Virus Database


Nucleii.1388

Description Nucleii.1388

This is a benign non-memory resident encrypted parasitic virus. It searches for COM files, then writes itself to the end of the file. On the 30th of any month, the virus displays the following messages:
+------------------------- F-PROT anti-anti-virus program------------------+
| Version 1.0 nUcLeii Software International |
+--------------------------------------------------------------------------+
Scan +------------------------------------------+
| Too bad your now infected with the frisk |
| virus. Sorry.,.hehe., but thats the way |
Options | shit works. If you weren't stealing soft |
| ware, or trying to get p0rn or something,|
| then this might not of happened. |
Infomation | Don't buy products that harass their user|
| Stay away from things like McAfee, Norton|
| Invircible, err well,.hehe., seems like |
Quit | everyone is selling out these days.,,. |
| |
| Greetings to fridrik and frisk software. |
+------------------------------------------+
+--------------------------------------------------------------------------+
|Information about antivirus scanners, and how most are just crap not worth|
|wasting your money on. Hope this is "nit-witty" enough for ya fridrik!!! |
+--------------------------------------------------------------------------+

The virus also contains the "copyright" text:
** frisk by nUcLeii 9/09/98

Check other viruses! Be aware! Use Antiviral Software

Linux.Gildo

Description Linux.Gildo

It is not a dangerous, memory resident parasitic virus. It was written in the assembler language. It uses system calls (syscall) while working with files. The virus infects ELF files. It writes itself to the middle of the file.
After starts the virus divides a main process and continues its work. The resident part scans the directories from the root. The virus checks the access right for each found file. If file has a write access the virus will infect it. While infecting file the virus increases its code section size on 4096 bytes and writes its code to the free space. After that the virus changes parameters for the ELF file upper sections and setups a new Entry point for it. The virus displays the message on each start:
Gildo virus
email Gildo@jazz.hm (for comments)
The virus contains the text strings:
hello, nice boys, I hope you will enjoy this program written with nasm. I want to say thanks to all my programmers friend.Bye from Gildo. The Netwide Assembler 0.98 .symtab .strtab .shstrtab .text .data .sbss .bss .comment
It also contains the debug strings from the compiler:
virus.asm parent parent_process ahah scan_dir c_stat others_permissions user_permissions group_permissions c_permissions is_regular_file c1_is_regular_file c2_is_regular_file is_directory c1_is_directory l_readdir skip_l_readdir e_l_readdir error_stat error_opening_file e_scan_dir infect_file open no_open_error file_length mmap c_mmap is_suitable error_suitable c1_is_suitable read_ehdr c_ehdr is_suitable_space patch_ehdr patch_e_entry patch_e_sh_offset patch_phdrs l_read_ph dont_patch_phtext dont_patch_ph patch_shdrs l_read_sh dont_patch_shtext dont_patch_sh find_current_entry_point write suit_error munmap mmap_error close open_error __exit __bss_start main _edata _end

Linux.Kagob.a

Description Linux.Kagob.a

It is a harmless nonmemory resident parasitic Linux virus. The virus itself is Linux executable module (ELF file). It searches for other ELF files in the system, then infects them.
While infecting the virus moved victim file contents down, and writes itself to file header. To release control to the host file the virus "disinfects" it to a temporary file and executes it.
The virus does not manifest itself in any way. It body contains the "copyright" text string:
Linux.Kaiowas by Gobleen Warrior//SMF

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Italy India Calling
Payday Loan Online
Top-designer Carports
Palau Phone Cards
Hawaii Auto Loan

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com