home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Hacker
/
Hacker.iso
/
HACKER
/
ANTIVIR
/
k_grief
/
K_GRIEF.DOC
< prev
next >
Wrap
Text File
|
1997-05-03
|
3KB
|
89 lines
K-Grief
----------------------------------------------------------------------------
(C)opyright 1992-97 by:
-----------------------
ALL RIGHTS RESERVED!
┌────────────────────────────────┐
│ ROSE Softwareentwicklung │█
│ Dipl.-Ing. (FH) Ralph Roth │█
│ Finkenweg 24 │█
│ │█
│ D 78658 Zimmern o. R. │█
│ │█
│ FAX/AB: +49.741-32647 │█
└────────────────────────────────┘█
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
EMail: Ralph_Roth@p2.f2101.n246.z2.fidonet.org
Fido: 2:246/2101.2, 2:2480/8849.6 (Virus Help Munich)
Tips for removing the Grief virus:
----------------------------------------------------------------------------
1.) Boot from a virus free disc!
2.) Run K_Grief c: -r to clean your drive c:
3.) Boot from HDD. Work for a few hours.
4.) Repeat steps 1-3 to ensure that the virus is gone.
5.) Scan all your disc with k_Grief a:
Hint: This cleaner can handle and remove multiple infections.
----------------------------------------------------------------------------
German description: See GRIEF.DOC
----------------------------------------------------------------------------
There are 2 variants of this virus:
- Standard version (GRIEF.3584.Standard)
- Lucky (GRIEF.3584.Lucky)
The other scanners meanwhile detect this virus family as
Nostradamus.3584...
The cleaner detects both variants and cleans both variants (they
use different encryption keys!).
This virus uses the EMME (Eternal Maverick Multilevel Encryptor)
v3.0. Polymorphic (from 1 up to 4 levels of encryption) resident
COM, EXE & OV? infector. Does not decrease memory size and is
not detectable by heuristic analysers (like WEB,F-PROT & TBAV).
Does not destroy overlayed EXE, does not conflict with CHKDSK and
residents, can not be cured with TBCLEAN. Many resident virus
traps (like ANTIAPE.SYS). Blockers are not able to intercept its
attempt to stay resident (if it is possible it uses UMB, if not -
waits for program termination and then allocates about 2700 bytes
in low memory). It uses an original technique to find DOS INT 21h
handler. It is a true stealth virus. Uses anti-debugging tricks,
disables stealth when archivators are executed. It destroys Adinf
tables when executed first time. Formats your harddisc if the
following condition is true:
(day of week + 1) * 2 == weekday
E.g. Sat. 14 Dec. 96 (6+1)*2 == 14
General:
----------------------------------------------------------------------------
K_GRIEF uses a small part of the decryption engine from VSP (I was
_too_ lazy to write a standalone encryption engine :) - Therefore
K_Grief will find at least the following viruses using a polymorph
mutation engine (ME):
EMME 3.0 (Grief)
BWME (Biolocial Warfare ME)
RME (Rajaat's ME)
MIME
VME
SVL (Slovakia)
As well as the "Live Bait Test" will catch allmost every resident
virus. But this are only benefical side-effects.... :-)
(C) by ROSE, Ralph Roth