home *** CD-ROM | disk | FTP | other *** search
- @BEGIN_FILE_ID.DIZ
- ____ ___ ____ _ ___ ___ ____
- .:::: / . \_/ ___)_/_)/ .__)(___)/ ___)::::.
- :::::/ ¦ \___ \ \ ¦ \/ \___ \:::::
- :::::\_____/___ /_ /__| \_ /___ /:::::
- [RD10/CodX]
- We are NOT release the virus infected
- ORS-QB3.LHA. Read all about the facts!
- @END_FILE_ID.DIZ
-
-
-
- Hi Folks!
-
- Here speaks RD10/Osiris because anybody uses my Pseudo and Release Logo to spread
- his fucking virus infected "Release" to our BBS Systems!
-
- I think this is a direct affront to me, i have in the last 3 weeks flamed a stupid
- fake release, other affronts i don`t know.
-
- If anybody discredit me, shall i write me direct! Or if you are an teeny boy who
- don`t have courage ?!
-
- Anyway, for all spreaders:
-
- WE DON`T RELEASE THE "RELEASE" ORS-QB3.LHA !!! ALL RELEASES FROM OSIRIS UNDERLINED,
- E.G. ORS_, NOT ORS-.
-
- Additionaly we release no 2 years old package from a firm that not exists anymore since
- 1994 . Bullshit: "AFS" Filesystem :-))
-
- Sorry to all who confused from this bullshit. In the future i include to all ORS
- releases an PUBLIC KEY from PGP, so you can verify the correctness.
-
- An sure: WE FIND THE LAMER WHO MAKES THIS !!!! You are warned!
-
- ^^^^ AMO ON:
-
- Amo: I checked some bigger boards and don't find that "FAKE" package from us.
- Look if you have that file in your board and please sent it 2 me and the
- name of the uploader ..
-
- And remeber .. the real ORS - Releases come "only" from my bbs ...
-
- ^^^^ AMO OFF:
- ____ ___ ____ _ ___ ___ ____
- .:::: / . \_/ ___)_/_)/ .__)(___)/ ___)::::.
- :::::/ ¦ \___ \ \ ¦ \/ \___ \:::::
- :::::\_____/___ /_ /__| \_ /___ /:::::
- [RD10/CodX]
-
-
-
-
-
- Warning ! The file ORS-QB3.lha contains another COP trojan. Here
- a first analyse of this little bastard.
-
- bye the way, the FILE ID looks like this:
-
-
- ____ ___ ____ _ ___ ___ ____
- ::::: / . \_/ ___)_/_)/ .__)(___)/ ___)::::.
- :::::/ ª \___ \ \ ª \/ \___ \:::::
- :::::\_____/___ /_ /__| \_ /___ /:::::
- `--[RD10/CodX]¼\/--\/--¼ª____\\/---¼\/---'
- QUARTER BACK TOOLS DIAMOND
- SUPPORTS AFS FILE SYSTEM, XPK PARTITIONS,
- REORGANIZES BETTER THEN REORG, AND USES A
- SAFETY DISK WHEN REORGANIZING! NO CRASH
-
-
-
-
- Greets
-
- Flake/TRSi
-
-
-
-
-
- Entry...............: COP-Trojan
- Alias(es)...........: Quarterback3 Trojan, ORS-QB3.lha trojan
- Virus Strain........: -
- Virus detected when.: 9/95
- where.: Denmark
- Classification......: Trojan, memoryresident, not resetresident
- Length of Virus.....: 1. Length on storage medium: 227716 Bytes (unpacked)
- 2. Length in RAM: 227716 Bytes
- - redundant hunkdata
- --------------------- Preconditions ------------------------------------
-
- Operating System(s).: AMIGA-DOS
- Version/Release.....: 3.00 and above (V39+) (Some functions are supposed
- to work only on V40 ?)
- Computer model(s)...: all models/processors (MC68000-MC68060)
-
- --------------------- Attributes ---------------------------------------
-
- Easy Identification.: Filelength
-
- Type of infection...: Overwriting all files in the destination directories
-
- Infection Trigger...: none
-
- Storage media affected: all DOS-devices
-
- Interrupts hooked...: None
-
- Damage..............: Permanent damage:
-
- Overwriting files in ENV, SYS, LIBS,NCOMM and S
- with a 75 bytes long text containing the following
- information:
-
- "=CIRCLE OF POWER= [ WE ARE BACK! THE RETURN "
- "OF THE POWER PEOPLE! / GRYZOR ]"
-
-
-
- Damage Trigger......: Permanent damage:
- - Start of programm
- Transient damage:
- - Start of programm
-
- Particularities.....: The trojans uses the DosList to get access to
- the various directories and then starts to
- damage the information in this files. The code
- uses some Kickstart 3.x functions and is so
- not working on older systems. Some failure-
- recognition routines were build in (in
- comparison to older COP trojans).
-
- Normal behavior blockers are able to stop
- this trojans. No tunneling techniques are used
- for this little bastard.
-
-
-
- Similarities: A lot of the routines are comparable to older
- COP trojans found in various wide spread
- utilities. Some codes are optimized, but still
- the old style is recognizeable.
-
-
- Stealth.............: None
-
-
- Armouring...........: Important parts are crypted using a logical
- loop, which is breakable by a normal code
- simulator.
-
-
- --------------------- Agents -------------------------------------------
-
- Countermeasures.....: none
- Countermeasures successful: All of the above
- Standard means......: -
-
- --------------------- Acknowledgement ----------------------------------
-
- Location............: Hannover, Germany 16.9.1995.
- Classification by...: Markus Schmall
- Documentation by....: Markus Schmall
- Date................: September,16. 1995
- Information Source..: Reverse engineering of original trojan
- Copyright...........: Markus Schmall
- Special.............: No use of this analyse except VTC Uni Hamburg
- in their CMBase releases
-
- ===================== End of Quarterback3 COP Trojan ============================
-