IStrip 2.1 BBS Trojan:
 ----------------------

 Filelength 1156 Bytes (unpacked)
 Filename: Istrip/S/Istrip.bin

 This is a classical BBS trojan, which tries to read the user.data
 file from AmiExpress systems and write it into the uploaddirectorie
 under the name: eatme.lha. This way of hacking boards was performed
 by Zonder Kommando some months ago. The code looks quite good and
 the programmer of this shit is no beginner in assembly-language.

 File_ID.Diz:

 ---- - -- - -- --- - --- ----- - --- - -- -
        TAS / MEDELLiN UK PRESENTS
 ---- - -- - -- --- - --- ----- - --- - -- -
 --> ISTRIP 2.1 beta LhA turbo stripper! <--
 --> There is no other stripper! Doesn't <--
 --> use LhA for stripping, custom 680x0 <--
 --> code! - Can kill #?#? & *.* banners <--
 --> As well as delete protected files + <--
 --> Ansi Analyzing improved with 60 %   <--
 -->                                     <--
 -->    WORLD BEST/FASTEST STRIPPER!     <--
 ------[..SSF..]-dANCE-wITH-mE-[..5D..]-----

 I think it exists a real IStrip and someone just resourced it and
 put a new routine additional in it. VirusWorkshop only recognizes
 the virus itself, not the loader.


 Test by Markus Schmall                 Detection tested 17.1.1995.

[Go back]