TIP: Click on subject to list as thread! ANSI
echo: virus_info
to: DAVID KIRSCHBAUM
from: KURT WISMER
date: 1997-05-07 18:49:00
subject: 486to586

 -=> Mocking David Kirschbaum to All <=-
   
 DK> Has anyone disassembled this bogus utility?  (It purports 
 DK> to somehow magically change your system so your 486 now 
 DK> runs as well as a 586 .. and the most recent versions say 
 DK> it'll run like a Pentium.)
i downloaded this program a couple years ago, tbav actually picked it up
as a trojan... unfortunately i can't find any information on it
anymore...
 DK> It's encrypted (several layers), of course.  I worked through the
 DK> decryption  in DEBUG, saved a chunk of the "clear-text" (if you can use
 DK> that phrase for a binary program) out .. and it looks like 
 DK> the original program was programmed in C.  So the 
 DK> disassembly is gonna be ugly.
depends on the tool you use... i hear there's a new feature for ida,
something about a library recognition system... it's supposed to make
disassembly of hll programs easier from what i gather...
... ow that you know that i know that you know that i kn...
--- Maximus 2.02
---------------
* Origin: Virus Watch BBS ,[(416)654-3814] (1:250/503)

SOURCE: echomail via exec-pc

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.