======================================================================= * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT A new virus has been reported at a leading company in Atlanta. The virus contains the string 'Screaming Fist II', presumably this is the handle of the author (?). A 711 byte virus "Screaming Fist" was reported in Virus Bulletin March 1992, named 'SCREAMER'. Symptoms are not yet completely known, but machine does hang. VIRUS NAME: 'Screaming Fist II' TYPE: Variable Encrypted INFECTS: EXE, COM, including COMMAND.COM ORIGIN: Unknown COMMENTS: A sample arrived at Leprechaun Software's Labs yesterday and has been partially disassembled. The virus goes TSR and infects files as they are opened. COM infections always grow 693 bytes while EXE's grow 693 to 1172 bytes (seems like larger EXE's grow more, might be a trivial attempt to disguise infection's trail). There is a special release of Virus Buster available. FOR A COMPLETE LISTING OF COMMONLY SEEN VIRUSES, CONTACT VIRUS NETWORK / PC ADVICE P.O. BOX 467215 FAX (404) 396-0916 ATLANTA, GA 30346-7215 VOICE (404) 396-2217 * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * ======================================================================= ======================================================================= * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT Last week we reported a new virus found in Atlanta. The virus contains the string "Screaming Fist II", presumably this is the handle of the author (?). A 711 byte virus "Screaming Fist" was also reported in Virus Bulletin March 1992, named "SCREAMER". A third virus (or version?) of Screaming Fist II has been identified and is guaranteed to be in the wild. It appears to be a completely different virus with the same string embedded "Screaming Fist II". This newly discovered virus is Multi-Partite, meaning it infects "boot sectors" and "program files" (EXE, COMs, etc.). Additionally, by observing the advanced programing techniques used in all three of these viruses, it appears they all may be a product of an underground hacker group. According to analysts at Leprechaun Software, the code seems to fit the concept of shared techniques. FOR A COMPLETE LISTING OF COMMONLY SEEN VIRUSES, CONTACT VIRUS NETWORK / PC ADVICE P.O. BOX 467215 FAX (404) 396-0916 ATLANTA, GA 30346-7215 VOICE (404) 396-2217 * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * ======================================================================= ======================================================================= * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT Last week, a leading company reported finding 3 occurrences of the Michelangelo virus. Two infected machines were in different areas of the company. All machines were cleaned before March 6th this year. VIRUS NAME: 'Michelangelo' TYPE: Common - Boot infector INFECTS: Partition Tables COMMENTS: You know the details. ======================================================================= * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT Last week a major Atlanta corporation reported finding the 1575 virus. VIRUS NAME: '1575 - Green Caterpillar' TYPE: Common Parasitic INFECTS: EXE, COM, including COMMAND.COM ORIGIN: Unknown COMMENTS: Hooks interrupt 21. Infected files grow 1,577 and 1,591 bytes. There are at least 3 known variants. ======================================================================= * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT The "FORM" virus is going to become more prevalent. A company reports today that it may have accidentally distributed a large number of diskettes to it's clients. Since the master disk is clean, the duplication service or the diskette provider probably passed it along. We reported "FORM-18" in January of this year. VIRUS NAME: "FORM" TYPE: Common - Boot infector INFECTS: Boot Sector COMMENTS: A clicking noise may be emitted from the system speaker on the 24th day of every month. Some systems will hang. FOR A COMPLETE LISTING OF SEEN VIRUSES, CONTACT GARY RUSSELL / PC ADVICE P.O. BOX 467215 FAX (404) 396-0916 ATLANTA, GA 30346-7215 VOICE (404) 396-2217 * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * VIRUS ALERT * =======================================================================