Virus Database


HelloUser Family

Description HelloUser Family

These are benign non-memory resident parasitic encrypted viruses. They search for .COM files, and write themselves to the end of the file. If the date and month correspond in number (1st of January, 2nd of February,all) the viruses display:
"HelloUser.365":
Hello User,You have got The HEXAMETRICX Virus !!!

"HelloUser.545.a,547":
Hello User,You have got The HEXAMETRICX Virus !!!
T o d a y is the month's B i r t h d a y !
I was written in the City of Langen(Hessen),Germany
by SuIgImErIuS (¢)1993 v.1.3
GREETINGS TO ALL OTHER VIRUS WRITERS !

"HelloUser.545.b":
Hello User, You have The Boehse Onkelz Virus 1.5!
I was written in Eastgermany in Sept. 1993 !
If you're an Onkelz Fan, call the following number!
Germany (0049): 069/445052 !
Wir ham' noch lange nicht genug...!!!

"HelloUser.550":
Hello User,You have got The Ebbelwoi Virus !!!
T o d a y is the month's B i r t h d a y !
I was written in the City of Langen, Germany, MRMS
by SuIgImErIuS (¢)1993 v.1.3
GREETINGS TO ALL OTHER VIRUS WRITERS !

"HelloUser.554":
Hello User,You have got The Friendly Virus !!!
T o d a y is the month's B i r t h d a y !
I was written in the City of Langen, Germany, MRMS
by SuIgImErIuS (¢)1993 v.1.3
GREETINGS TO ALL OTHER VIRUS WRITERS !

Check other viruses! Be aware! Use Antiviral Software

Linux.Kagob.a

Description Linux.Kagob.a

It is a harmless nonmemory resident parasitic Linux virus. The virus itself is Linux executable module (ELF file). It searches for other ELF files in the system, then infects them.
While infecting the virus moved victim file contents down, and writes itself to file header. To release control to the host file the virus "disinfects" it to a temporary file and executes it.
The virus does not manifest itself in any way. It body contains the "copyright" text string:
Linux.Kaiowas by Gobleen Warrior//SMF

Linux.Nuxbee.1403

Description Linux.Nuxbee.1403

This is a relatively harmless, non-memory resident parasitic Linux virus. It searches for ELF files in the directory bin, then writes itself to the middle of the file. The virus infects files if the current user has administrator rights. It writes itself to the Entry point offset, encrypts and saves original bytes at the end of a file.
Before infecting: After infecting:

ÚÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ¿ ÚÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ¿
³ ELF Headers ³ÄÄ¿ ³ ELF Headers ³ÄÄ¿
³ ³ ³ ³ ³ ³
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā ³ ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā ³
³ Section 1 ³<ÄÙ Entry ³ Virus ³<ÄÙ Entry
³ ³ point ³ ³ point
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā
³ Section 2 ³ ³ Section 2 ³
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā
. . . . . .
ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā
³ Section n ³ ³ Section n ³
ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÙ ÃÄÄÄÄÄÄÄÄÄÄÄÄÄÄā
³ EP data ³ Encrypted data
³ ³
ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÙ

To restore an original file, the virus reads and encrypts the original bytes from the host file. It uses file mapping functions to infect files. All system functions are summoned by INT 80h (Sys call). The virus contains the following text string:
NuxBee by Bumblebee - The NeXt Frontier

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com