home *** CD-ROM | disk | FTP | other *** search
- *********************************************
- The DIARRHEA viruses: graphic .COM infectors
- *********************************************
-
-
- Rationale: To create a really annoying nuisance virus which
- once discovered compels the user to drop everything
- and attempt to find it.
-
- Characteristics:
-
- DIARRHEA.COM is a appending .COM infector which will
- display the ANSI "EAT MY DIARRHEA!" - GG Allin &
- The Texas Nazis'" on every Friday an infected file
- is executed. The ANSI is sufficiently glaring so
- that anyone with ANSI.SYS loaded won't miss it.
-
- DIARRHEA.COM spreads by way of a path search, so
- hard disk targets are somewhat dependent upon the
- personal idiosyncracies of those hit.
-
- The virus was created with the help of Nowhere Man's
- VCL and a crunched .ASM ANSI format created by TheDraw
- 5.4. You should note that crunched ANSI's loaded into
- assembly listings aren't always perfect. For example,
- outlining the ANSI message produces garbled results,
- so for your projects, avoid it. VCL listings will also
- accept 'normal' ANSI .ASM tables but size is a
- prohibiting factor. (That is UNLESS you want a virus
- that is over 5k in size with only a very small ANSI
- comment for a message.)
-
- DIARRHE6.COM is a final development in the DIARRHEA
- virus tale. It displays no message itself, but instead
- drops a .COMfile ANSI display onto all .EXE files
- in its path. The virus itself is an appending .COM
- infector which will search the breadth of the directory
- tree for uninfected files.
-
- This virus is a bit more hazardous than DIARRHEA in
- that it irreversibly ruins .EXE's corrupted with
- TheDraw developed ANSI .COM display. The interesting
- part of the infection comes when a ruined .EXE is
- called. The ANSI message from DIARRHEA is displayed,
- with a nice flashing blue box outlining it. You can
- imagine this might be rather maddening to anyone who's
- favorite game, gl-loader or whatever is ruined by
- it. In the meanwhile, the virus is still doing its
- thing.
-
- Some technical notes on detection:
-
- There's been quite a bit of squawk on the FidoNet from
- a number of anti-virus researchers who have assured
- themselves that VCL-produced code is easily scanned by
- F-Prot. One researcher based these findings on the fact that F-PROT can detect some VCL code as 'Vienna'
- contaminated. While there is some truth to this, F-PROT
- can only detect these traces in samples fresh from the
- assembler. If an encryption routine is included and
- the virus executed once, F-PROT loses its lock. In fact, if the virus is supplied attached to a small (let's say
- 6-byte) shell, the task of detection is complicated even more.
- .
- And this is how I've chosen to supply the DIARRHEA
- viruses. You could 'dummy' them up more by trying a
- controlled infection or PKliting them, but its a bit
- of overkill and I leave it to the individual user.
-
- -URNST KOUCH
- VIRUS_MAN BBS 215-PRI-VATE
- DARK KOFFIN BBS/CryPt 215-966-3576
-
-