Translated text from VT-Knows by Heiner Schneegold
     --------------------------------------------------


   - SnoopDos-Saddam-Virus  File   Length: 13776 Bytes
          A Trojan Horse
          Saddam-Clone removed: 11568 Bytes
          Using Hunklab a Saddam-Clone-4711 is linked to SnoopDos.
          I can't decide wether the SnoopDos V2.1 is real, but I don't
          think so - it's the same length as V1.9. I don't know of a
          version 2.1 (Aug.93). Possibly someone has changed the version
          number. SnoopDos is clean.
           4e752456 45523a20 536e6f6f 70446f73 Nu$VER: SnoopDos
           20322e31 20283232 2e30372e 39332900  2.1 (22.07.93).
          Reactions:
          SnoopDos V2.1 never showed up on the monitor when infected.
          KS2.04:
          The file gives a GURU 3 and memory is clean after a reset.
          KS1.3:
          The file loads. Snoop-Dos V2.1 never showed on-screen.
          If you write it shows on-screen, but nothing else happens.
          AND NO THE BAD PART
          After a reset the SADDAM-Disk-Validator works in RAM (remember
          that SADDAM has a Cold-Reboot-Routine that works with FastMem
          too). The Kreset-Prg in VT-Schutz sub-dir do help against this
          too.



      Translated by Torben Danoe

[Go back]