  		   ]------issue #3 1 of 2 -------[




				.ed"""" """NoMecy.
                              -"           ^""**NoMe.
                            ."                   'NoMc
                           /                      "4Nob
                          d  3                      NoMe
                          N  *                   .NoMerc
                         .N  ^c           NoMercyVirusTe.
                         dNL  4.         4NoMercyVirusTeb
                         NoMer ^cyVirus  4NoMercyVirusTea
             eN""=.      NoMer dNoMer N NoMercyVir sTeaMN
            zNoM. ^c      NoMe "NoMer   NoMercyVi  NoMer"      .=""No
             4NoMer        NoP"  "NNb   .NoMercyV...eNo      .=eNoM.
           ^*NoMerc  %..   *c    ..    No 3NoMercyVirus     zPdNoMer
             "**NoMer   "   %ce""    NoM  NoMercyVir*    .r"=NoMer""
                   "*No.  "c  *Ne.    *** dNoMer"LNo    .d"eNo***"
                     ^*NoM ^No NoM      4JNoMer% NoM .e*".eNoM"
                        "NoMerc"'N=e....N*No**NoMer" "..dN*"
                          "*NoM  *=%4.NoMerC NoMecy NoMr"
                             "N   "%*ebJLzbNoMercyb NP"
                               %..      4NoMercyVir "
                                NoMe   zNoMercyVir%
                                "*Nc  "NoMercyV"
                                  ."""*NoMercyVir
                               .-"    .N***NoM"""*e.
                            .-"    .eN"     "*Nc  ^*b.
                     .=*""""    .eN*"          "*bc  "*Ne..
                   .N"        .z*"               ^*Ne.   "*****e.
                  NoMerc   .d"                     "*N.        3.
                   ^*NE")N..N"                         *   .ee==d%
                      N.dNoM*                           *  JNoMe*
                       """""             _                 "NoM"     


----------- issue III of NoMercyVirusTeam ----------------
1. Introduction
2. Greeting and thanks
3. What's New
4. REVIEW!
5. Archive from K-Elektronik


1. Introduction
----------------
	  Welcome to issue #3, this week many virus was produced
	for examples, Creed by RAiD, Prospero by Opic, and Macro
	viruses from ZeMakroKiller'98, soo becarefull may be one
	of them was landed on your PC. 
	  Keep wacthing!!

			]------------------------[

2. Greeting and thanks
-----------------------
   Greeting
	Opic		: send me more ok ;o)
	Crazyman	: keep reading
	SlageHammer	: finally the master down ;o)
	RAiD		: keep on good work
	Mikee		: still wait your mail ;o)
	Ice Man		: welcome to VX
	Aurodreph	: miss your mail brother
	SpoOky		: luv ya hehehehe
	serialkiller	: gimee your best shot, and lets infect
			  indonesia ;o)
	ZeMakrokiller	: send me again, i love it
	Mr.Vic		: still waiting your new virus

   Thanks
	K-Elektrinik	: well master of puppet was done!
	Mr.Vic + Slage	: for review
	My new girl	: support me honey! ;o)
	Serialkiller	: many thank!!!!!!!
	

			]------------------------[

3. What's New
-------------
	1. CREED, a multi OS infector done by RAiD of SLAM Virus
           Team. Take a look this
	   Virus Target: *.EXE / *.COM
	   Virus Size..: 5209 bytes.
	   Target OS...: DOS/Win3x/Win95/WinNT/Os2Warp
	   Virus Info..: Non-resident prepender. Limited stealth
			 /retro.
	   Encryption..: Variably Mutating on host data, AntiAVD
			 isinfection routine.
	   Payload.....: Infected file may commit suicide, random
			 short msgs.
	   Stealth.....: Host disinfection, exe/com masking. 
			 [Does not work on Virusafe]
	   Retro.......: VSAFE/VSHIELD disable/restore, Av sigs 
			 deleted, exe/com masking.
	   Special Info: This virus is the first of mine to exploit
			 Host control. This feature allows my virus 
			 to access files from where the host is
			 working, and to where the host is going.
		         Example: pkunzip c:\warez\3d1.exe c:\work\ 
			 would cause between one and eight exe/coms 
			 in \warez to be infected, and between one 
			 and eight exe/coms in \work to be infected 
			 after they are created.

	2. Prospero, a polymorph virus by opic of the COdeBreakers
	   with  kewl payload. take alook this
	   Polymorphic...: Yes, there is a stock of 3op encryption 
			   algorithms decryptors and delta offsets 
			   rutines from which the virus chooses to 
			   use in each infection. the rest are 
			   safely encrypted inside the virus body.
	   Antiheuristics: yes.
	   DirTransversal: DotDot method 
	   Rate of infect: no more then 7 per run
	   Payload 	 : The virus will manifest a payload on the
			   1st day of the month if the minutes are 
			   above 30. A large graphical color text 
			   effect as well as a message is delivered
			   from through printer.

	3. WM.MultiVirus, a macro virus from ZeMakroKiller
		Macros:			Actions:
		================================
		- PayBadBoy	-> contains the payload
		- PaySchoo	-> contains the payload
		- PayVeneno	-> contains the payload
		- AutoOpen	-> calls PaySchoo, infects normal.dot
				   file and if the normal.dot file is 
				   infected, the virus calls PayBadBoy
		- AutoExec	-> calls PayVeneno and infects normal
		- FilePrint	-> if the seconds are above 57, the 
				   virus appends some strings to the 
				   end of the document
		- FilePrintDefault -> the same as FilePrint
		- FileSaveAs	-> infects the document and save as 
				   template
		- FileTemplates	-> displays a message box
		- ToolsMacro	-> displays a message box
		- ViewVBCode	-> displays the assistant with a error
				   message
	
		The payload:	
		- PayBadBoy:  When infects a document, the virus
			      changes somes imformations in File
			      SummaryInfo.If the normal.dot file
			      is infected and the date = 1st or 
			      13th the virus displays many msg 
			      boxes and set the password of doc
			      to gangsta98 on openning the doc 
	   	- PaySchoo  : When infecting athe normal.dot file,
			      the virus adds autocorrection 
			      commands. Since 28 may 1998, the 
			      virus displays a message box If you
			      are the 28 may 1998, displays other 
			      msg box and after displays other 
			      message box again
	   	- PayVeneno : If the minutes are less 5 minutes, 
			      the virus inserts a strings in the
			      doc and replaces the strings "ste" 
			      with "stes" and sets the password 
			      to "Veneno98"
			      if the seconds are above than 57 
			      the appends strings to the end of 
			      the document when save the doc, if 
			      the seconds=38 then displays a msg 
			      box if random number = 50 then
			      overwrites the Autoexec.bat and 
			      config.sys

	4. WM97. Cryptor,  a macro virus from ZeMakroKiller
		Macros:			Actions:
		================================
		- AutoClose	-> contains the payload
		- AutoOpen	-> infects Normal.dot file
		- FileSaveAs	-> save as template
		- FileTemplates	-> displays a message box
		- ToolsMacro	-> displays a message box
		- ViewVBCode	-> displays a message box

		The Payload: 
		if the date is odd number then on closing doc,
                the virus displays a message in status bar and
		crypt the text of the doc and finally, displays
		a message in the status bar and save it When a 
		document is just infecting or normal.dot file, 
		the virus displays a message box.
	
			]------------------------[

                        ]---- continue to #2 ----[


