home *** CD-ROM | disk | FTP | other *** search
- Hi Todor !
-
- We have read your msg in the echo where you published your viruslist. We
- are very interested in the methods virii use as we have got a BBS in
- Germany which deals with all problems around virii.
-
- Virus Research Center Karlsruhe 18.00 - 08.00 CET 2400 8N1
- Tel.: 049-721-517735 FIDO : 2:241/7508.7
-
- We have already analysed Blackjack, Jerusalem, Stoned and VCS.
- We haven't found this 'Virus Construction Set' in your list so we think
- you are interested in this virus. Here is a short description of it. We
- already posted it in the virus-echo...
-
- Virus Name: VCS 1.0
- Aliases:
- Status: New
- Discovered: March, 1991
- Symptoms: .COM file growth, message, deleted autoexec and config
- Origin: Hamburg
- Eff. length| 1077
- Type: Non-Resident, .COM infector
- Detection
- Method: See comments below
- Removal
- Instructions: Delete Infected Files
-
- General Comments:
-
- if you start vcs.exe you are asked for the name of a textfile which will be
- included in the created virus-code. Then you are asked after how many
- generations this text is to be displayed and autoexec + config are to be
- deleted.
-
- Now a virusfile is created (length 1077 bytes). If called, it copies itself to
- a com-File on the actual drive. It is NOT limited to the actual path or the
- environment-path.
- The virus is non-resident. This means it is only spread if an infected file is
- called. It doesn't hook any vectors (would be senseless without TSR ;-)).
- If the virus detects that FluShot is in memory it doesn't become active.
- The virus mutates in any generation. But there are some constant bytes...
-
- Search String (quoting Robert Hoerner):
-
- AA E2 FA C3 ?? 81 ?? 03 01 ?? E8 E3 FF
-
-
-
- You wrote you would exchange virii with everybody who uploads a new
- one. Ok, we upload you our version of vcs: vcs10.zip
-
- ..we are particularly interested in Dark Avenger, 4096, Fish 6,
- Whale and Den Zuk. It would be great if you could give us access to
- download virii from your board...
-
- please contact us via netmail -> 2:241/7508.7
-
- this message is also contained in the zip-File.
-
- Hoping for your soon reply
-
- best regards
- Mirko & Christian - Sysops of VRC
-