Virus Database


Macro.Word97.Aleja

Description Macro.Word97.Aleja

The virus contains six macros: AutoClose, AutoOpen, ArchivoGuardar, ArchivoGuardarComo, ArchivoImprimir, ArchivoImprimirPredeter.
The virus spreads on opening, saving documents or saving them with new name. To hide its code the virus disables the ToolsMacro menu. It also turns off the VirusProtection option.
Before document printing, the virus replaces primary header with the text:
Documento infectado con el virus ALEJA5

Check other viruses! Be aware! Use Antiviral Software

Line.908

Description Line.908

It is not a dangerous memory resident parasitic virus. It hooks INT 9 (keyboard), 21h and writes itself to the end of COM files (except COMMAND.COM) that are executed. Depending on its internal counter (after 3000+ characters that entered from keyboard) it resets INT 9, hooks INT 1Ch and manifests itself with a blinking (on fast PCs) or moving (on old PCs) screen line.

Linux.Bliss.a

Description Linux.Bliss.a

This is nonmemory resident parasitic virus written in GNU C. It infects Linux OS only - infected files may be executed, and the virus may spread itself only under Linux. The virus searches for executable Linux files (ELF internal format) and infect them. While infecting, the virus shifts the file body down, write itself to the beginning of the file and append to the end of file the ID-text:
infected by bliss: 00010002:000045e4
It seems that the former hex number in these lines is a virus version, and the latter is the virus length - the virus lengths are 17892 and 18604 bytes.
When an infected file is run, the virus searches for not more than three non-infected files and infects them. If there are not any infected files in the current directory, the virus scans the system and infects the files in other directories. After infecting, the viruses return control to the host program, and it will work correctly.
Linux is an access-protected system; i.e., users and programs may access only files that they have permission to. The same goes for a virus - it may infect only the files and directories that are declared as "write-able" for the current username. If the current username has total access (system administrator), the virus will infect all the files on the computer.
The virus seems to be "under debugging," and while searching for files and infecting them, the virus displays several messages:
already infected
skipping, infected with same virus or a different type
replacing an older version
replacing ourselves with a newer version
infecting: bytes
infect() returning success
been to already!
traversing
our size is
copy() returning success
copy() returning failure
disinfecting:
not infected
couldn't malloc bytes, skipping
couldn't read() all bytes
read bytes
happy_commit() failed, skipping
couldn't write() all bytes, hope you had backups!
successfully (i hope) disinfected
Debugging is ON
Disinfecting filesall
using infection log:
The virus also contains the text strings:
dedicated to rkd
/tmp/.bliss
asmlinkage int sys_umask(int mask)
mask&023000 return if(mask&023000) {{current->uid = current->euid =
current->suid = current->fsuid = 0; return old&023000} } bliss.%s.%d -l
rsh%s%s %s 'cat>%s;chmod 777 %s;%s;rm -f %s' doing popen("%s" /.rhosts r
%s %s .rhosts: %s, %s localhost doing do_worm_stuff() /etc/hosts.equiv
hosts.equiv: %s HOME --bliss- uninfect-files-please disinfect-files-please
version %d.%d.%d (%.8x)
Compiled on Sep 28 1996 at 22:24:03
Written by electric eel.
dont-run-original
just-run-bliss
dont-run-virus
dont-run-bliss
just-run-original
exec
infect-file unsupported version
help help? hah! read the source!
/proc/loadavg %d.
loadav is %d
bliss was run %d sex ago, rep_wait=%d
/tmp/.bliss-tmp.%d execv /bin
PATH : /usr/spool/news /var/spool/news wow

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Teletyre Ab
Jk:s I VÄsterÅs Ab
Gripenbergs FotvÅrd
Bms Gruppen Ab
N G Entreprenad

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com