@database "Newupdates"
@Node Main
@Next "A"
@Toc "Main"
             B O O T X   R E C O G   V E R S I O N  1.96


MADE BY SAFE HEX INTERNATIONAL
Programmer: Michael Nielsen

I hope you will appreciate our work!



     CONTENTS:   @{" * 11-02-94       BootX Recog 1.96, 32.484 bytes   " link 11-02-94}
                 @{"   19-11-93       BootX Recog 1.89, 32.216 bytes   " link 19-11-93}
                 @{"   03-10-93       BootX Recog 1.85, 31.848 bytes   " link 03-10-93}
                 @{"   13-09-93       BootX Recog 1.80, 31.708 bytes   " link 13-09-93}

                 @{"   Why this new update by Safe Hex International   " link WhySHI?}
                 @{"   Thanks to Peter from all of us                  " link FromAllOfUs}
                 @{"   SHI need your help for futher locale support    " link localeSupport}
                 @{"   Viruses wanted for new bootx updates            " link VirusesWanted}
                 @{"   Emergency BBS hot-line to SHI                   " link Emer}
                 @{"   How to get in contact with SHI                  " link a}
                 @{"   Safe Hex International address list             " link Ad}

                                  @{"   Attention dear Amiga friend!   " Link always}
@Endnode


@Node 11-02-94
@Next "A"
@Prev "Main"
@Toc "Main"
THE BOOTX RECOG VERSION IN THIS 1.96 UPDATE KNOWS THESE NEW VIRUSES:

                   @{"  Ingo Return                                     " link IngoReturn}
                   @{"  PayDay                                          " link PayDay}
                   @{"  Overkill                                        " link Overkill}
                   @{"  Wahnfried                                       " link Wahnfried}
                   @{"  Mutilator                                       " link Mutilator}
                   @{"  G-Zus 0.01 a damage program                     " link Gzus}
                   @{"  Eleni Clock virus                               " link Eleni}


The  german  BootX  locale  is "finished".  A very excellent work thanks to
Steffen Salzmann, Germany!


Our  thanks are going the following excellent guys for the support of these
new  viruses.   Without  these  excellent  guys  there  have not been a new
update:


Rune Goksr, Norway.  Ulrik Nielsen, Denmark.  Gert Lamers, Holland.  David
Elmquest, Denmark.  Jim Maciorowski, USA.  Martin, Austria.  Sten Andersen,
Denmark.   Torben Dan, Denmark.  Kosta Angelis, Greece.  Alex Dimitriadis,
Germany.  Johan  Sahlberg, Sweden. Flavio Stanchina, Italy. Gabriele Greco,
Italy.


@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node IngoReturn
@Next "A"
@Prev "11-02-94"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


INGO RETURN



                     The  Ingo  Return is an  ordinary bootblock virus very
                     like some of the Lamer Exterminator viruses.  Contrary
                     the lamer viruses this new strain writes "Fuck" in the
                     blocks on the disk.

                     Like  the lamer viruses the Ingo virus change the code
                     you  can  see in the bootblock for every new infection
                     of disks.

                     Files  infected with Ingo damaged blocks are permanent
                     damaged, no possibility to salvage!


@Endnode

@Node PayDay
@Next "A"
@Prev "11-02-94"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


PAYDAY


                     PayDay is one of many bad antivirus bootblocks,  which
                     was very popular for years ago.  Because this one only
                     knows very few boot viruses.  The origin is a program,
                     which  offer you to install this Payday antivirus boot
                     block.

                     The PayDay isn't a virus at all, but because this one 
                     will "guru" at Kickstart versions later than 1.3, it's
                     better to remove. (Use Install)


@Endnode


@Node Overkill
@Next "A"
@Prev "11-02-94"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


OVERKILL


                     The  Overkill virus is a special bootblock virus which
                     occupies 4 blocks:

                     Block 0 and 1 = Virus
                     Block 2 and 3 = The original bootblock


                     Unfortunately  this  Overkill  virus is working at all
                     Kickstarts  versions  included Amiga 4040, and is able
                     to infect your harddisk too.

                     This  virus  have to be said as VERY dangerous because
                     it  can maybe overwrite important data on disk or your
                     harddisk.  

                     The Overkill virus codes virus in a new form for every
                     new bootblock infection!!!

                     If  you  have your harddisk infected the block  2-3 on
                     your  harddisk  will  be  overwritten  by the Overkill
                     virus  and  the  consequence can be:  No boot-up and a
                     damaged  RigidDiskBlock  of  your  harddisk and/or the
                     damaged bootblocks.

                     Have  you  been  unlucky? Try some of salvage programs
                     e.g. FixDisk or DiskSalv, and check what might be left
                     to re-install again.


@Endnode


@Node Wahnfried
@Next "A"
@Prev "11-02-94"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


WAHNFRIED


                     The  name Wahnfried is to read in the bootblock.  This
                     virus  can  infect  at  Kickstart  1.2, 1.3, and later
                     versions. ATTENTION.. be careful this virus can infect
                     your harddisk too!


                     All  written  Wahnfried  infected bootblock don't work
                     because  a  checksum error.  A counter will start, and
                     when  this  counter  reach 0 a  DisplayAlert will come
                     at your monitor with the following text:


                     "Hardware Failure Press left mouse button to
                     continue  Guru Meditation #00000015.00C03L12
                     Hooligen-Bits randalieren im Datenbus!
                                                      Gru Erich!"


@Endnode


@Node Mutilator 
@Next "A"
@Prev "11-02-94"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


MUTILATOR


                     Mutilator is a bootblock virus, but ATTENTION.......be
                     careful this virus can infect your harddisk too!

                     As soon as counters reaches $e0 and the other 3 you'll
                     get the following text on your monitor:



                     "THIS IS THE NEW MUTILATOR-VIRUS !
                     BY MAX OF STARLIGHT

                     Thanx to The Executors for Spreading this
                     GREAT code ! done: - 1992 - ...."


@Endnode


@Node GZus 
@Next "A"
@Prev "11-02-94"
@Toc "Main"


G-ZUS PACKER


                     The  G-Zus  Packer 0.01 isn't a virus at all,  but you
                     can say a kind of a damage program. 

                     The  original unpacked G-Zus have been spread by modem
                     named  as  "gzus001.lha" = 12.520 bytes.  The original
                     unpacked G-Zus file is 15016 bytes.

                     The G-Zus packer looks as a very trustable program but
                     don't..... trust it! In the G-Zus doc one of the first
                     lines are saying:

                     "You  take  ALL  the  risks in using this software. We
                     offer NO guarantee"... 


                     Don't  attempt  to  use  it you will be fooled by this
                     packer!!!!

                     If  you  tries  to load a file for crunching this file
                     will  be deleted and the new crunched file will always
                     have the same length = 30 bytes.  In this new file you
                     can read some garbage and the following text: 

                     "This Is Magic"


                     There isn't any possibility to salvage your lost data,
                     if  you  have been fooled by this silly pseudo packer.


@Endnode


@Node Eleni 
@Next "A"
@Prev "11-02-94"
@Toc "Main"


ELENI CLOCK VIRUS 


                     Well....here you have the first virus which affect the
                     internal clock in your Amiga.

                     Rumors  have been heard in several years about a clock
                     virus in the meaning a virus, which could live in your
                     internal  clock and survive living by current from the
                     battery in this clock.  Of course this isn't possible.

                     Even if you have some few possible byte in the memory,
                     this  memory is all too little for a virus to survive.

                     The  Eleni virus is an ordinary bootvirus, but a quite
                     new nasty type,  which have several new features which
                     have not been seen before:



                     WHAT IS HAPPEN
                   - The  first time you are booting with an Eleni infected
                     disk,  your  second  disk drive will start running and
                     the  lamp  will be active a while.  (Of course only if
                     you  have a second drive).  This virus does not infect
                     if you have kickstart 1.2 or 1.3.

                   - The  5.th  time  you boot-up with an infected disk you
                     will  get  the  following  screen message in the upper
                     left corner: 

                     "*Eleni* *Eleni* *Eleni* *Eleni*"


                   - Between  the  1.st and  the  9.th boot-up the internal
                     clock  is  changed  and is set and saved to a new date
                     for  every  boot-up with an infected disk (A test have
                     given  different  dates  from  the years 1924 to 2014.

                   - The  9.th  time  you boot-up with an infected disk the
                     clock set and saved to the date to-day + 20 years.

                   - At  the  same  time  all disk drives will start to run
                     periodic and the infected disk(s) will not be execute-
                     able.  (Before  you  clear  the  virus in the memory).

                   - This  very  special  bootvirus  don't  overwrites  the
                     bootblock,  but replace the original bootblock on some
                     other  tracks.  When  the  Eleni  virus is removed you
                     will  get  the  original  bootblock automatic replaced
                     again??? ....What do you mean surprised?

                   - This  virus can even infect a track loader disk (Demos
                     and like). Maybe surprised again?


                     DAMAGE
                     After  the  9.th  boot-up you will get pseudo checksum
                     errors in all files on your disk. But all these errors
                     will  disappear again,  when  you install (remove) the
                     Eleni virus from the bootblock again.


                     ATTENTION!
                     This  Eleni  virus  can  infect  your harddisk too, so
                     please be very, careful in the future! 


@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node 19-11-93 
@Next "A"
@Prev "Main"
@Toc "Main"
THE BOOTX RECOG VERSION IN THIS 1.89 UPDATE KNOWS THESE NEW VIRUSES:

                   @{"  Fred Choen boot virus                           " link FredChoen}
                   @{"  Digital Dream virus installer                   " link DigitalTrojan}
                   @{"  Digital Dream boot virus                        " link Digitalbootvirus}
                   @{"  Sentinel boot virus                             " link Sentinel}
                   @{"  Leviathan file + boot virus                     " link Leviathan}
                   @{"  Creeping Eel boot virus bug corrected           " link CreepingBug}

Our  thanks are going the following excellent guys for the support of these
new  viruses.   Without  these  excellent  guys  there  have not been a new
update:

Rune  Goksr,  Norway.  Ulrik Nielsen, Denmark.  Gert Lamers, Holland.David
Elmquest, Denmark.  Jim Maciorowski, USA.  Martin, Austria.  Sten Andersen,
Denmark.   Torben Dan, Denmark.  Kosta Angelis, Greece.  Alex Dimitriadis,
Germany.
 

The german BootX locale is now "finished".  A very excellent work thanks to
Steffen Salzmann, Germany!


@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node FredChoen 
@Next "A"
@Prev "19-11-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


FRED CHOEN            


                     A  ordinary  bootvirus,  which  only infects Kickstart
                     1.3  Amigas.  In  the  bootblock  you can read:  "Fred
                     Cohen the university of California"
@Endnode

@Node DigitalTrojan 
@Next "A"
@Prev "19-11-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


DIGITAL DREAM TROJAN  


                     This  virus  is  original  spreaden  as  a powerpacked
                     file  6496 bytes.  Unpacked  9960 bytes. DigitalDreams
                     pretend  to  be a virus  killer  for the Jeff viruses,
                     but false don't trust it, it installs a bootvirus.

                  1. When  the Digital Dream is executed you gett a big red
                     cross  on  a black  background and below at the screen
                     you  can  read:  

                     This  is the: Jeff-Viruskiller V2.67 press left mouse-
                     button to continue.

                  2. Then  you  get a blue/black  text on a grey background
                     in the next screen and the following text:

                     Jeff-Viruskiller V.2.67
                 
                     Please  inset  a  disk  in  drive  0.  Then press left
                     mouse-button to kill Jeff on it.

                  3. If  you  don't  have  an unprotected in this drive you
                      will be asked to remove the write-protection!
                      
                     But  if your disk isn't write-protected, the disk will
                     be  infected with the virus long time before you press
                     the left mouse-button!
@Endnode


@Node Digitalbootvirus 
@Next "A"
@Prev "19-11-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


DIGITAL DREAM BOOT VIRUS


                     This  is  the  bootvirus,  which  is installed  by the
                     Digital Dream  trojan.  The  bootvirus is spreading at
                     kickstart  2.0 and it is a mutation virus.  That means
                     the  virus  is changing it's code every time the virus
                     infects a new disk.
@Endnode


@Node Sentinel 
@Next "A"
@Prev "19-11-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


SENTINEL BOOT VIRUS


                     This  virus  is called USSR 492 too.  It is a ordinany
                     bootblock  virus  which  writes  itself  to  $7f400 in
                     memory  without allocating memory.  The Sentinel virus
                     is a "Excrement" clone only the text is changed.

                     The  only  destructive  thing  it does is to overwrite
                     any  bootblock,  which hasn't been infected yet.  This
                     virus  is quite harmless,  and don't infects disks, if
                     you run kickstart 2.0-3.0.
@Endnode


@Node Leviathan 
@Next "A"
@Prev "19-11-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


LEVIATHAN BOOT- AND FILE VIRUS            


                     This  virus is a multihead virus, that means the virus
                     is  both  a bootblock  and a file  virus (1056  bytes)
                     like  the  "good" old CCCP virus and the later Starcom
                     1, and Irak 3 CCCP clones.

                     The  above means,  that the file virus part is able to
                     infect  a bootblock  with  the  bootvirus part of this
                     virus  and - the bootvirus part can of course infect a
                     new  file virus part.  By kickstart 1.3 -2.0 the virus
                     will guru and can't infect. 


                     ATTENTION
                     The  virus  file-part is changing in the first line of
                     the startup-sequence:


                     Original startup-sequence: setpatch
                     Infected startup-sequence: s/..setpatch

                     (Remark you have to correct this line by yourself).
@Endnode


@Node CreepingBug 
@Next "A"
@Prev "19-11-93"
@Toc "Main"
CREEPING EEL BOOT VIRUS BUG CORRECTED


                     Well.... you can't win every time. I have got some few
                     rapports  saying, that the former BootX recog 1.85 was
                     too good. 


                     Acually you could find some virus, which wasn't virus.
                     Now I think the problems are solved 


                     SORRY, FOLKS! 
@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node 03-10-93 
@Next "A"
@Prev "Main"
@Toc "Main"
THE BOOTX RECOG VERSION IN THIS 1.85 UPDATE KNOWS THESE NEW VIRUSES:

                   @{"  Descriptor 3.0 Trojan                           " link Descriptor3.0}
                   @{"  Cascade ID92 boot virus                         " link CascadeID92}
                   @{"  Creeping Eel boot virus                         " link CreepingEel}
                   @{"  Sentinel boot virus                             " link SentinelB}
                   @{"  Detlef boot virus                               " link Detlefboot}


Our  thanks are going the following excellent guys for the support of these
new  viruses.   Without  these  excellent  guys  there  have not been a new
update:


Rune Goksr, Norway.  Ulrik Nielsen, Denmark.  Gert Lamers, Holland.  David
Elmquest  Denmark.  Jim Maciorowski, USA.  Martin, Austria.  Sten Andersen,
Denmark.  


@Endnode


@Node Descriptor3.0 
@Next "A"
@Prev "03-10-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


DESCRIPTOR 3.0


                     This  virus  is  original  spreaden as descr4.0.lha or
                     -z-speed.lha =  3484 bytes,  from  some pirate BBS'es:

                     descr4.0.lha  3484 bytes.  The new DescriptorV4.0 with
                     new  POWER Snap.....Run without Snap in background and
                     you  will  see  the new Powersnap 120 % faster in copy
                     Descriptions.


                     Or renamed to the following:

                     -z-speed.lha   3484 bytes    ZENITH MODEM SPEEDER


                     When unpacked you got a file: descr4.0.exe 7016 bytes
                     (When  spread  as  descr4.0.lha   file.  I don't know
                     anything about the -z-speed.lha yet)


                     SOME FACTS:

                  .  There is no docs with this file, but the program look
                     like a kind of scene-utility or like.

                  .  The  unpacked  "Descriptor  3.0"  bomb is 7016 bytes.
                     Please remark IT ISN'T ....the 4.0 version, but a 3.0
                     version!  

                  .  The   "Discriptor  3.0"  trojan   needs a  file named
                     "descriptions.txt"  placed  in the S/Dir,  if not the
                     descriptor will guru.

                  .  If executed the "Discriptor  bomb" will tell, that it
                     need a file  called "Snap" in memory or tries to load
                     it from the C/Dir., Don't trust this...

                  .  In fact  you  Amiga  will  get the following command:
                     "Delete :#? all" 

                  .  And OH, NO GUESS WHAT.....your whole harddisk or disk
                     will be deleted! (Not formatted)

                  .  This trojan can't infect and be spreaden. It can ONLY
                     DAMAGE IF EXECUTED -  A REAL TROJAN!
@Endnode

@Node CascadeID92 
@Next "A"
@Prev "03-10-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


CASCADE 2.1


                     This bootvirus does not need the trackdisk.device.  In
                     the  bootblock  you can read the following ASCII text:
                     "Cascade V2.1CCount".

                  .  By  using  Kickstart  2.0  and later versions you will
                     probably get a guru.

                  .  By  using  Kickstart  1.3  your  mousepointer  will be
                     transformed into a penis.
@Endnode


@Node CreepingEel 
@Next "A"
@Prev "03-10-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


CREEPING EEL         

                     This bootvirus does not need the trackdisk.device.  As
                     soon as the counter reaches the value $14 you will get
                     the German flag colors on the screen. In the bootblock
                     you can read the following ASCII text:

                     "Hello Computerfreak. You've got now your first virus.
                     The Creeping Eel. Many disks are infected ! Written by
                     Max of Starlight 29.04.1992 <<MAX>>".
                     
                  .  Damage: Over writes bootblock. But even worse.... this
                     virus can damage your disks or harddisk too. The virus
                     writes garbage in a cylinder on your disks or harddisk
                     On disks the root-Cylinder will be damaged.
@Endnode


@Node Detlefboot 
@Next "A"
@Prev "03-10-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


DETLEF BOOT VIRUS


                     This  bootvirus  does  not  need the trackdisk.device.
                     When  the  virus  is active you will get the following
                     message:
                                        Guten Tag.
                                    Ich heie DETLEF 
                     Ich werde Sie in der nchsten Zeit etwas nerven.
                     Gemacht wurde ich von       M  A  X       .

                     (You  can  see  again...... an other german lame virus
                     programmer, who are working in the night with the holy
                     spirit and flame, until the police a day will come and
                     catch him)
@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node 13-09-93 
@Next "A"
@Prev "Main"
@Toc "Main"
THE BOOTX RECOG VERSION IN THIS 1.80 UPDATE KNOWS THESE NEW VIRUSES:

                   @{"  Access Forbidden boot virus                     " link AccessForbidden}
                   @{"  Dum II Dum boot virus                           " link DumIIDum}
                   @{"  The European Disaster                           " link EuropeanDisaster}
                   @{"  TTK Virus boot virus                            " link TTKVirusboot}
                   @{"  Message Acid Link Virus                         " link MessageAcid}
                   @{"  Thaho8 2.0 Virus boot virus                     " link Thaho8}
                   @{"  The Fuck infector (ModemCheck)                  " link FuckModemCheck}



Our  thanks are going the following excellent guys for the support of these
new  viruses.   Without  these  excellent  guys  there  have not been a new
update:


Rune Goksr, Norway.  Ulrik Nielsen, Denmark.  Gert Lamers, Holland.  David
Elmquest Denmark.  Jim Maciorowski, USA.


@Endnode


@Node AccessForbidden 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


ACCESS FORBIDDEN


                     This  one  display  a  picture  at boot time.  It then
                     modifies  the disk boot sector.  And then it makes the
                     disk  to  a  "not  a  DOS disk".  The picture shows an
                     access forbidden logo.  This is the reaction of Access
                     forbidden being run with Kickstart 3.0. 
@Endnode


@Node DumIIDum 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


DUM II DUM


                     This  virus  is  not  a  link  virus  nor a filevirus,
                     it  is  not  even  a  true boot virus.  It fills about
                     the  first  4  sectors of the disk included the 2 boot
                     sectors. The thing it does on boottime is that it will
                     Allocate  memory as low as possible. and then load the
                     sectors 2-4 into that area,  from there the virus will
                     infect your other disks.  
@Endnode


@Node EuropeanDisaster 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


EUROPEAN DISASTER


                     It's a  ordinary  bootblock virus,  which can't infect
                     Amiga  with  Kickstart >1.3, but will guru if you boot
                     infected disks at kickstart 2.0.
@Endnode


@Node TTKVirusboot 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


TTK VIRUS            It's  a  ordinary bootblock virus,  which can't infect
                     Amiga  with  Kickstart  >1.3, but guru if you boot the
                     disk at kickstart 2.0.
@Endnode


@Node MessageAcid 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


MESSAGE ACID LINK VIRUS


                     A  very  nasty  easy  spreaden  linkvirus,  which  can
                     affect a  lot of damaged files on your harddisk.  Take
                     care fellows.
@Endnode

@Node Thaho8 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


Thaho8 2.0 Virus     


                     It's a very nasty bootblock virus. Nothing more to say
@Endnode


@Node FuckModemCheck 
@Next "A"
@Prev "13-09-93"
@Toc "Main"
THE NEW VIRUS IN THIS UPDATE:


THE FUCK INFECTOR (MODEM CHECKER)  


                     This  virus  is  original  spreaden  in  a  file named
                     MCheck.lha  16.772  bytes,  which  should  pretend  to
                     be a  modem checker program: "MODEMCHECK  V1.1 (07.05.
                     93)  Copyright  1993  by Mario Zeltik".  But false the
                     Modemcheck  program  is  a trojan, which install a new
                     "LoadWB" the virus itself 3604 bytes. 

                     BootX  will  recognize the unpacked version (but still
                     CrunchMania packed)  15516 bytes,  the unpacked Modem-
                     Checker  22252  bytes  and the "LoadWB" containing the
                     virus part, which cause all the damage.

                     It's very nasty one. The fuck virus, will not activate
                     itself  if  SnoopDos  is active. This trojan  "loadwb"
                     will start the horrible damage,  if you don't use your
                     keyboard  10 minutes.  After  that  time your harddisk
                     will  be  low  level formated filling casually all the
                     tracks with: FUCKFUCKFUCK.. and so on. 

                     The  only  way  to  get  rid  of the Fuck virus, is to
                     delete the ModemCheck program.

                  *  REMEMBER  to  delete the loadwb i the c directory too!
                     Here you have a screen dump:

                               MODEMCHECK V1.1 (07.05.93)
                     Copyright  1993 by Mario Zeltik. All Rights Reserved


                     Checking CTS Line.....................Ok!
                     Checking CD  Line.....................Ok!
                     Checking DTR Line.....................Ok!
                     Checking RI  Line.....................Ok!
                     Checking TXD Line.....................Ok!
                     Checking RXD Line.....................Ok!
                     Checking RTS Line.....................Ok!

                     (Yes excellent  inded?, "Fuck me", but my modem wasn't
                     connected !!!!!!!)

                     BootX  will  recognize the unpacked version (but still
                     CrunchMania packed)  15516  bytes, the unpacked Modem-
                     Checker 22252 bytes, and Loadwb 3604 bytes.


                     I have got this excellent analyse from Bjrn Rese from
                     the University of Odense, thank you Bjrn!:

                     Type: File (Trojan)
                     Alias: MODEMCHECK
                     Origin: Modemchecker in MCheck.lha
                     Infect: C:LoadWB

                     SHORT: Destroys contents of harddisks


                     LONG:
                     MCheck.lha (size: 16772 bytes) contains
                     Modemcheck.doc (size: 2227)
                     Modemchecker (size:  15516, version:  V1.1 (07.05.93))

                     Modemchecker is packed with CrunchMania. Unpacked size
                     is 22252 bytes.

                     Modemchecker is a phony.  It pretends to check various
                     modem  lines (CTS, CD, DTR, RT, TXD, RXD, RTS), but it
                     reports  success  no  matter what (even if no modem is
                     attached.)  When Modemchecker is started it will write
                     the  virus  to C:LoadWB (new size is 3604 bytes.) Next
                     time  C:LoadWB  is  started  (typical  at startup) the
                     virus will become active.

                     The   virus  in  LoadWB  launches  a  new  task  using
                     CreateProc.   The  new  task is called Diskdriver.proc
                     (stack  = 4096, priority = 0).  Afterwards it proceeds
                     with   the   original   LoadWB   ("$VER   loadwb  38.9
                     (30.3.92)",10,13,0).

                     The  Diskdriver.proc  task  is the malicious part.  It
                     waits  for  30000  ticks  (ticks/50  seconds  for PAL,
                     equals  10  minutes, ticks/60 for NTSC), when it fills
                     an internal buffer of 150000 bytes (allocated by a BSS
                     section  (HUNK_BSS)) with FUCKFUCKFUCK...  It tries to
                     open  a file called S:HORSE.  If it was successful the
                     virus  will  gracefully  exit,  if  not  it will cause
                     havoc.   It will examine all physical devices (dn_Type
                     =  DLT_DEVICE),  and pick out all where (de_numheads >
                     2) OR (de_uppercyl >= 90) OR (de_blkspertrack > 22)

                     Then  it will write the content of the internal buffer
                     (FUCKFUCK...)  on  all  track from the lowest cylinder
                     (de_lowcyl)  to  the highest cylinder (de_yppercyl) of
                     all  selected  devices  (typical  harddisks).  When it
                     exits.


                     Observations:

                     The  programming style is pretty clean which indicates
                     a  rather  experienced programmer.  He's probably from
                     Europe  (30000 ticks yields exactly 10 minutes by 50Hz
                     powersupplies.)

                     S:HORSE  seems  to be a safety line for the programmer
                     (and his friends (if he has any :-))

                     It doesn't destroy ordinary floppy disks.

                     Destruction  is performed at exec.library level (using
                     DoIO)


                     Notes:

                     Some  uncorrect  things  have been said about the FUCK
                     virus.

                [1]  "The  'LoadWB'  that  contains  the  virus  is the 2.1
                     version,  so  the  virus  isn't danger for any machine
                     with 1.2 or 1.3."

                [2]  "Before the infection begins a couple of tests is run:
                     -  execversion  =  37.132 = KS2.04 .  If no there's NO
                     infection.   The  program  just  stops.  This means no
                     danger to owners of A600, A600HD and so on."

                     Deadly wrong!  Even though LoadWB will fail because it
                     requires  at least V36 (dos.library) it has already at
                     this  point  launched the virus, which doesn't require
                     any  particular  version  of the OS.  I tested this on
                     1.2, and the Diskdriver.proc was running.

                [1]  "Once  installed  at  the  boot  Fuck  Virus will wait
                     patiently  and  if  not  IDCMP  message of any type is
                     registered [...] 10 minutes, it will proceed...""7.

                [3]  This  trojan  "loadwb" will start the horrible damage,
                     if you don't use your keyboard 10 minutes."

                     The  havoc start (provided S:HORSE wasn't found) after
                     approx.  10 minutes (30000 ticks) no matter what IDCMP
                     messages  is  registered.   It doesn't care about user
                     interaction.

                [4]  Casual filling of the tracks

                     Data    isn't    destroyed    randomly,    but    very
                     systematically.   From  the  lowest  cylinder  to  the
                     highest.   The  reason why it seems random is probably
                     due to the fragmentation of the harddisk.


                    [1] FuckVirus.doc by Gabriele Greco, author of 
                        FuckChecker (Fuckchck.lha).

                    [2] VT.Knows by Heiner Schneegold, author of VT.

                    [3] VirWarn-1b by Erik Loevendahl Soerensen.

                    [4] Everybody, except me ;-)

                    Analysed by

                    Bjorn Reese.
                    SAFE HEX INTERNATIONAL
@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node WhySHI? 
@Next "A"
@Prev "Main"
@Toc "Main"

WHY THIS NEW SHI UPDATE?



Concerning  the serious lack of new viruses and the absence of support from
the users Peter Stuer have send the following 2 messages explaining, why he
have stopped to make future updates:



              @{"  1.st letter from Peter Stuer To: All: End of BootX  " link EndofBootX}

              @{"  2.nd letter from Peter Stuhr future updates by SHI  " link futureUpdates}
@Endnode


@Node EndofBootX 
@Next "A"
@Prev "WhySHI?"
@Toc "Main"


LETTER FROM PETER STUER TO: ALL SUBJ: END OF BOOTB



Area: BOOTX
From: Peter Stuer (2:292/603.7)
  To: All
Subj: End of BootX

Dear users,

after nearly 4 years of virus hunting I have decided to leave the challenge
to  other programmers.  During the last year a few of nice competitors have
emerged  in  the anti-virus scene (I will not mention any names).  It is up
to their programmers to fill the possible void that BootX leaves.

The  last  BootX version released was BootX 5.23a Recog 1.75.  This version
has  apparently  rapidly aged.  At the time 60 and 90 days seemed extremely
long  times  between updates.  However, during the last 2 months I have not
received any new viruses, which explains the aging of BootX.

I  hope all BootX users find another viruskiller to replace it.  Thanks for
all your support.

Peter.
@Endnode


@Node futureUpdates 
@Next "A"
@Prev "WhySHI?"
@Toc "Main"

LETTER FROM PETER STUHR CONCERNING, THAT THE FUTURE BOOTX UPDATES ARE TAKEN
OVER NOW BY SAFE HEX INTERNATIONAL:



Dear user,

Ever  since  I  stopped  the BootX development, SHI has been pressing me to
either  continue  BootX  or  to  release  the source to them.  The first is
impossible and the latter not appealing.

However,  to  make the transition more smoothly, I have released this patch
to BootX 5.23a.  It will no longer bug you with the date requesters.

Also in this archive you will find BootX.Recog library 1.75a which also has
the date check removed.

NOTE:   These are patches done by me, Peter Stuer.  This is a one of a kind
event.   I  am  sending  the source of the Recog library to SHI in Denmark.
They  will  decide  if  anyone of their programmers is going to pick up the
release of new BootX Recog libraries.

If  you  doubt the authentity of this patch, feel free to drop me a Netmail
at Fido 2:292/603.7.

Peter.
@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

@Node FromAllOfUs 
@Next "A"
@Prev "Main"
@Toc "Main"

THANKS TO PETER FROM ALL OF US. YOU ARE A REAL GOOD FRIEND!


First SHI would like to thank Peter Stuer for the excellent job he did with
BootX. Thanks Peter from all of us.


    As  you can see of the in this doc-guide, the development of BootX was
    stopped for some time.  We are doing our best to keep BootX up-to-date
    with  all the latest viruses.  BUT I need YOUR....support too.  Please
    send all new vira to us, or to the nearest SHI virus center.




           ONLY WITH YOUR HELP TOO, (YES YOU, THE READER OF THIS DOCUMENT),
           WE CAN SUCCEED!


                               Michael Nielsen & Erik Loevendahl from SHI.


@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node localesupport 
@Next "A"
@Prev "Main"
@Toc "Main"
SHI NEED YOUR HELP FOR FUTHER LOCALE SUPPORT!


          For futher locale support I need help to get the BootX menu
          localized  for  the following countries:  Spanish, Turkish,
          Portuguese,  Polish,  Finnish,  Greek  and  of course every
          country, which isn't localized yet. Please send your locale
          translation direct to me:


Programmer:   Michael Nielsen
              steralle 44  
              6500 Vojens
              Dk. Denmark

Phone:       +45 74-540416
@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node VirusesWanted 
@Next "A"
@Prev "Main"
@Toc "Main"
VIRUSES WANTED FOR NEW BOOTX UPDATES, 



SHI NEED YOUR HELP FOR FURTHER UPDATES!
As  you  can  see  of  the  in this doc-guide, the development of BootX was
stopped  for  some  time.  I am doing my best to keep BootX up-to-date with
all  the  latest viruses.  BUT I need YOUR....support too.  Please send all
new vira to me, or to the nearest SHI virus center.


I...... YOU FIND new viruses, please send them TO-DAY!!!! SHI are currently
searching for the following viruses :


$4EB9 Link clone             -  0  0-L
ABC Virus (need block 1-3)   -  0  0
Aibon 2  trojan (784)        -  0  0-BBS
Aibon-ACP.Ctrl.              -  0  0
A.I.S.F. Virus (8708)        -  0  0-T   Damage maybe the heads of harddisk
Amida                        -  0  0
AmiPatch virus 1.0a (8288)   -  0  0-BBS Infiltrate or damage BBS
Anti-Knacken                 -  0  0 
Antivirus                    -  0  0
AeReg.BBS-Trojan (664)       -  0  0-BBS Infiltrate or damage BBS
A.H.C. Virus                 -  0  0
Australian Paradise          -  0  0
AutoBootingBootProtector2.0  -  0  0
BB-Prot                      -  0  0
BBS/Whitebox v 8.0  (34896)  -  0  0-BBS Infiltrate or damage BBS
Beethoven (2608)             -  0  0
Black Night                  -  0  0
Blockchain Virus             -  0  0
Boot-Aids                    -  0  0
Butonic 4.55                 -  0  0-F
Chain V0.23                  -  5  0-I
Charlie Brown (Hireling)     -  0  0
Check Filevirus (18644)      -  0  0-F
Christmas Violator (1060)    -  0  0-F
Clock 1.1 (setmap & Install) -  0  0
Clock Virus (fast running)   -  0  0
Clock Virus (back running)   -  0  0
CompuPhagozyte 7             -  0  0-F
CopyLock-Virus (Block 0-3)   -  0  0
Cracker Exterminator         -  0  0
CompuPhagozyte 7             -  0  0-F
CopyLock-Virus (Block 0-3)   -  0  0
Cracker Exterminator         -  0  0
Dailer BBS V2.8g (33908)     -  0  0-BBS Infiltrate or damage BBS
Dark Avenger B link (1072)   -  0  0-L
Datacrime-killer (ASV clone) -  0  0
DirOpus CRC  (20716)         -  0  0-BBS Infiltrate or damage BBS
Disk.info Bomb (370)         -  D  0-F
Dark Avenger B link (1072)   -  0  0-L
Datacrime-killer (ASV clone) -  0  0
DirOpus CRC  (20716)         -  0  0-BBS Infiltrate or damage BBS
Disgust                      -  0  0
Disk.info Bomb (370)         -  D  0-F
Disktroyer v2 (812)          -  0  0-F
Disktest (1348)              -  0  0-F
Disk-Killer 1.0 (1368)       -  0  0
Disk Repair v 2.6 (37740)    -  0  0-F
Dlog V1.8 Messeagetop BBS    -  0  0-BBS Infiltrate or damage BBS
Dopus (6408)                 -  0  0-F
DStructure A (428)           -  0  0-B
DStructure B (352)           -  0  0-B
DwEditv1.6 (43700)           -  0  0-BBS
Excrement Installer          -  0  0
Freshmaker virus             -  0  0
GCA                          -  0  0
Gandalf                      -  0  0
GCA BB (forpib clone)        -  0  0
Genetic Protector 2.0 BB     -  0  0
Guardian.DMS                 -  0  0-BBS Infiltrate or damage BBS
Guardians Boot Aids          -  0  0
Happy New Year               -  0  0
HNA Virus                    -  0  0
Influenza                    -  0  0
Infector (Fast Eddie clone)  -  0  0 
IRQ II (1164)                -  0  X-F
Jeff-Butonic 3.10 (2916)     -  0  V-F  Promt "Sauf blos keinen Wodka"
Jeff-Butonic 3.20 (2900)     -  0  V-F  Attention destroy harddisk boot!
Jeff-Butonic 4.55 (3408)     -  0  V-F  Promt "hoffentlich stoere ich sehr"
Jismtro.exe                  -  0  0-BBS Infiltrate or damage BBS
Joshua 3                     -  0  0
KaKo                         -  0  0
Kako Loadwb Virus (2804)     -  0  0
Kefrens II                   -  0  0
Killkim.exe                  -  0  0-BBS Infiltrate or damage BBS
Kobold II                    -  0  0
M Chat-Trojan (13.492)       -  0  0-BBS Infiltrate or damage BBS
MAD 2a                       -  0  0
MemSearcher virus            -  0  0
Monkey Killer                -  0  0
Mount Virus (1072)           -  0  0-B
MVK (1052)                   -  0  0-F
Monkey Killer                -  0  0
MWB virus (Julie clone)      -  0  0
Nano 2                       -  0  0-F
New Age virus                -  0  0
Ninja                        -  0  0
Noname 2 (Incognito 2)       -  0  0
Nuked 007                    -  0  0
Ohio                         -  0  0
P-Cracks                     -  0  0
Phatasmic Force              -  0  0
Power Team                   -  0  0
PP Bomb 3-MegaMon (26856)    -  0  0-BBS Infiltrate or damage BBS
Pstats                       -  0  0-F
R.A.F                        -  0  0        
Rimednac                     -  0  0
Sachsen Virus no 2           -  0  0
Saddam clone Lame (1848)     -  A  0-FL
Saddam clone Animal (1848)   -  A  0-FL
Saddam clone Kick (1848)     -  A  0-FL
Saddam clone Nato (1848)     -  A  0-FL
Saddam clone 1.29 (1848)     -  A  0-FL
Sao Paulo                    -  0  0
SCA 666                      -  0  F
SCA Atomix                   -  C  F
SCA Karl Marx                -  0  F
Schwartznegger               -  0  0
SCSI virus (1560)            -  A  0-F
Setmap & install             -  0  0
SMBX-Mount.Installer.(64488) -  0  0-F
Snap PP Bomb (44260)         -  0  0-B
SnoopDos 1.9 Trojan (sd-tv)  -  0  0-T   Installer of the Butonic 4.55
Suntron                      -  0  0
Sysinfo 1.1 (5680)           -  0  0-BBS Infiltrate or damage BBS
T.ET.E Virus                 -  0  0
T.ET.E  Zombi Clone          -  0  0
T.F.C. clone                 -  0  0
T.F.C. Revenge LWB 1.3 (2804)-  0  0
Thaho8 2.0                   -  0  0
TimeBomb 0.9 clone (1584)    -  E  0-B
Tomates Gentechnic Service 2 -  0  0
Topdog 1.0 (2260)            -  0  0-BBS Infiltrate or damage BBS
Top Util Virus (2260)        -  0  0-BBS Infiltrate or damage BBS
Tristar Viruskiller Virus    -  0  0
Tristar-Viruskiller V1.0     -  0  0
TTK Virus                    -  0  0
UCA                          -  0  0
UcAIDS                       -  0  0
Uhr virus.BB                 -  0  0
UInfo (13048)                -  0  0-BBS Infiltrate or damage BBS
Ulog V1.8 Messagetop BBS     -  0  0-BBS Infiltrate or damage BBS
Uinfo (13048)                -  0  0-BBS Infiltrate or damage BBS
Umyj Dupe Virus              -  0  0
VirConSet virus              -  0  0
VirconSet 2 virus            -  0  0
Virkill 2                    -  0  0
Virus Construktion Set       -  0  0-F
Virus Terminator 6.0 (1880)  -  0  0-T
Virus II                     -  0  0
Virusmaker 1                 -  0  0
Zorro Willow                 -  0  0
Zviruskiller 1.5             -  0  0
ZSpeed (9556)                -  0  0-BBS Infiltrate or damage BBS
XaCa virus (1368)            -  0  0-F
Xcopy2                       -  0  0
XprZSpeed 3.2 (9556)         -  0  0-BBS Infiltrate or damage BBS




And infected disks with the "French Kiss virus" and "ABC virus" containing
the whole viruses (Block 0-3- or 4).  I ONLY..have the first 1024 bytes!!!
   


And of course I will be very happy for any NEW.......VIRUS you might find !



          Please....mark the disk "Attention Virus"(please take care of our
          harddisk) Remember to state your address and phone number, if you
          want a reply,  but isn't necessary,  if you want to be anonymous,
          only  the  VIRUS counts. (SHI don't care, what "KIND" of disk you
          send  us).  After  the disk is analyzed the disk is formatted and
          your name,  will be 100 % arcivated in my trashcan. SHI....ALWAYS
          keep our promises!!, (no more questions then!)


          SEND A LETTER PLEASE: 
          An VERY EASY..way is to send the viruses to your regional center,
          who will then send them along to SHImain:


                                  @{"   SHI Addresses  " Link Ad}

@Endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@node a "How to get in contact with SHI"
@Prev "Main"
@Toc "Main"
HOW TO GET IN CONTACT WITH SHI



Please contact one of our centers and we will try to help you.
See more information in the @{"   Addresses  " link Ad} file.



                         MAIN CENTRAL VIRUS CENTER:

                         Erik Loevendahl Soerensen
                         Snaphanevej 10
                         DK-4720 Praestoe
                         DENMARK





@endnode


@node Ad "Addresses"
@Prev "Menu"
@Toc "Menu"
                    SAFE HEX INTERNATIONAL ADDRESS LIST:

SHI need 2-3 centres in most of the following countries. Are you more than
20 years old and knowing 2-3 good friends with interrest to help.  Do your
friends or  yourself  have a phone, a 24 pin printer or laserprinter.  And
most important time and interrest  to  run a new  virus help centre,  in a
serious way with the aim to get our SHI disks to be the most popular Amiga
disks around?
Then please conctact me, @{"Erik Loevendahl Soerensen." link a}

                         SHI Regional Virus Center's
	    @{" ARGENTINA    " link ARGENTINA}    @{" AUSTRALIA    " link AUSTRALIA}    @{" AUSTRIA      " link AUSTRIA}
	    @{" BELGIUM      " link BELGIUM}    @{" CZECH        " link CZECH}    @{" DENMARK      " link DENMARK}
	    @{" EAST ASIA    " link EAST_ASIA}    @{" ENGLAND      " link ENGLAND}    @{" FINLAND      " link FINLAND}
	    @{" FRANCE       " link FRANCE}    @{" GERMANY      " link GERMANY}    @{" GREECE       " link GREECE}
	    @{" HOLLAND      " link HOLLAND}    @{" IRAN         " link IRAN}    @{" IRELAND      " link IRELAND}
	    @{" ITALY        " link ITALY}    @{" NORWAY       " link NORWAY}    @{" POLAND       " link POLAND}
	    @{" PORTUGAL     " link PORTUGAL}    @{" ROMANIA      " link ROMANIA}    @{" SLOVAKIA     " link SLOVAKIA}
	    @{" AFRICA       " link SOUTH_AFRICA}    @{" SPAIN        " link SPAIN}    @{" SWEDEN       " link SWEDEN}
	    @{" SWITZERLAND  " link  SWITZERLAND}    @{" TURKEY       " link TURKEY}    @{" USA          " link USA}
            @{" HUNGARIA     " link HUNGARIA}    @{" CANADA       " link Canada}    @{" REP OF CHINA " link CHINA}

  @{" SAFE HEX BUDDY SYSTEM " link BUDDY}  @{" SAFE HEX MAGAZINE " link RESIDENT}  @{" SAFE HEX BULLETIN BOARD " link BULLETIN} 

        @{" SHI MAIN CENTRAL VIRUS CENTRE " link cen}
@endnode



@node RESIDENT "SAFE HEX MAGAZINE RESIDENT"
@Toc "Ad"

        SAFE HEX MAGAZINE RESIDENT

        Vidar Bang
        Sagahyden 24
        9500 Alta
        Norway

        Phone: + 47 84 30660

@endnode


@node BULLETIN "SAFE HEX INTERNATIONAL BULLETIN BOARD"
@Toc "Ad"

        SAFE HEX INTERNATIONAL BULLETIN BOARD:

        Jan Bo Andersen
        Veronikavej 33 1 tv.
        DK-2610 Rdovre
        Denmark

        BBS: + 45 36 72 68 67

        Open 0000 -2400. Modem v32 bis.

        Always the newest anti-virus stoff and a lot of texts
        concerning data security. You are welcome, to get any
        virus problem solved by our worldwide virus "HOT-LINE"
        if you contact some of our local virus centers.

        Or you can contact the sysop in Denmark by voice:

        @{" Oh yes! I would like " link DENMARK}


@endnode



@node BUDDY "SAFE HEX BUDDY SYSTEM"
@Toc "Ad"

	SAFE HEX BUDDY SYSTEM

	Stefan Daugaard Hansen
	Tranehjen 236
	5250 Odense sv
	Denmark

	Phone + 45 65 92 65 42


@endnode



@node HOLLAND "SHI REGIONAL VIRUS CENTRE HOLLAND"
@Toc "Ad"

	SHI REGIONAL VIRUS CENTRE HOLLAND

	Marco van den Hout
	Doornboomplein 9
	NL-5081 GR Hilvarenbeek
	The Netherlands

	Phone +31 04255 3513

@endnode



@node AUSTRALIA "SHI REGIONAL VIRUS CENTRE AUSTRALIA"
@Toc "Ad"

	SHI REGIONAL VIRUS CENTRE AUSTRALIA

	Amiga Quarantine
	Brian & Rick Logan
	P.O. Box 533
	Engadine
	N.S.W 2233
	Australia

	(No phone)


@endnode



@node SLOVAKIA SHI REGIONAL VIRUS CENTRE SLOVAKIA"
@Toc "Ad"

	SHI REGIONAL VIRUS CENTRE SLOVAKIA

	Ondrej Krebs
	SNP 4
	908 51 Holic
	Slovakia Republic

	Phone: + 0801 3764

@endnode


@node CZECH "SHI REGIONAL VIRUS CENTRE CZECH"
@Toc "Ad"

	SHI REGIONAL VIRUS CENTRE CZECH

	MB Soft
	Dalimilova 6
	130 00 Praha 3
	Czech Pepublic


@endnode


@node DENMARK "SHI REGIONAL VIRUS CENTRE DENMARK"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE DENMARK

        Jan Andersen
        Veronikavej 33 I tv.
        2610 Rdovre

        Phone + 31 41 68 67



@endnode



@node ITALY "SHI REGIONAL VIRUS CENTRE ITALY"
@Toc "Ad"

	SHI REGIONAL VIRUS CENTRE ITALY

	Massimo Gais
	V. Vittorio Veneto 31
	80029 S. Antimo (NA)
	Italy

	Phone + 39 81 5052256


@endnode


@node ENGLAND "SHI REGIONAL VIRUS CENTRE ENGLAND"
@Toc "Ad"

	SHI REGIONAL VIRUS CENTRE ENGLAND

        Paul Browne
        304 Leeds Road
        Eccleshill
        Bradford
        W.Yorks
        BD2 3LQ
        England

        Phone + 44 274 631 041
        Fidonet 2:256/301.2@

@endnode


@node USA "SHI REGIONAL VIRUS CENTRE USA"
@Toc "Ad"

  SHI REGIONAL VIRUS CENTER USA?

Do you have the time and the interest to become leader of a "Regional Virus
Center" in USA?  


If  so,  you  are very welcome to contact SHImain, and we will give you all
the  help  you  need to start.  It is VERY important that you are "at home"
with  your Amiga and know a lot about viruses and the like, so that you can
help people in your own country with their virus problems.



@endnode


@node GREECE "SHI REGIONAL VIRUS CENTRE GREECE"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE GREECE

        Konstantinos Angelis
        P.O. Box 50784
        54014 Thessaloniki 22
        Greece

        Phone: +30 431 29207
        Fax  : +30 431 38214
        BBS  : +30 431 72171


@endnode


@node BELGIUM "SHI REGIONAL VIRUS CENTRE BELGIUM"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE BELGIUM

        Dutch Language:

        Koen Peetermans
        Vrijheersstraat 8
        B-3891 Gingelom
        Belgium

        Phone: + 32 11 48 58 19


        SHI REGIONAL VIRUS CENTRE BELGIUM

        French Language:

        Gregoire Jean-Christophe
        64 Franstimmermansstraat
        1600 Sint Pieters Leeuw
        Belgium

        Phone: + 02 377 76 78
@endnode


@node SPAIN "SHI REGIONAL VIRUS CENTRE SPAIN"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE SPAIN

        John Lohmeyer
        Parque Guell 7
        08338 Premia de Dalt
        Barcelona
        Spain

        Phone: + 03 752 38 85
        Fax  : + 03 752 30 79
        BBS  : + 03 892 39 83


@endnode


@node GERMANY "SHI REGIONAL VIRUS CENTRE GERMANY"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE GERMANY


Do you have the time and the interest to become leader of a "Regional Virus
Center" in Sweden?  


If  so,  you  are very welcome to contact SHImain, and we will give you all
the  help  you  need to start.  It is VERY important that you are "at home"
with  your Amiga and know a lot about viruses and the like, so that you can
help people in your own country with their virus problems.  




@endnode


@node SWEDEN "SHI REGIONAL VIRUS CENTRE SWEDEN"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE SWEDEN

Do you have the time and the interest to become leader of a "Regional Virus
Center" in Sweden?  


If  so,  you  are very welcome to contact SHImain, and we will give you all
the  help  you  need to start.  It is VERY important that you are "at home"
with  your Amiga and know a lot about viruses and the like, so that you can
help people in your own country with their virus problems.  


@endnode


@node POLAND "SHI REGIONAL VIRUS CENTRE POLAND"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE POLAND:

        Wojtek Gorzkowski
        UL. Rewolucji Pazd 95/102
        01-242 Warsaw
        Poland                  

        Phone : + 48 22 367 443  (18.00-20.00)
        Phone : + 48 26 252 994  (10.00-17.00)
        BBS   : + 48 22 367 443  (20.00-08.00)


@endnode


@node FRANCE "SHI REGIONAL VIRUS CENTRE FRANCE"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE FRANCE:

        Brun Stephane
        255 Chemin Fontisson
        F-84470 Chateaneuf de Gadagne
        France

        Phone : + 90 22 54 22


@endnode


@node NORWAY "SHI REGIONAL VIRUS CENTRE NORWAY"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE NORWAY:

        Kurt Hansen
        Langyveien 13
        N-4026 Stavanger
        Norway

        Phone : + 47 4 520420


@endnode


@node EAST_ASIA "SHI REGIONAL VIRUS CENTRE EAST ASIA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE EAST ASIA:

        Javed Islam
        P. O. Box 10119
        Feroze Pur Road
        Lahore 54600
        Pakistan


@endnode


@node YUGOSLAVIA "SHI REGIONAL VIRUS CENTRE YUGOSLAVIA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE YUGOSLAVIA:

        Nikolic Tomislav
        Vase Stajica 3
        Sombor 25000
        Yugoslavia-Serbia

        Phone: + 382 520 189
        BBS  : + 813 849 4034

@endnode


@node ARGENTINA "SHI REGIONAL VIRUS CENTRE ARGENTINA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE ARGENTINA:

        Pablo A. Trincavelli
        Dorrego 459 1 er. piso
        2000 Rosario
        Santa Fe
        Argentina

        Phone: +54 41 252906


@endnode


@node FINLAND "SHI REGIONAL VIRUS CENTRE FINLAND"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE FINLAND:

        Johannes Verwijnen
        Hiihtomentie 33 B 16
        SF-00800 Helsinki
        Finland

        Phone: 358 0 759 1263
        Phone: 358 0 787 449



@endnode


@node PORTUGAL "SHI REGIONAL VIRUS CENTRE PORTUGAL"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE PORTUGAL:

        Alexandre Manuel Reis
        Casal de So Brs
        Rua Antnio Nobre, Lote 5, R/C DTO
        2700 Amadora
        Portugal

        Phone: + 351 01 494 8932
        Fax  : + 351 01 494 4662



@endnode


@node SWITZERLAND "SHI REGIONAL VIRUS CENTRE SWITZERLAND"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE SWITZERLAND:

        Meier Remy
        Hardstrasse 111
        CH-4052 Basel
        Switzerland

        Phone: + 41 61 312 63 95
        Fax  : + 41 61 312 63 95


@endnode


@node SOUTH_AFRICA "SHI REGIONAL VIRUS CENTRE SOUTH AFRICA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE SOUTH AFRICA:

        Richard Harris
        P.O.Box 3147
        1610 Edenvale
        South Africa

        Phone: + 27 011 453 6327


@endnode


@node TURKEY "SHI REGIONAL VIRUS CENTRE TURKEY"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE TURKEY:

        Volkan Umak
        Sakiz Sok. Berkel Ap. 6/2
        81300 Kadiky Istanbul
        Turkey

        Phone: + (1) 346 86 48
        Fax  : + (1) 349 96 35


@endnode


@node AUSTRIA "SHI REGIONAL VIRUS CENTRE AUSTRIA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE AUSTRIA:

        David Van Assche
        Sieveringer Strasse 126, 4
        Vienna 1190
        Austria

        Phone: + 222 44 39 91
        Fax  : + 222 44 42 51


@endnode


@node IRELAND "SHI REGIONAL VIRUS CENTRE IRELAND"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE IRELAND:

        Anthony Melia
        4 Seagrange Drive
        Baldoyle
        Dublin 13
        Ireland

        Phone + 01 39 31 23


@endnode


@node IRAN "SHI REGIONAL VIRUS CENTRE IRAN"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE IRAN:

        Soroush Khalatbari
        3 floor 32, Mehraban
        Eskandari-Jonobi street.
        13116 Tehran
        Iran

@endnode


@node ROMANIA "SHI REGIONAL VIRUS CENTRE ROMANIA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE ROMANIA:

        Prundeanu Cristian
        Str. Rodnei nr. 6
        1900 Timisoara
        Romania


@endnode


@node HUNGARIA "SHI REGIONAL VIRUS CENTRE ROMANIA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE HUNGARIA

        Pista Palacy
        Szechenyi U. 55 II/1
        7100 Szekszard
        Hungaria

        Phone: +36 74 3130 913
        Fax  : +36 74 3130 913

@endnode


@node Canada "SHI REGIONAL VIRUS CENTRE CANADA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE CANADA:

        Ray J. Morrell
        45 Salisbury Ave.
        Toronto, ON
        M4X1C5 Canada

        Phone: + (416) 324 9513
        BBS  : + (416) 324 9439

@endnode


@node China "SHI REGIONAL VIRUS CENTRE REP. OF CHINA"
@Toc "Ad"

        SHI REGIONAL VIRUS CENTRE CHINA

        Chen Pan
        56, Lane 25, Sung-Teh Road
        Taipei, Taiwan
        Republic of China

        Phone: + 886 2 759 1371
        Fax  : + 886 2 727 1235

@endnode


@node Cen "SHI MAIN CENTRAL VIRUS CENTRE"
@Toc "Ad"

        SHI MAIN CENTRAL VIRUS CENTRE:

        Erik Loevendahl Soerensen
        Snaphanevej 10
        DK-4720 Praestoe
        Denmark

        Phone: +45 55 992512
        Fax  : +45 55 993498


(Please  send  2 "Coupon-Response  International" , if you want information
about SHI by letter).


SALE: (Main Center:

Only ....the english SHI versions, but in Denmark the sale of PC killers in
danish is very popular too!


PAYMENT (Main Center):

Scandinavian:  Postgiro Account:  9884645  (Only  scandinavian citizens. $1
(USD) is equal 6 Dkr/, 6 Skr/, 6Nkr)! You are welcome to send money in cool
cash but in a safety.. way!


FOREIGNERS
Don't...send bank cheque, ONLY ....cool cash or international giro (Avis de
Versement International). Please don't send coins only bank notes.


Phone   : + 45 55 992512 (NOT a BBS, but I have a modem Robotics V42 HST!).
Fax     : + 45 55 993498

Fidonet : 2:23424/43 (Remember your post address)

            Attention:  Fidonet mail is only replied by post letters or
            by faxsimile, therefore state your name and adderess to me.


Virus helpline: Phone +45 55 992512 between 1600-2200 GMT
Virus helpline: Fax   +45 55 993498 between 0000-2400 GMT

@endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node Emer 
@Next "A"
@Prev "Main"
@Toc "Main"

IF YOU HAVE A MODEM. PLEASE SEND NEW VIRUSES DIRECT TO:




 .  SAFE HEX INTERNATIONAL BBS - REGIONALE VIRUS CENTER DENMARK EAST
    BBS phone (+45) 3672 6867  - modem 14.400 V32 bis. Open 00-24:00


             SysOp Jan Bo Andersen



                    Remember only the new virus count. We don't care,  what
                    kind of infected programs you send to us be quite sure.
@endnode


:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::


@Node always 
@Next "A"
@Prev "Main"
@Toc "Main"
DEAR AMIGA FRIEND

         THANK YOU VERY MUCH FOR YOUR HELP TO IMPROVE BOOTX TO KNOW 


                         *   EVEN MORE VIRUSES  *




                     WITHOUT YOUR HELP THERE HAVE BEEN NO BOOTX VIRUS 
                     KILLER TO-DAY, BE QUITE SHURE!



                                                 KIND REGARDS


                                                 ERIK LOEVENDAHL SORENSEN
                                                 SHI MAIN CENTER DENMARK

@Endnode