home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: Info on Commander Bomber and Starship? (PC)
- Message-ID: <0012.9211101922.AA06969@barnabas.cert.org>
- Date: 4 Nov 92 11:15:52 GMT
- Sender: virus-l@lehigh.edu
- Lines: 25
- Approved: news@netnews.cc.lehigh.edu
-
- pehmo@parker.ositech.fi (Petteri Jarvinen) writes:
-
- > Has anybody dissected and analyzed these new advanced viruses like
- > Commander Bomber and Starship? Virus Bulletin, perhaps?
-
- I have seen several analyses of StarShip. Two excellent ones are by
- Dmitry Gryaznov and Igor Muttik. Dmitry's analyse is published in
- Virus News International (I think). Maybe Ken has Igor's description
- on-line?
-
- Commander Bomber is a damn hard thing... Something like the MtE, but
- the MtE is about 2.5 Kb and this one is 4 Kb... :-( The virus itself
- is relatively easy (I'll post a short description, if you are
- interested) - just like the Dedicated virus is relatively trivial. The
- hard thing is the code generation engine generates the small pieces of
- code that transfer control to the main body... I have not "cracked" it
- completely yet... :-(
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.0 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-