Linux.Gildo
Description Linux.Gildo
It is not a dangerous, memory resident parasitic virus. It was written in the assembler language. It uses system calls (syscall) while working with files. The virus infects ELF files. It writes itself to the middle of the file. After starts the virus divides a main process and continues its work. The resident part scans the directories from the root. The virus checks the access right for each found file. If file has a write access the virus will infect it. While infecting file the virus increases its code section size on 4096 bytes and writes its code to the free space. After that the virus changes parameters for the ELF file upper sections and setups a new Entry point for it. The virus displays the message on each start: Gildo virus email Gildo@jazz.hm (for comments) The virus contains the text strings: hello, nice boys, I hope you will enjoy this program written with nasm. I want to say thanks to all my programmers friend.Bye from Gildo. The Netwide Assembler 0.98 .symtab .strtab .shstrtab .text .data .sbss .bss .comment It also contains the debug strings from the compiler: virus.asm parent parent_process ahah scan_dir c_stat others_permissions user_permissions group_permissions c_permissions is_regular_file c1_is_regular_file c2_is_regular_file is_directory c1_is_directory l_readdir skip_l_readdir e_l_readdir error_stat error_opening_file e_scan_dir infect_file open no_open_error file_length mmap c_mmap is_suitable error_suitable c1_is_suitable read_ehdr c_ehdr is_suitable_space patch_ehdr patch_e_entry patch_e_sh_offset patch_phdrs l_read_ph dont_patch_phtext dont_patch_ph patch_shdrs l_read_sh dont_patch_shtext dont_patch_sh find_current_entry_point write suit_error munmap mmap_error close open_error __exit __bss_start main _edata _end
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Sveta
Description Macro.Word.Sveta
This virus contains two macros: AutoOpen, Sveta. It replicates on opening infected documents (AutoOpen): it searches for documents in FileList (recently used files list) and infects them. So the virus is "nonmemory resident" - it is active only when infected document is being opened, and AutoOpen macro takes control. When it releases control, the virus does not intercept any events and does not infect files (if, of course, NORMAL.DOT or some another auto-loaded template is not listed in FileList). On activating at 13 seconds (i.e. on opening an infected document) the virus displays to the StatusBar the message: ----------======> SVETA by Kid Chaos [SLAM] <=======----------
Macro.Word.Switcher
Description Macro.Word.Switcher
This is an encrypted stealth Word macro virus. It contains ten macros: AutoExec, AutoOpen, AutoClose, FileClose, FileOpen, FileSave, FileSaveAs, FilePrint, FileTemplates, ToolsMacro. The virus infects the global macros area (NORMAL.DOT) on opening an infected document, saving it, saving with new name, closing, printing and entering Tools/Macro menu. Documents get infection when they are saved, saved with new name or closed. The infection routine is placed in FileClose macro, other macros call that macro to run infection. On closing a document if the seconds are less than 10, the virus replaces one random digit in current document. On entering Tools/Macro and File/Templates menus the virus displays the MessageBox: Configuration conflict - menu item is not available.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Properties Sale Turkey Flowers Gotogate Potenzmittel Arab Emirates Dating
|