home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
-
- VCS (VIRUS CONSTRUCTION SET) VIRUSES
- ====================================
-
- Several viruses, which are now known to have been generated by the
- Virus Construction Set, have been reported including V-1077 and
- PUSSY (Germany). They are now easily recognized by their
- characteristic length (1077 bytes) and the PERSONALIZED boxed
- message that they produce. The following description of the VIRUS
- CONSTRUCTION SET has been provided by the Virus Research Center,
- Karlsruhe.
-
- Virus Name: VCS 1.0
- Status: New
- Discovered: March, 1991
- Symptoms: .COM file growth, message, deleted autoexec and config
- Origin: Hamburg
- Eff. length: 1077
- Type: Non-Resident, .COM infector
- Instructions: Delete Infected Files
-
- General Comments:
-
- If you start vcs.exe you are asked for the name of a textfile which
- will be included in the created virus-code. Then you are asked
- after how many generations this text is to be displayed and autoexec
- + config are to be deleted.
-
- Now a virusfile is created (length 1077 bytes). If called, it copies
- itself to a com-file on the actual drive. It is NOT limited to the
- actual path or the environment-path.
-
- The virus is non-resident. This means it is only spread if an
- infected file is called. It doesn't hook any vectors (would be
- senseless without TSR ;-)). If the virus detects that FluShot is in
- memory it doesn't become active. The virus mutates in any
- generation. But there are some constant bytes...
-
- Search String (quoting Robert Hoerner):
-
- AA E2 FA C3 ?? 81 ?? 03 01 ?? E8 E3 FF
-
- Best regards
-
- Mirko & Christian - Sysops of VRC
-
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++