===============================================================================
As this *is* a replicating virus, it is recommended you use extreme caution
when dealing with it. The author frowns upon intentional misuse of this virus
as it was written for *educational* purposes only! Any other use is prohibited!
===============================================================================
Warning: This virus does contain some code which can result in data loss when
triggered. It is not advised to play around with this virus.

Virus Author.: Raid - [SLAM] June 2000
Virus Name  .: IRoK v1.1c [CoreEngine Fix Release]
Virus Target.: EXE and COM infection.
Virus Size...: 7,840 bytes in length.
Target OS....: DOS - Win3x - Win9x - WinNT - Os2Warp*
               W2k based operating systems have not been tested for
               compatability. This virus may or may not function
               on those operating systems.
Encryption...: Yes - AntiAv v1.07 [Modified]
Payload......: Yes. Time triggered. May cause data loss when triggered.
AntiAV.......: Yes. Vsafe/Vshield & Norton v4/v5 resident blocker disable.
Stealth......: Yes. The infected executable will not be aware of the virus.
Sleep........: Yes. Between 3pm to 5pm*
Worm Ability.: Yes. OutLook And Mirc supported. Irok takes advantage of
               the windows scripting host to handle most of the outlook
               support. Implementing this turned out to be too easy. ;p
===============================================================================
As this *is* a replicating virus, it is recommended you use extreme caution
when dealing with it. The author frowns upon intentional misuse of this virus
as it was written for *educational* purposes only! Any other use is prohibited!
===============================================================================

Please view the file included with this archive named 'Warning.you' for more
information regarding an anti-viral product you'd be better off avoiding.

DISCLAIMER:
THE AUTHOR ASSUMES NO LIABILITY WHATSOEVER FOR ANY USE AND/OR MISUSE
RESULTING FROM THIS DOCUMENTATION AND/OR ANY BINARIES INCLUDED.

IRoK's engine has a 'Safe Infect' feature. Which means, until a file has
become infected, IRoK's payloads are off, and it is restricted to current
directory only. Only when IRoK is executed from an infected file are
the payloads and other spreading systems online. This allows you to safely
study IRoK, infecting executables without any risk to yourself. Of course,
this feature was only added for EDUCATIONAL PURPOSES! The author is not
suggesting in any way shape or form, nor was this routine written to break
any laws or suggest to do so in any way shape or form.

This virus does employ worm support if the infected user makes use of the
mIRC client and has it installed in the default directory.  If these
conditions are met, IRoK will create a new script.ini file (overwriting any
previous ones the user may already have) with instructions to initiate a
DCC send with anyone who joins a channel the infected user is in. After
writing a new script.ini file, irok will create an executable of itself
named irok.exe which is used by the script for dcc sending the virus as
a worm. The executable created is modified to engage screen saving when
launched, So as to hide it's infectious intentions from the user.

Irok will also attempt to send a message to 65 users listed in the
infected users addressbook if they are an OutLook user. This letter tells
them that Irok is a screen saver taken from paramount pictures website.
The infected user will not be aware of the fact that he is sending out
emails to some of his/her friends and business contacts. The vbs file
responsible for this is only created once by irok, and does self destruct
leaving no evidence behind.

To make disinfection difficult and annoying, This virus employs
AntiAVFuCK (tm) encryption (c) 1998 [Raid slam]. This encryption
technique does pose a risk to your executables. Infected executables
must be handled with caution and properly to prevent date/time stamp
changes, which WILL result in corruption of the file when it is later
executed.

The Outlook support present in this version of Irok is due mostly because
of a generous virus author by the name of Jackie from Metaphase. He allowed
me to borrow the modified section of code that irok uses for outlook
communication. Thanks once again Jackie!

This virus will take advantage of an SVGA card if the user has one present
in his/her system. The effect is similiar to a first person side view
of something (you) flying in space. Depending on your system speed, the
image might fly by too fast to view it, lucky you. Pressing enter while
the screen saver is running will exit it.

IRoK does have built in working sleep routines. However in response to a
certain person who shall remain nameless, They do have the ability to bring
the entire virus back online on a moments Notice. Do you feel like some
russian roulette tonight?

Various lyrics used in the IRoK virus are from assorted Tool and Nirvana
songs which I felt were appropriate for this virus design.

Finally, IRoK does employ some routines which might cause data loss when and
if they should trigger. You may wish to consider backing up your system
before experimenting with this virus. Should something go wrong, you could
wind up losing everything.

- This release is functionally identical to version 1.1a, except it contains
a bug fix. Yes that's right, a fix for a glitch in the previous version.
This glitch did not show up right away during initial testing. But after
examining some antivirus websites and then doing a bit of experimentation
I discovered the virus did not pass the command line properly! :( This was
due to a serious programming error on my part, which I have since corrected.

- This release is what release v1.1b was supposed to do. However, due to
  some pisspoor beta-testing on my part, It had some issues.
  This release shouldn't cause anymore "this program has generated an
  illegal function call" error window on win98 based systems. Other then
  some bug fixes and encryption changeouts, Nothing else has been changed.
  A later release may follow which does some new and interesting things.
  Treat this sample as a working-bug fix. Or an "upgrade" :)


There are plans in the future to incorporate the "Call home" technology which
is still under development.

