Virus Database


Vesna Family

Description Vesna Family

These are benign non-memory resident parasitic viruses. They search for *.COM, *.EXE, CH*.* and *.°°° files, then write themselves to the end of the file.
Vesna.1000
These viruses infect only .COM files. "Vesna.1000.a" runs itself with a video "noise." On Friday the 13th, it displays:
Friday 13th ?
Friday 13th all
Friday 13th !
Good bye !

"Vesna.1000.b" on the 22nd of June, this virus searches for EXE files and corrupts them.
These virus contains the text strings:
"Vesna.1000.a": AIDS
My name is GARRY
"Vesna.1000.b": *TULA*
*KILLER*

Vesna.1614 and 1700
These viruses check the file name, and do not infect the files with the names from the string (two bytes per name - VS*.*, DR*.*, and so on): "Vesna.1614": drwetbmsmvavaiscadutanatsdncvcdnwiioibvi "Vesna.1700": vsdrmswechaiioadscibutvranclavdowiatsdwsidvi "Vesna.1614" is the encrypted virus. It displays the messages:
éÑß¡á "_¿_½á!
Unpress key TURBO to continue...
Format drive c: completed
PRESS RESET TO CONTINUE
Å"_á "¿__ ¬"_Ñ!
çñÑß_ í_½ êú"__ ä.
æ½___, __... _¶óá¬... "Ñ_Ññá_ "_¿óÑ_ éÑñÑ¡ÑÑó"_ ï"_¿ßÑ!
VESNA (c) 1994,96 -=* Uni Tula *=-

In March, "Vesna.1700" displays a message, waits for a keystroke, and then reboots the computer:
Bad command or file name
DOS not support!
You have virus!
Press any key to reboot...

This virus also contains encrypted text strings:
*.exe *.com
ch*.* *.°°°
TULA
c:command.com

Vesna.1833
On the 28th of November, this virus displays:
TYPE "HAPPY BIRTHDAY GARRY" !

On Friday the 13th, it displays the following messages:
Friday 13th !
You have virus !
My name is GARRY ...
I fuck your PC !

Check other viruses! Be aware! Use Antiviral Software

NoFrills Family

Description NoFrills Family

There are not dangerous memory resident parasitic viruses. They hooks INT 21h and write themselves to the end of COM and EXE files that are accessed. Some of these viruses infect COM files in incorrect way, these files halt the system being executed. The viruses contain the text strings:
"NoFrills.813": +-No Frills by Harry McBungus-+
"NoFrills.815": +-No Frills 1.01 by Harry McBungus-+
"NoFrills.840": +-NF3.0-H.McB-[PuKE]-+
"NoFrills.843": +-No Frills 2.0 by Harry McBungus-+

NoFrills.Bungus
This virus hooks INT 8, 21h. It contains the texts:
*X-Fungus by Harry McBungus*
*Nugga!*
*Greets SCP*
*Greets RABID*
* Patricia: Grow some programming knowledge *
*Grease me!*
*K-Mart in full effect*
*Epileptic Downer*

This virus decrypts and displays:
John Bonham - September 20, 1980
- L E D Z E P P E L I N -

NoFrills.Dudley
It is a harmless polymorphic virus. It contains the text string:
[Oi Dudley!][PuKE]

NoFrills.Kcat.1358
It is a very dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM and EXE files that are executed, opened, or while accessing to the file attributes. The virus corrupts EXE files while infecting them.
The virus creates the C:WIN386.DAT and writes into there the keystrokes that are entered. The virus contains the text strings:
Kcat 3.01
5% - By Sir Twist & Thunderbird, with Many Thankz to Harry McBungus
whose coded we politely nicked.

NoFrills.K-Lame.950
On Sundays this virus creates the C:HARRY.MCB file, and while infecting any file the virus writes (appends) to that file the string:
+-K-Lame Kreation by Harry McBungus-+

NoHook.48

Description NoHook.48

These are very dangerous memory resident overwriting viruses. They copy themselves to the Interrupt Vectors Table, hook INT 85h and patch DOS kernel with INT 85h call. Then they overwrite files that are executed. Major versions of these viruses contain the text:
it's not necessary 2 hook int 21h!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com