== xvs.library - The eXternal Virus Scanner Library ==
== Copyright © 1997-1999/2001-2022 by Georg Wittmann ==
== Copyright © 1999-2001 by Alex van Niel ==
== Copyright © 2001 by Jan Erik Olausen ==
The xvs.library contains all virus recognitions and disinfection code that
was formerly included inside VirusZ. This step has been taken for one major
reason: VirusZ, Virus_Checker, Virus_Executor and all the other antivirus
software can be updated quickly without releasing the whole packages every
time a new virus appears.
So simply install the xvs.library from this archive to your LIBS: drawer to
get 100% protection against the latest viruses.
To be able to check if the library in this archive really came straight from
the author, you can use my public key with the .sig files in the archive.
If you are not sure or do not trust the included key, then you can always
request an original copy straight from me (by email, see below) or get it
from the VHT-Denmark homepage.
Currently I (Georg Wittmann) am developing the xvs.library package alone
again, so for any bug reports, comments or new ideas just contact me at the
following e-mail address:
xvs.library 33.46 (size: 66.876 bytes)
- Fixed recognition for 'VCS 2' bootblock virus to detect encrypted
and decrypted versions. Thanks to Jan Andersen of VHT-DK for the
- Added more bootblock viruses (mostly strains of known viruses):
'Blizzard 1.0 Ultra', 'Copylock', 'Killed Katrin', 'Oral Device',
'Supply Team Lazer', 'SystemZ 5.3 Sear', 'Time Bomb 1 Bad Boy',
'Australian Parasite VHT', 'Warhawk 1 VHT' and 'By J.H.'.
Thanks again to Jan Andersen of VHT-DK for sending them.
- Renamed bootvirus 'Byte B. 1 Shut Berlin' to only 'Shut Berlin'.
- Fixed recognition of 'Revenge Bootloader' bootblock virus in order
to detect strains too. Added 'Disk Doktors BJH' bootblock virus.
Thanks to Crashdisk for sending them.
- Fixed recognition of 'Rene' bootblock virus to avoid false alarms
when scanning for bootblock viruses inside files. Thanks again to
Jan Andersen for the example file.
- Added 'Liquid Acid' linkvirus. This one is quite special as it
doesn't change the size of an infected file by simply crunching
parts of the original file together with its own code. Thanks once
more to Jan Andersen of VHT-DK for the copy.
- Added 'DiskJerk' filevirus, the uncrunched version of 'Karacic'
filevirus, the three malicious scripts of the StellarX demo called
'FuZZ Script #x' datavirus and the malicious files from Zine #10
disk-magazine called 'Zine10 .fastdir', 'Zine10 c/.fastdir' and
'Zine10 Disk-Validator' filevirus.
These were again sent by Jan Andersen of VHT-DK too, thanks.
- Analysed 'BBS.Conftop' files said to be AE backdoors, but didn't
find any suspicious code. Analysed 'dmv05.exe' file said to be a
COP trojan, but that file is truncated, cannot be executed and
hence isn't dangerous at all.
-> both files NOT added, although VT 3.17 detects them as virus!