Msg#:13430 *viru* 07-01-93 18:21:19 From: ARYEH GORETSKY To: SANDRA CAREY Subj: REPLY TO MSG# 13352 (BUTTERFLY VIRUS) Hello Ms. Carey, The Butterfly virus is a 302 byte long .COM file infector based on another virus called the Civil War virus. It infects .COM files by attaching its code to their end, and then modifying their initial instructions to jump to the virus code at the end of the file. Once the virus code has initialized, it then transfers control back to the host program. The virus has the message "Goddamn Butterflies" embedded in it. Listed below are signatures for updating VIRUSCAN to detect the Butterfly and Parity Boot 2 viruses which have been reported at multiple sites since V106 was released. To use them, create an ASCII text file with one signature to a line, save it to a file with a name like NEWVIR.TXT, and then runVIRUSCAN by typing: SCAN {path} /EXT NEWVIR.TXT Here are the signatures. Lines with a # sign are comments. #Parity Boot 2 virus is a boot sector infector "A3 13 04 B1 06 D3 E0 2D C0 07 A3 4E" Parity Boot 2 #Butterfly is a file infector about 400 bytes long "B4 4E 8D B6 50 02 8D 96 2C 02 52 EB 3C" Butterfly For more information on using the /EXT option, please refer to Appendix A of the VIRUSCAN documentation. Regards, Aryeh Goretsky Tech Support <->, ubby, eply, gain, ext, or top?