Short: Safe v13.3 - virus dicovering system Author: Zbigniew `Zeeball` Trzcionkowski (zeeball@interia.pl) Uploader: Tomasz Wiszkowski (error@alpha.net.pl) Version: 13.3 (05.06.2000) Type: util/virus Requires: Amiga with OS 2.04+ (xvs.library strongly recommended) Name: Safe STATUS: FreeWare FEATURES: - system friendly, non resident, can discover new link viruses - TCP newshell guard option - ANTISTEALTH abilities and HEURISTIC vector check option - can clear VBR - added memory removals for NeuroticDeath1&2 viruses (Thanks to Jan Andersen) - added SAVEMEM option (for advanced users) - can find and disable in memory PolishPower (Thanks to Jan Andersen) - tested with lot of viruses (Thanks to Jan Andersen) - not crashes with PatchControl! (Thanks to Tomasz Wiszkowski for the show :) - `Safe VECS` allows You to REMOVE ANY patches from LoadSeg and NewLoadSeg vectors! - added primitive memory check for rexxfunc trojan (more info below) - added kit to discover unknown Vaginitis Clones like TCP:2421 (more info below) ************************************************************************* - added QUICKTEST tool to detect and remove new TCP: trojans! ************************************************************************* NOTE THAT THIS IS VIRUS DETECTOR - NOT FILE CHECKER OR CLEANER! IT ONLY INFORMS ABOUT ATTACK AND REMOVES VIRUS FROM MEMORY IF POSSIBLE! There are TCP trojans on wild! BIG THANKS TO PAUL FOR FINDING THEM! Use new tool added to Safe`s package - QUICKTEST. It is able to find and remove the rexxfifo and rexxfunc trojans. ******************************************************************* Rexxfifo.library trojan TCP:4097 remote shell Installer: (faked YAM?) QUICKTEST can seek and destroy this one. Then please reboot. ******************************************************************* Rexxfunc.library trojan TCP: 2001 remote shell Installer: `miamispoof` size: 8468 (The file is StoneCracked and then modified to prevent decrunching) QUICKTEST can seek and destroy this one. Then please reboot. ******************************************************************* bigger c:mount TCP:2421 remote shell Yes. There is another link-virus. The memory patch is detected as STD Vaginitis #1 and removed correctly by xvs.library. Yes I`ve decoded it and now I know that author just used Vaginitis to have cool TCP shell opener :-) This mutation is designed to infect C:mount, so just if You have Vaginitis message then just replace Your mount with the original one. Installer: `jizzer` size: 15368 attacks C:mount (adds 700 bytes with virus) So if You have such TCP:2421 shell then please replace c:mount with the original one. Look into AntiVag directory of Safe`s package to find temporary solution to detect such mutations if there are more. ...and look for newest xvs.library from Alex van Niel. ============================= Archive contents ============================= Original Packed Ratio Date Time Name -------- ------- ----- --------- -------- ------------- 2358 1271 46.0% 06-Jun-00 06:05:10 Safe13.3.info 496 377 23.9% 06-Jun-00 06:05:10 +AntiVag 422 290 31.2% 06-Jun-00 06:05:10 +AntiVag.doc 2358 1273 46.0% 06-Jun-00 06:05:10 +Docs.info 11391 4628 59.3% 06-Jun-00 06:05:10 +SafeENG.guide 3231 2302 28.7% 06-Jun-00 06:05:10 +SafeENG.guide.info 4098 1335 67.4% 06-Jun-00 06:05:10 +TestResults.readme 3231 2304 28.6% 06-Jun-00 06:05:10 +TestResults.readme.info 2685 1227 54.3% 06-Jun-00 06:05:10 +InstallSafe 2774 1758 36.6% 06-Jun-00 06:05:10 +InstallSafe.info 2192 2128 2.9% 06-Jun-00 06:05:10 +QUICKTEST 1414 1006 28.8% 06-Jun-00 06:05:10 +QuickTest.info 7000 4824 31.0% 06-Jun-00 06:05:10 +Safe 1414 1006 28.8% 06-Jun-00 06:05:10 +Safe.info 2985 1364 54.3% 06-Jun-00 06:05:10 +Safe.readme -------- ------- ----- --------- -------- 48049 27093 43.6% 06-Jun-100 21:41:44 15 files