CopKiller v1.1 - Made By Bo Jolle, Safe Hex International Denmark :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: The ultimate killer for the Circle Of Power viruses :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: Since i havn't seen any C.O.P. killers for their new cryptation of their trojans (used f.ex in the file 'BMPD.EXE' which claims to be a bitmapped Intro) i decided to code one that finds both old and new C.O.P. Files. What it actually does is that it patches the read command. And Takes a checksum of the first 512 bytes before it's allowed to be executed, if CopKiller thinks it's a trojan it will pop a requester asking you if you want to run the file anyway (usually the answer should be NO). Since the C.O.P. viruses destroy their files by opening them as 'mode newfile' this killer will also recognize future crypting methods by the C.O.P. people, simply by checking if more than five 'mode newfiles' have been opened in less than 2 seconds. Unfortunaly you will loose the first five files. But after that the program opening the 'mode newfiles' will be frozen and a requester will pop up and warn you of possible directory trashing. You can click on the 'Remove task' button (Will kill the task that opened the files) or you can click on the 'No worries' (If you ACTUALLY have a program that you KNOW is supposed to open newfiles in that high rate (not at all many does) INSTALLATION Simply copy the file COPKILLER to your c: dir and add this line to the end of your s:startup-sequence C:CopKiller The program will work in the background with minimum CPU Time usage Since it's only called when a file is opened. p.s. A Message to the members of C.O.P. by disassembling your trojans i've noticed that you have high coding skills why don't you use your skills to help people out by coding Virus killers or something else usefull instead of pissing people off?? Jolle / SHI