home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
HPAVC
/
HPAVC CD-ROM.iso
/
R.ZIP
/
REDHRNG.ZIP
/
REDHRNG.DOC
< prev
Wrap
Text File
|
1992-08-11
|
2KB
|
35 lines
********************************************
REDHERRING virus - DIARRHEA variant included
in CryPt newsletter, #1
********************************************
The REDHERRING virus is the assembled version
of the DIARRHEA variant included in the first
CryPt newsletter.
REDHERRING is a simple, encrypted appending
.COM infector. However, it will destroy
.EXE's in its search path by dropping a
viral 'dummy' onto them. This viral dummy
is not infectious. However, when the corrupted
.EXE is called, the viral dummy will execute and
display a message from the CRAZY EDDIE virus!
If the .EXE is scanned it will test positive
for either WHALE virus (VIREX), DIR (TBScan)
or SPARSE (SCAN). Scan strings for these
viruses are embedded in the dummy, causing
the positive call. F-PROT may or may not
detect WHALE; it's heuristic scan will flag
the file as dodgy.
Have fun with REDHERRING. Put it into a situation
where someone has a viral scanner. It will
test their sophistication as they attempt to
track down this confusing infection pattern.
CONFUSION TO YOUR ENEMIES!
-URNST KOUCH
DARK COFFIN [215-966-3576]