View Single Post
  #2  
Old 04-27-2005, 19:59
bgrimm bgrimm is offline
Friend
 
Join Date: Jan 2004
Location: South of The North Pole
Posts: 66
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 3 Times in 3 Posts
bgrimm Reputation: 0
Don't quote me on this, as I'm not to familiar with the 9x VX scene.

But it is my understanding the HPS virus used an undocumented int21 routine to access Kernel32.dll, then from there you can find VxDCall.

An overview of how it is done is located here:
h**p://vx.netlux.org/lib/vgy06.html

An analysis of the HPS virus is here:
h**p://www.peterszor.com/hps.pdf


-bg
Reply With Quote