Virus Database


Spanska.1000

Description Spanska.1000

These are not dangerous nonmemory resident encrypted parasitic viruses. They search for .COM files except COMMAND.COM, then write themselves to the end of the file. "Spanska.1500" affects both .COM and EXE files. Depending on the system time they display the texts:
"Spanska.1000,1008":
Remember those who died for Madrid
No Pasaran! Virus v2 by Spanska 1997

"Spanska.1120.a":
Remember those who died for Madrid
No Pasaran! Virus (c) Spanska 1996

"Spanska.1120.b":
To Carl Sagan, poet and scientist,this little Cosmos.
(Spanska 97)

"Spanska.1500,1509":
Mars Land, by Spanska(coding a virus can be creative)

"Spanska.1500,1509" also manifest themselves by a video effect.

Check other viruses! Be aware! Use Antiviral Software

Linux.Diesel

Description Linux.Diesel

This is a relatively harmless, non-memory resident parasitic virus. It searches for Linux executable files in system directories and subdirectories, then writes itself to the middle of the file. Before searching files, the virus reads its code from the host file. It moves the original bytes to the end of the file and increases the size of the previous section.
File before infecting File after infecting:

--------------- ---------------
? Header ? ? Header ?
+-------------+ +-------------+
? ? ? ?
? ? ? ?
? ? ? ?
+-------------+<- Entry point +-------------+<- Entry point
?Program code ? ? Virus code ?
+-------------+ +-------------+
? ? ? ?
? ? ? ?
L-------------- +-------------+
?Program code ?
L--------------

After finishing its work, the virus restores the host and transfers control to it. The virus contains the text string:
/ home root sbin bin opt
[ Diesel : Oil, Heavy Petroleum Fraction Used In Diesel Engines ]

Linux.Gildo

Description Linux.Gildo

It is not a dangerous, memory resident parasitic virus. It was written in the assembler language. It uses system calls (syscall) while working with files. The virus infects ELF files. It writes itself to the middle of the file.
After starts the virus divides a main process and continues its work. The resident part scans the directories from the root. The virus checks the access right for each found file. If file has a write access the virus will infect it. While infecting file the virus increases its code section size on 4096 bytes and writes its code to the free space. After that the virus changes parameters for the ELF file upper sections and setups a new Entry point for it. The virus displays the message on each start:
Gildo virus
email Gildo@jazz.hm (for comments)
The virus contains the text strings:
hello, nice boys, I hope you will enjoy this program written with nasm. I want to say thanks to all my programmers friend.Bye from Gildo. The Netwide Assembler 0.98 .symtab .strtab .shstrtab .text .data .sbss .bss .comment
It also contains the debug strings from the compiler:
virus.asm parent parent_process ahah scan_dir c_stat others_permissions user_permissions group_permissions c_permissions is_regular_file c1_is_regular_file c2_is_regular_file is_directory c1_is_directory l_readdir skip_l_readdir e_l_readdir error_stat error_opening_file e_scan_dir infect_file open no_open_error file_length mmap c_mmap is_suitable error_suitable c1_is_suitable read_ehdr c_ehdr is_suitable_space patch_ehdr patch_e_entry patch_e_sh_offset patch_phdrs l_read_ph dont_patch_phtext dont_patch_ph patch_shdrs l_read_sh dont_patch_shtext dont_patch_sh find_current_entry_point write suit_error munmap mmap_error close open_error __exit __bss_start main _edata _end

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Thai Recipes
Crockpot Recipe
Colocation

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com