Virus Database


Bach.498

Description Bach.498

It's a dangerous not memory resident parasitic virus. It searches for .COM-files and writes itself at their ends. Depending on current date it hooks INT 13h and sometimes redirects information that are read or saved to disk. It contains the internal text string: "J.S. Bach by TXQ".

Check other viruses! Be aware! Use Antiviral Software

CS.Gala

Description CS.Gala

This is the first known virus to infect CorelDraw scripts. When this script is activated, it searches in the current folder for other CorelDraw scripts (*.CSC files), reads their data and gets names of the first infected and first non-infected scripts. Then it reads the virus code from the infected script and writes it to the beginning of victim non-infected script. The virus infects one script at a time, and after infection, it returns control to the original script commands.
While infecting, the virus uses the temporary file MALLORN.TMP: the virus renames the victim file to this name, creates its copy with a victim file name, and appends to it the original victim file code from a MALLORN.TMP file.
The virus manifests itself on June 6th - it displays the following message window:
GaLaDRieL ViRUS bY zAxOn/DDT
Ai! lauri" lantar lassi sêrinen!.
YLni ênãtime ve rmar aldaron,
yLni ve linte yuldar vnier
mi oromardi lisse-miruvãreva
Andêne pella Vardo tellumar
nu luini yassen tintilar i eleni
ãmaryo airetri-lirinen.
all.

The virus code also contains comments at the very beginning of the virus and at the very end of its code:
REM ViRUS GaLaDRieL FOR COREL SCRIPT bY zAxOn/DDT
REM END OF ViRUS GaLaDRieL bY zAxOn/DDT

The possibility of CorelDraw script infection is based on the fact that this application supports programs that are written in a script language that is very close to VisualBasic used in MS Office. The CorelDraw scripts, as well as scripts in other applications and macros in MS Office, are used to customize the application. The CorelDraw script language supports a set of instructions that is enough to copy one script code to another one, access disk files and as a result to create a virus.

Csf.240

Description Csf.240

It's a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of COM-files that are executed. It contains the internal text string: "csf".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Bisnis Online
Avskjed
EGCE AB
CHRISTERS MÅLERI AB
GÄLLIVARE INDUSTRISERVICE AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com