Stasi.1728
Description Stasi.1728
It is a very dangerous nonmemory resident parasitic polymorphic virus. It searches for EXE files and writes itself to the end of the file. The virus contains the lists of the file names. The first list is: (.ID ANTI-VIR.DAT C:TBAVVIRSCAN.DAT CHKLIST.CPS C:CPAVCHKLIST.CPS C:NAV_._NO C:NOVIRCVR.CTS C:NOVIPERF.DAT C:TOOLKITFILES.LST C:FSIZES.QCV C:UNTOUCHUT.UT1 C:UNTOUCHUT.UT2 C:VS.VS
and the virus deletes these files when they are executed. The virus does not infect the file if the file name contains the string from the second list: F- FLU SCAN CLEAN TB TNT VIR
Sometimes this virus displays one of the messages: Erich Mielke is still alive! Watch out for Stasi spys! Ever heard of Markus Wolf? Stasi is watching you!
The virus writes to the Boot sectors the command that halts the computer while booting. The virus also contains the text string: Stasi is watching you! Nice programming, eh? The Stasi virus is written by the author of Vriest, 789 (aka Filehider) and Witcode. Black Axis
Check other viruses! Be aware! Use Antiviral Software
IRC-Worm.Mabra.a
Description IRC-Worm.Mabra.a
This is a silly IRC worm that spreads through IRC channels using mIRC client for spreading. The worm appears on a computer as the DOS EXE file with MABRA.EXE, CDMAN.EXE, or GLADYS.EXE filename (depending on the worm's version), and about 14K in file size. When this file is executed by a user, the worm copies itself into C:WINDOWS, C:WINDOWSSYSTEM or C:WINDOWSSYSTEM32 directory (depending on worm version), and overwrites the mIRC script file SCRIPT.INI in the C:MIRC directory. The new script sends the worm copy to any user that enters an infected channel. Depending on the system time, the worm erases the C:WINDOWSWIN.COM file.
IRC-Worm.Milbug.a
Description IRC-Worm.Milbug.a
This is an IRC virus-worm that spreads itself via mIRC channels. It appears as a MILBUG_A.EXE or MILBUG_B.EXE DOS EXE file about 10Kb in length. The file name depends on the worm version. When the worm file is executed, it overwrites the SCRIPT.INI file in the C:MIRC directory with its own script program that has just two instructions. The first one sends the following message to any new user in the channel: I'm testing my millenium bug fix program. Receive it and test it
The second one sends the MILBUG EXE file to this user. The worm does not have any dangerous payload and does not manifest itself in any other way.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Saltvikens GÅrd RÅnnemÅla Änglaskog Aa Andegar Beck StÄdservice I GÖteborg Ab Benema Ab
|