home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
The Unsorted BBS Collection
/
thegreatunsorted.tar
/
thegreatunsorted
/
programming
/
misc_programming
/
diarrhea.doc
< prev
next >
Wrap
Text File
|
1992-08-07
|
4KB
|
73 lines
*********************************************
The DIARRHEA viruses: graphic .COM infectors
*********************************************
Rationale: To create a really annoying nuisance virus which
once discovered compels the user to drop everything
and attempt to find it.
Characteristics:
DIARRHEA.COM is a appending .COM infector which will
display the ANSI "EAT MY DIARRHEA!" - GG Allin &
The Texas Nazis'" on every Friday an infected file
is executed. The ANSI is sufficiently glaring so
that anyone with ANSI.SYS loaded won't miss it.
DIARRHEA.COM spreads by way of a path search, so
hard disk targets are somewhat dependent upon the
personal idiosyncracies of those hit.
The virus was created with the help of Nowhere Man's
VCL and a crunched .ASM ANSI format created by TheDraw
5.4. You should note that crunched ANSI's loaded into
assembly listings aren't always perfect. For example,
outlining the ANSI message produces garbled results,
so for your projects, avoid it. VCL listings will also
accept 'normal' ANSI .ASM tables but size is a
prohibiting factor. (That is UNLESS you want a virus
that is over 5k in size with only a very small ANSI
comment for a message.)
DIARRHE6.COM is a final development in the DIARRHEA
virus tale. It displays no message itself, but instead
drops a .COMfile ANSI display onto all .EXE files
in its path. The virus itself is an appending .COM
infector which will search the breadth of the directory
tree for uninfected files.
This virus is a bit more hazardous than DIARRHEA in
that it irreversibly ruins .EXE's corrupted with
TheDraw developed ANSI .COM display. The interesting
part of the infection comes when a ruined .EXE is
called. The ANSI message from DIARRHEA is displayed,
with a nice flashing blue box outlining it. You can
imagine this might be rather maddening to anyone who's
favorite game, gl-loader or whatever is ruined by
it. In the meanwhile, the virus is still doing its
thing.
Some technical notes on detection:
There's been quite a bit of squawk on the FidoNet from
a number of anti-virus researchers who have assured
themselves that VCL-produced code is easily scanned by
F-Prot. One researcher based these findings on the fact that F-PROT can detect some VCL code as 'Vienna'
contaminated. While there is some truth to this, F-PROT
can only detect these traces in samples fresh from the
assembler. If an encryption routine is included and
the virus executed once, F-PROT loses its lock. In fact, if the virus is supplied attached to a small (let's say
6-byte) shell, the task of detection is complicated even more.
.
And this is how I've chosen to supply the DIARRHEA
viruses. You could 'dummy' them up more by trying a
controlled infection or PKliting them, but its a bit
of overkill and I leave it to the individual user.
-URNST KOUCH
VIRUS_MAN BBS 215-PRI-VATE
DARK KOFFIN BBS/CryPt 215-966-3576