

Data Fellows releases real time virus scanning for both
NT Workstation and NT servers. Windows NT is quickly
gaining popularity as the default operating system used
by enterprises in both servers and workstations. The
information security features of NT computers are
significantly more advanced than those of normal Windows
systems, but at the same time the computers are more
complicated to manage. Data Fellows is keeping up with
this trend, and we have invested strongly on the
development of NT products in both our virus protection
and encryption products.

This version of F-PROT features a real-time virus
protection capability for the NT environment: F-PROT
Gatekeeper for Windows NT. We support Microsoft Windows
3.50, 3.51 and 4.0. To guarantee the highest degree of
reliability and performance, the NT version of Gatekeeper
has been programmed as a low-level file system driver,
FSD. This technique makes it possible for the server
version of F-PROT NT to check files even when they are
used over the network by a workstation. The workstation
version is shipped to all registered NT users. Please
inquire from our sales for the sever version.

In the new NT version of the program, F-Agent has also
been changed to a Service program. That way, it can run
scheduled virus checks even when no one is logged into
the computer.

You can expect other significant innovations in the F-
PROT product family as well. These will include, for
instance, support for automatic SMS installations and
SNMP-based reporting over LANs and WANs.

The Global Virus Situation
--------------------------

The Word Macro Virus Situation
------------------------------
Microsoft released Office 97 in February 1997. Compared
to Word 6 or 7, it has improved anti-virus capabilities,
but it is still not foolproof. The number of Word macro
viruses continues to increase, and at the time this was
written it was already over 300 (February 1997).

ShareFun - a mix of macro virus and a chain letter
--------------------------------------------------
WordMacro/ShareFun is a Word macro virus, loosely based
on WordMacro/Wazzu. The only noteworthy thing about it is
that it attempts to spread over e-mail attachments. Every
time an infected file is opened, there is a 1/4 chance
that the virus will activate.

If Microsoft Mail is running, the virus attempts to send
e-mail messages to three random people listed in the
local MS Mail alias list. The subject of these messages
is:

        You have GOT to see this!

The messages contain no text, only a file attachment
called DOC1.DOC which is infected by the virus. The
document itself is the document that the user happened to
have open when the virus activated.

If the recipient double-clicks on the attachment, his or
her computer will get infected by the virus. The virus
will then spread further by using the MS Mail in the
computer. Thus, ShareFun can be considered to be mix
between a macro virus and an automatic chain letter.

 An example of what an e-mail sent by the ShareFun virus
                       looks like

Do notice that this is not an "e-mail virus". You do not
get infected just by reading e-mail - you need to
actively use an attachment file, and you should therefore
always use attachment files with caution.

ShareFun also has code to protect itself. If a user tries
to analyze a sample of the virus via Tools/Macro or
File/Templates menus, the virus will execute and infect
the NORMAL.DOT template.

ShareFun was found in the wild in USA, in February 1997.

F-PROT 2.26 detects and disinfects the
WordMacro/ShareFun. A virus. F-PROT Gatekeeper will deny
access to the attachment files sent by the virus and
therefore stop the virus before it has a chance to
spread.

WordMacro/Kompu
---------------
WordMacro/Kompu is the first Word macro virus which has
been written in Estonia (a small country separated from
Soviet Union in the early 1990's).

WordMacro/Kompu was found from Estonia in December 1996.
It spreads when infected DOC files are opened in Word.
After this, all other documents will get infected when
they are opened or closed.

On the 6th or 8th of any month, the virus activates. If
any document is opened on these dates, the virus will
display a dialog box with the title "Mul on paha tuju!"
and requests "Tahan kommi!".



           Dialog displayed by WordMacro/Kompu

These texts are in Estonian and mean "I'm in a bad mood"
and "Give me a candy". The virus will not let the user
continue working until he writes the word 'komm' (candy)
to the window. After this, the virus changes the Word
status bar text to read:

        Namm-Namm-Namm-Namm-Amps-Amps-Klomps-Kraak!

WordMacro/Kompu has been reported in several countries in
northern Europe.

WordMacro/Showoff
-----------------
WordMacro/Showoff was found in USA at the end of 1996. It
has since become common all over the world. The virus is
also known as SHOWOFXX.

Showoff consists of three encrypted macros: AUTOOPEN,
CFXX and SHOW. It infects documents whenever they are
opened or closed.

Showoff contains code to display messages like:

        ra ono we, U can delete this mess later

The virus does not contain any directly harmful code.

After Concept and Wazzu, WordMacro/Showoff.B has been one
of the most frequently reported macro viruses in Europe.

Latest Hoax: NaughtyRobot
-------------------------
This is not a virus but a widespread hoax. Somebody has
been distributing e-mail messages like the one below in
the Internet. The messages are possibly created by an
automatic e-mail robot. The sender of the message has
been faked, and it is usually the e-mail address of the
recipient of the message.

    Subject: EMERGENCY - security breached by
    NaughtyRobot

    This message was sent to you by NaughtyRobot, an
    Internet spider that crawls into your server through
    a tiny hole in the World Wide Web.

    NaughtyRobot exploits a security bug in HTTP and has
    visited your host system to collect personal,
    private, and sensitive information.

    It has captured your Email and physical addresses, as
    well as your phone and credit card numbers.  To
    protect yourself against the misuse of this
    information, do the following:

           1. alert your server SysOp,
           2. contact your local police,
           3. disconnect your telephone, and
           4. report your credit cards as lost.

    Act at once.  Remember: only YOU can prevent DATA
    fires.

    This has been a public service announcement from the
    makers of NaughtyRobot -- CarJacking its way onto the
    Information SuperHighway.

Ignore the message - this is just a hoax.

The Cruel Virus Shipped on CD-ROM Driver Floppies
-------------------------------------------------
A virus called Cruel has been shipped internationally on
the driver diskettes of Maverick 12X CD-ROM drives by
Optics Storage.

        Have you seen this floppy? If so, check your system.

Cruel is a boot sector virus originating from Hungary.
Unlike most other boot sector infectors, it overwrites
the DOS boot sector. Upon activation, the virus
occasionally corrupts the CMOS setup information. This
can cause the loss of hard drive settings or even turn on
the BIOS password protection with a random password.

The virus is able to spread from the driver diskettes
only if the computer is booted with the diskette in drive
A:.

Optics Storage from Singapore is aware of this incident,
and has made sure the current master diskettes are clean.

F-PROT detects several different Cruel variants,
including this one.

Linux Viruses Are Here
----------------------
Roughly two years after Linux-specific viruses were
predicted, the first real-world samples have been found.
Two functional Linux viruses have been discovered.
Although these are not yet a cause for concern for the
average Unix administrator, they do remind us to watch
carefully over our systems, regardless of the operating
system.

Linux/Staog
-----------
This virus spreads only under the Linux operating system,
infecting Elf-style executables. Found in the fall of
1996, Staog is the first known Linux virus.

Staog is written in assembler. It attempts to stay
resident and infect binaries as they are executed by any
user. Staog tries to subvert root access via three known
vulnerabilities (mount buffer overflow, tip buffer
overflow and one suidperl bug).

Staog contains several text strings, including:

        Staog by Quantum / VLAD
        /dev/kmemx/etc/mtab~
        /sbin/mount
        /tmp/t.dip
        /bin/sh
        /sbin/dip /tmp/t.dip
        chatkey
        /tmp/hs
        #!/bin/sh\nchmod 666 /dev/kmem\n/tmp/hs
        #!/usr/bin/suidperl -
        U\n$ENV{PATH}=\"/bin:/usr/bin\";
        \n$>=0;$<=0;\nexec(\"chmod 666 /dev/kmem\");\n

VLAD is an Australian virus group which has also written
the first Windows 95 virus, Boza.

At the time this was written, Staog was not known to be
in the wild (February 1997).

Linux/Bliss
-----------
This virus spreads only under Linux operating system,
infecting Elf-style executables. Found in the wild in
February 1997, Bliss is the second known Linux virus.

Bliss locates binaries with write access and overwrites
them with its own code. When an infected file is
executed, the original program does not gain control at
all. However, it is still possible to clean infected
files.

Bliss does not try to subvert any additional user rights,
but it does have some basic worm-like features, looking
for new hosts to infect via the /etc/hosts.equiv file.

Bliss contains several text strings, including:

        dedicated to rkd
        infected by bliss
        skipping, infected with same vers or different type
        replacing older version
        replacing ourselves with newer version
        infect() returning success
        successfully (i hope) disinfected
        rsh%s%s %s 'cat>%s;chmod 777 %s;%s;rm -f %s'
        doing do_worm_stuff()
        /etc/hosts.equiv
        Compiled on Sep 28 1996 at 22:24:03
        Written by electric eel.
        help? hah! read the source!
        bliss was run %d sex ago, rep_wait=%d
        /usr/spool/news
        GCC: (GNU) 2.7.2.l.2

Bliss does contain potentially harmful code, but it is
not clear whether it is executed or not.

Bliss will disinfect itself if an infected binary is
executed with the --bliss-disinfect-files-please switch.
F-PROT 2.26 will detect and disinfect the infected
binaries, but the program will scan Linux binaries only
if you include all files in the scan.

HLLP.3263
---------
This virus, which is also known as Gremlin and Weed, was
posted to the popular SimTel ftp site in January 1997.
After that, it has been reported in the wild several
times.

HLLP.3263 overwrites the beginning of the files it
infects. It can sometimes be disinfected but often not -
F-PROT will not attempt to remove it. Instead, you should
delete infected files and reinstall them.

The code of HLLP.3263 has been compressed with LZEXE.

HLLP.3263 contains the text:

     WEED - v1.0

Spanska
-------
Spanska was distributed in several usenet newsgroups in
Internet in January 1997. It is a simple direct action
infector of COM files.

Spanska activates occasionally, displaying this text:

        Remember those who died for Madrid
        No Pasaran! Virus (c) Spanska 1996

The text is displayed on a screen which contains an
animation of flames. The text seems to refer to a famous
speech given by Dolores Ibarruri, a Spanish freedom
fighter. She said the famous "No Pasaran" ("They shall
not pass") phrase in her radio speech in 1936.

A later 1000-byte variant, with minor differences is also
known. The displayed text has been changed to:

        Remember those who died for Madrid
        No Pasaran! Virus v2 by Spanska 1997

Spanska is a good example of a simple virus which could
never have made it `in the wild' without Internet-wide
distribution.

Common Questions and Answers
----------------------------

If you have questions about information security or virus
prevention, contact your local F-PROT distributor. You
can also contact Data Fellows directly via phone at +358-
9-478 444.

Written questions can be e-mailed to:

F-PROT-Support@DataFellows.com

Or mailed to:

Data Fellows Ltd
F-PROT Support
Pivntaite 8
02210 ESPOO
FINLAND

In my new computer, I have the OSR2 version of Windows 95
with the new FAT32 file system. Will F-PROT work under
it?

        Yes. However, we recommend that you create
        DOS-based boot diskettes in some other computer
        for emergency use. In an OSR2 computer, it is not
        possible to create a boot diskette which would in
        itself be sufficient for booting the computer.

I installed the Service Pack 2 (SP2) update in my Windows
NT 4.0 computer. I have heard that it may cause problems
with anti-virus programs. Is it compatible with the
Windows NT version of F-PROT?

        Yes. Microsoft has also published several
        corrections, so- called Hotfix packages, for SP2.
        You can find out more about them at:
        www.microsoft.com.

I found a document infected by a macro virus. F-PROT
reported the infection as a new version and would not
remove it, whereas another product identified it as a
normal Concept virus and disinfected it. What's going on
here?

        The infection was most probably caused by an
        altered version of the Concept virus. F-PROT
        performs an exact identification on macro viruses
        also, in other words it calculates a 32-bit
        checksum from the virus' code and is therefore
        able to detect even slight alterations in its
        functioning. This way, F-PROT can avoid damaging
        files during disinfection. New, unknown variants
        can often be disinfected just like the previous
        versions of the same virus, but this can not be
        relied on. When encountering new variants of
        viruses, samples should always be sent to F-PROT
        support for analysis. The incorporation of the
        disinfection procedure for a new macro virus can
        usually be done while you wait.

Does F-PROT for DOS support the detection and
disinfection of macro viruses?

        No. The OLE2 engine used by F-PROT requires so
        much memory that it cannot be used by the DOS
        version of the program (F-PROT.EXE and
        VIRSTOP.EXE). F-PROT.EXE has a limited ability to
        detect some of the most common macro viruses, but
        we recommend that you always use F-PROT for
        Windows for combating macro viruses. An
        alternative is to use the program F-MACRO.EXE
        under DOS. F-MACRO.EXE contains the macro virus
        search engine used by F-PROT for Windows,
        compiled into a DOS program.

        Known macro viruses spread only under Windows.


Changes in F-PROT Professional Version 2.26
-------------------------------------------

A massive renaming of viruses has taken place in order to
make F-PROT conform more closely to the CARO virus naming
standard. The list of renamed viruses can be found at the
end of this document.

Changes in F-PROT for DOS
-------------------------
The program used to give the false alarm `Possibly a new
variant of Jerusalem' about the file ONGUARD.COM. This
has now been corrected.

Changes in F-PROT for Windows
-----------------------------
Iomega ZIPdrive and other similar removable drives were
not scanned if a task was set to scan the drive (the scan
did work if the task was set to scan the root directory
of the drive). The drive did not appear in the list of
drives in the Task Settings dialog, either. This has been
corrected.

A GPF occurred when a document file in a directory with
an "abnormally" long pathname was scanned. An example of
such a directory:

c:\This is a Test 1\This is a Test 2\This is a Test
3\This is a Test 4\This is a Test 5\This is a Test 6\This
is a Test 7\This is a Test 8\

Note that such a directory cannot be created under DOS,
but does not pose any problems in Windows 95 or Windows
NT.

Support for MACRO.DEF has been added to F-PROT for
Windows 3.x, 95 and NT and Gatekeeper 3.1. Gatekeeper 95
and NT will start to support MACRO.DEF in the next
released version. Users can now update the macro scan
engine very frequently by downloading the latest
MACRO.DEF from http://www.DataFellows.com/. Also the DOS-
based F-MACRO.EXE program supports it.

Changes in F-PROT for Windows NT
--------------------------------
F-PROT for Windows NT now includes the Gatekeeper active
protection. You need administrator rights to install it.
Gatekeeper is not turned on during default installation.

F-Agent is now running as a Service.

Autoinstaller supports NT Gatekeeper installation. The
usual

[Gatekeeper]
Enable=

-setting applies.

Autoinst and setup wait for 5 seconds after terminating F-
Agent before starting to copy new files, in order to
allow DFSAV32.DLL time to unload. This will correct the
"unable to copy DFSAV32.DLL" bug.

Autow32 used to create shortcuts (program items)
incorrectly under NT 4: no quotes were placed around the
executable name. Now they are created properly (like in
Windows 95).

Support for NT Gatekeeper and NT F-Agent Service
installation has been added.

Changes in F-PROT for Windows 3.x
---------------------------------
In some configurations (especially when NETDDE.EXE was
loaded), a GPF occurred in DFWIN.DLL when the main
program was closed. This has been corrected.

The detection problem F-PROT Gatekeeper suffered from
when an infected file was opened from Word in certain
conditions has been fixed.

Changes in F-PROT for Windows 95
--------------------------------
The memory scan of F-PROT Gatekeeper had problems with
finding viruses. This has been corrected.

F-PROT Gatekeeper 95 did not scan XLS files by default.
It does now.

New Viruses Detected by F-PROT
------------------------------

The following 61 viruses are now identified, but can not
be removed as they overwrite or corrupt infected files.
Some of them were detected by earlier versions of F-PROT,
but not identified accurately.

Druid.313
Druidic.297
HLLO.3201
HLLO.4000
HLLO.4176
HLLO.4200
HLLO.4317
HLLO.4317.B
HLLO.4317.C
HLLO.4891
HLLO.4928
HLLO.5008
HLLO.5056
HLLO.6208.B
HLLO.6528
HLLO.6544
HLLO.6896
HLLO.7424.B
HLLO.7504
HLLO.8259
HLLO.13452
HLLO.15788.B
HLLO.16622
HLLO.23802
Leprosy.390
Leprosy.666.X
Leprosy.666.Y
Leprosy.666.Z
Leprosy.666.AA
Milan.268
NGV.1152.B
NGV.1312.B
NGV.1408.B
NGV.1424
NGV.1468.A
MonsterO.213
MonsterO.217
MonsterO.323
MonsterO.327
Runme.6224
SillyOR.136
SillyOR.144
SillyOR.147
SillyOR.155
Suxx.442
Syrian.296
Tridow.4095.B
Trivial.36.6
Trivial.44.H
Trivial.61.A
Trivial.61.B
Trivial.63
Trivial.64.C
Trivial.93
Trivial.100.B
Trivial.134
Trivial.166
Trivial.332
VCL.O.470
VCL.527.B
Vofca.275

The following 431 new viruses can now be removed. Many of
them were detected by earlier versions, but are now
identified accurately.

_239
_382
_938
_1145
_1169
_1367
_3809
_5632.D
Afour.656
Aiwed.678
Aiwed.852
Akuku.889.E
Akuku.889.F
Anomally.277
Anticad.3012.H
Anticad.4096.Mozart.B
Antipascal.529.B
AntiW.465
Antiwin.632
Apparition.1248
Asch.794
Astron.1056
At.149.B
Attitude.715
BadSectors.3150
Barrotes.1461
Bebe.1004.B
Beer.3047
Bell.337
Bero.670
Bero.1000.B
Black_Jec.281.D
Born.970
Box_10.1219
Burma.442.G
Burma.442.H
Burma.442.I
Burma.442.J
Butterfly.302.F
ByteWipe.1024
Breaking.1000.C
BW.881
BW.888
BW.889
BW.889.B
BW.890.A
BW.890.B
BW.890.C
BW.890.D
BW.890.E
BW.890.F
BW.892
BW.896.A
BW.896.B
BW.896.C
BW.897.A
BW.897.B
BW.897.C
BW.899.A
BW.899.B
BW.899.C
BW.900
BW.923
BW.Mayberry.742
Caca.390
Cagliari.621
Cagliari.622
CheapExe.1052
Cancerbero.670.B
Cancerbero.677.B
Cascade.1661.C
Cascade.1701.BH
Cascade.1701.BI
Cascade.1701.BJ
Cascade.1701.BK
Champaigne.636
Coconut.1870
Coconut.1942
Cog.1108
Cool.929
Corea.1811
CPP.239
Creeper.475.B
Creeper.475.C
Cripple.403
Croatia.1349
Cronic.613
Cuareim.790
Cybercide.1288
Cybertech.225
Danish_Tiny.284
Danish_Tiny.308.B
Dark_Avenger.1800.AE
Dead.1194
Dear.380
Dementia.4207.B
Democracy.3670
Desert.641
Dev_X.301
Diamond.666.C
Dima_II.325
Dnepr.377
DSA.263
Dreamer.8864.B
Dual_GTM.1527
Durbomk.607
Dust.1088
DvD.940
Ear.2487
Ear.2487.B
Emhala.749
Eraser.689
Eternity.566
Fairz.2086.B
Father_Mac.792
Father_Mac.1460
Flash.749.B
Folko.512
Fowstar.1194
Four_Weeks.2062
Fumble.866.B
Galacia.840
Genesis.185
Genesis.186
Ginger.2249
Ginger.2319
Ginger.2350
Ginger.2400
Ginger.2449
Ginger.2467
Ginger.2471
Ginger.2501
Ginger.2564
Ginger.2567
Ginger.2602
Ginger.2629
Ginger.2692
Ginger.2714
Ginger.2715
Gippo.1030.B
Gippo.1030.C
Gippo.1050.B
Golgi.467
Good_Luck.300
Grafa.482
Guerilla.1996
Guevara.1918
H-Andromeda.661
H-Andromeda.713.B
H-Andromeda.758.B
H-Andromeda.758.C
H-Andromeda.1036
Halka.1000.B
Halka.1000.C
Harlof.4096
Headache.269
Helloy.243
Helloy.293
Hi.892.B
Hidenowt.1741.B
Hidenowt.1741.C
Hideous.1024.D
HLLC.4894
HLLC.5000
HLLC.7584
HLLC.8064
HLLC.9948
HLLC.12969
HLLP.4255
HLLP.4536
HLLP.6425
HLLP.6549
HLLP.6606
HLLP.6667
HLLP.6685
HLLP.7253
HLLP.7643
HLLP.7929
HLLP.8416
HLLP.9072.C
HLLP.9533
HLLP.11652
HLLP.13040
HLLW.3686
HxH.1585
IBQQZ.556
Immortal.1899
Indonesia.2436.B
Insert.271
Intruder.1319.F
IVP.400
IVP.476
IVP.644.B
IVP.750
IVP.751.B
IVP.835
IVP.846
IVP.871
IVP.928
IVP.1824
IVP.2385
IVP.2385.C
Jain.1614
Jerusalem.1570.B
Jerusalem.1808.W95
Jerusalem.2027
Jerusalem.Sunday.U
Karina.850
Kela. 2007
Kevin.1558
Khiznjak.461
Khiznjak.556
Khiznjak.768
Kill.578
Kim.1000
KK.1011
Konek.512
Koniec.404
Koniec.432
Lichen.1024
Lobotomy.829
Lobotomy.966
Luri.1216
Malaga.2385
Malaga.2658
Mefl.700
Mephisto.1134
Milan.284
Mipht.460
Mixx.570
Mmaid.2048
MMIR.282
MoonRat.501
Mr_Gu.323
MShark.378.B
Murphy.1008.B
Murphy.1480.B
Nazgul.258
Nazgul.290
Nazgul.292
NGV.1088.C
NGV.1616
NGV.1632
NGV.1664
NGV.1680.C
NGV.1680.D
NGV.1680.E
NGV.1680.F
NGV.1680.G
NGV.1760.A
NGV.1760.B
NGV.1760.C
NGV.1760.D
NGV.1936
Ninja.1421
No_Of_The_Beast.512.AF
Nogra.789
Noon_beep.1163.B
Noon_beep.1166.B
Npox.611
Nymphet.1024
Odious.569
Otti.937
Paraguay.577
Paz.2560
Perfume.731.B
PH33R.1460
Phalcon.1117.B
Phalcon.1118.B
PI.2048.B
Pixel.299.D
Pixel.342.C
Pixel.847.M
Pixel.847.N
Pixel.851.C
Pixel.852.C
Pixel.740.B
PM.733
PMT.867
Polimer.512.B
Protovirus.720B
PS-MPC.331.D
PS-MPC.332
PS-MPC.374.D
PS-MPC.379.B
PS-MPC.379.C
PS-MPC.379.D
PS-MPC.392.C
PS-MPC.393.F
PS-MPC.393.G
PS-MPC.398
PS-MPC.398.B
PS-MPC.399.U
PS-MPC.408.B
PS-MPC.411.B
PS-MPC.415.D
PS-MPC.415.E
PS-MPC.425.C
PS-MPC.441.C
PS-MPC.458.F
PS-MPC.490.D
PS-MPC.501.B
PS-MPC.504.C
PS-MPC.514
PS-MPC.563.D
PS-MPC.564.F
PS-MPC.565.L
PS-MPC.569.H
PS-MPC.590.B
PS-MPC.595.C
PS-MPC.598.W
PS-MPC.602.I
PS-MPC.603.K
PS-MPC.612.J
PS-MPC.618.B
PS-MPC.618.C
PS-MPC.637
PS-MPC.643
PS-MPC.697.B
PS-MPC.853.B
PS-MPC.959
PS-MPC.1076
PS-MPC.1508.B
Punky.543
Qark.860
QRes.141
Rasek.1310
Rasek.1489.C
Revenger.505
Riot.470
Salmon.510
Saynay.5116.C
Sebo.2048
Sepultura.242
Shirley.4096.G
Shirley.4096.H
SillyC.99
SillyC.157
SillyC.160
SillyC.173
SillyC.243
SillyC.295
SillyC.358
SillyC.607
SillyC.619
SillyC.681
SillyC.32827
SillyC.32839
SillyC.32843
SillyCR.141
SillyCR.341
SMS.357
Span.1121
Spanska.1120
Sterculius.412
Stryke.253
SVC.3103.F
Swapper.746
Tadpole.2792
Tei.710
Tenerife.1550
Tic.101
Timid.290.B
Timid.305.B
Timid.306.B
Timid.513.B
Timid.513.C
Timid.526.B
Tiny_Family.133.B
TPVO.1329
TPVO.3783.B
Trance.1677
Traveler_Jack.868
Trident.647.B
Triplek.471
Undying.703.B
Undying.708
Ungame.645
Unkempt.1342
Uste.919
Vampiro.1000.F
Vampiro.1000.G
Vampiro.1000.H
VCC.358
VCC.32837
VCL.514.B
VCL.515
VCL.530
VCL.533
VCL.1019.B
VCL.1222.B
VCL.O.415
VCM.364
VXS.1077.B
Vienna.413
Vienna.575
Vienna.617
Vienna.645.E
Vienna.648.AH
Vienna.694
Vienna.762
Vienna.793
Vienna.827.B
Vienna.934.B
Vienna.1048
Vienna.BNB.429.N
Vienna.Choinka.D
Vienna.Sicilian_Mob_1a.B
Vienna.Vengeance.B
Vienna.Violator.716.D
Vienna.Violator.716.E
Vienna.Violator.1000.H
Vienna.Violator.1000.I
Vienna.Violator.1000.J
Virdem.836
Wadimka.481
WereWolf.1361
WMA.708
Xchange.1066
Xtiny.200
Xtiny.204
XXX.1060
Xynet.947
YB.2277.B
Yesno.862
Yiel.1363
Yomamma.24550
Yomamma.24558
Yosha.980
Zebra.935
Zyklon.754

We have also added the detection and disinfection of 2
Linux viruses:

Linux/Bliss.17930
Linux/Bliss.18642

The following 207 new viruses are now detected and
identified but can not yet be removed.

_188
_436
_692
_710
_821
_1089
_1537
_1878
_1919
_2200
_3600
Aderror.2660.A
Aderror.2660.B
Amuak.3189
Antipode.737
Aos.765
Aos.782
Aos.790
Aos.1029
Aos.1031
Arequipa.1994
Attitude.747
Bende.1600
Bladisco.2278
Box_10.1213
Bpu.2269
Carnivore.504
Civil_War.542
Critico.969
Daddy.1085
Dan.1081
Dan.1864
Dina.271
Dina.283
Dumbtrash.404
Ear.1083
Flavour.989
Funk.692
Groan.1131
H-Andromeda.1024.D
H-Andromeda.1024.G
Happy_End.1536
HLLC.4243
HLLP.2783
HLLP.3263
HLLP.3990.B
HLLP.4080
HLLP.4400
HLLP.4416
HLLP.5844
HLLP.6279
HLLP.6686
HLLP.6912
Homer.206
Horizons.703
Into.708
Inv_Evil.1623
Jouc.1608
JRIO.764
Kode.1024
Kranz.255
Kreations.834
Kurgan.1621
Lapis.442
Lapis.444
Leech.1014
Lost_Love.853
Mad.1288
MH.1499
Monster.421
Monster.422
Monster.424
Monster.491
Monster.492
Monster.493
Monster.494.A
Monster.494.B
Monster.495
Monster.496
Monster.496.B
Monster.497
Monster.498.A
Monster.498.B
Monster.500.A
Monster.500.B
Monster.502
Monster.503
Monster.505
Monster.506
Monster.507.A
Monster.507.B
Monster.508
Monster.509
Monster.524
Monster.528
Monster.529
Monster.531
Monster.535
Monster.536
Monster.538
Monster.555
Monster.557
Monster.559
Monster.570
Monster.752
Monster.577
Monster.578
Monster.579
Monster.580
Monster.581
Monster.582
Monster.583
Monster.584
Monster.585
Monster.589
Monster.592
Monster.593
Monster.594
Monster.596
Monster.597
Monster.598
Monster.599
Monster.600
Monster.601.A
Monster.601.B
Monster.602
Monster.603.A
Monster.603.B
Monster.604
Monster.605.A
Monster.605.B
Monster.607
Monster.611
Monster.614
Monster.615.A
Monster.615.B
Monster.616
Monster.618
Monster.619
Monster.620
Monster.622
Monster.622.B
Monster.633
Monster.638
Monster.640
Monster.641
Monster.642
Monster.643
Monster.645
Monster.657
Monster.661
Monster.662
Monster.669
MQ.278
NMSG.214
Nodes.4000
NRLG.641
NRLG.656.B
NRLG.664
NRLG.761
NRLG.818.B
Ogga.4325
Penthouse.1568
Qu.2000
Sailor.1107
Sailor.1108
Sailor.1113
Solar.98
SSR.717
SSR.736
SVC.3118
Tangle.378
Tangle.387
Tanya.2000.A
Tanya.2000.B
Tanya.2000.C
Tigre.1795
Torero.1427
Trivial.247
Tutanchamun.1039
Unbidden.507
Urodyne.773
Vampiro.1495
Vampiro.1545
Vak.672
Vegera.1688
Vienna.387
Wintermute.1052
WPC-Bats.3072
WRA.512
Xuxa.2058
Yz.1339
Yz.1434
ZhengZhou.3571.A
ZhengZhou.3571.B
ZhengZhou.3584.B
Zodiac.485

The following 1 new virus is now detected, but not
identified. F-PROT will just report the family name with
a (?), as it is not yet able to determine which variant
it is dealing with. Disinfection of this virus is not yet
possible.

Tourist

The following viruses have been renamed:

A-OD      ->   Adrenalin
AC        ->   ACV
Account   ->   Account_Avenger
AIDS_II   ->   HHLC
Air_Raid  ->   Fog
Amzon     ->   Amozon_Queen
AnotherW  ->   Another_World
Anticheck ->   Rebelbase
Antifor   ->   AntiFortran
Arg       ->   Argentina
Asmodeus  ->   Asmodeous
Aspargus  ->   Aparagus
Ass       ->   Assa
Awaits    ->   Hell_Awaits
A_Ant     ->   AtomAnt
Babyly    ->   Baby_L
Bero      ->   Cancerbero
Boot-466  ->   Pasta
Boot-Y    ->   CCBB
Canna     ->   Grass
Carzy     ->   Abba
Chang     ->   ZhengZhou
Chuck     ->   Chukcha
Click     ->   The_Click
Click_II  ->   Click
Coker     ->   Cocaine
Cor       ->   Cortex
Country   ->   Decided
Crawler   ->   Night Crawler
Crovir    ->   Inquisitor
Cvirus    ->   HLLO
Dackness  ->   Hell
Dagg      ->   Dagger_II
Dear      ->   Dear_Friend
Demand    ->   Human_Greed
DespChem  ->   Desperate
Dev_X     ->   Devastator
Dig_Death ->   Digital_Death
Div0      ->   ZeroDivide
Dr_Qumak_II-   ->   Dr_Qmak
Draw      ->   Coprohage
Drunk     ->   Drunk_Avenger
Du        ->   Dupa
Duplicate-     ->   Bagnara
Eb        ->   Ebcav
Eddie-2   ->   Eddie
ElFla     ->   Megadeath
Enero     ->   Lamento
Exterminator   ->   Extermin
Faca      ->   Flags3
Fat_Table ->   HLLO
Fkiller   ->   Fast_Killer
Genrat    ->   Zgenrat
Genvir    ->   NGV
Georgy    ->   Grigory
Godzialla ->   Nigeb
Gravity   ->   SillyC
GV        ->   GV1
Ha_loop   ->   Phunnie
Harvester ->   Tibet
Inch      ->   Inch_High
Ivy       ->   Poison_Ivy
Jerusalem.CVEX ->   CVEX
June_12th ->   Mabuhay
JH_Error  ->   Errorvir
JT8       ->   JT-8
Kamekaze  ->   HLLO
Kak       ->   Kakashka
Kcor      ->   Assignation
Klubb     ->   NoPM
Komp      ->   Kompanion
M01       ->   Orcam
Macav     ->   Maca
Matador   ->   Edolan
Material  ->   Materialism
Mathiew   ->   Matthew
Measles   ->   Exorcist
Metallica_II   ->   Metallica
Mickey    ->   Mitch
Nichols   ->   Scythe
Nla       ->   Antiarj
Noon_beep ->   Noon
NoPM      ->   Klubb
Ogre      ->   PCOgre
Ornr      ->   Ornery
Over      ->   Combat
Particle_Man   ->   Particle
Peligro   ->   Rogue
Pendule   ->   Monami
Pihenj    ->   Kicsit
Poison    ->   Moctezuma
PrDevil   ->   Print_Devil
Print_Screen_Boot   ->   Print_Screen
PvW       ->   DSPDH
Quark     ->   Quartile
Quit      ->   Annyit
Quiver    ->   LP
Radar     ->   Stealth_Bomber
Raine     ->   Inch
Red_Hacker     ->   Redhack
Red_Zar   ->   Torn
Retailer  ->   Patr
Rift      ->   Rift_Villy
Roma      ->   PG
Rosario   ->   Leproso
Sabados   ->   AntiSabados
Screen+1  ->   Kurgan
Selectronics   ->   Select
Semi      ->   Overnopped
Serve     ->   Mipth
Shatin    ->   Kwok
Shel      ->   Sofar
Sinada    ->   Sina
Skvernuk  ->   Xa-Xa
Slaughter ->   Solar_Wind
Slimline2 ->   Slimline
SmartC    ->   Smartcoc
Sod       ->   Skull
Sol       ->   Sold
Springs   ->   Tridow
St_R      ->   Bloody_Revenge
SuperF    ->   Super
Surprise  ->   Lame_Surprise
Swas      ->   Swash
Syskll    ->   Syskill
TCH       ->   Tchechen
Tea       ->   TeaForTwo
That      ->   That's_All
Thirty_First   ->   Birthday
TKD       ->   TaeKwonDoe
Topper    ->   Nightmare
TPworm    ->   HLLC
Triple5   ->   Triple_Five
Trivia    ->   Smgtest
Uneven    ->   Yellow_Worm
Uruk      ->   Uruk-Hai
Uucckk    ->   Uck
Uvst      ->   Ultra_Violent
Valid     ->   Jpage
VHX       ->   VXH
Virnn     ->   SMVB
Vivian    ->   Vivian_Lai
VSP3      ->   VSP
Wonder    ->   HLLO
Xeran     ->   Xeram
Yam_exe   ->   Admiral
Year_1992 ->   EUPM
You_Have  ->   YouHaveProble
Zarm      ->   Zarma
Zorm      ->   Zort
ZZZ       ->   Doublez
------------------------------------------------------------------------------
F-PROT Professional 2.26 Update Bulletin
========================================
Data Fellows Ltd, Paivantaite 8, FIN-02210 ESPOO, Finland
Tel. +358-9-478 444, Fax +358-9-478 44 599
E-mail: F-PROT-Support@datafellows.com, WWW: http://www.datafellows.com/

This material can be freely quoted when the source, F-PROT Professional
Update Bulletin 2.26 is mentioned. Copyright (c) 1997 Data Fellows Ltd.
------------------------------------------------------------------------------
