Virus Database


Vesna Family

Description Vesna Family

These are benign non-memory resident parasitic viruses. They search for *.COM, *.EXE, CH*.* and *.°°° files, then write themselves to the end of the file.
Vesna.1000
These viruses infect only .COM files. "Vesna.1000.a" runs itself with a video "noise." On Friday the 13th, it displays:
Friday 13th ?
Friday 13th all
Friday 13th !
Good bye !

"Vesna.1000.b" on the 22nd of June, this virus searches for EXE files and corrupts them.
These virus contains the text strings:
"Vesna.1000.a": AIDS
My name is GARRY
"Vesna.1000.b": *TULA*
*KILLER*

Vesna.1614 and 1700
These viruses check the file name, and do not infect the files with the names from the string (two bytes per name - VS*.*, DR*.*, and so on): "Vesna.1614": drwetbmsmvavaiscadutanatsdncvcdnwiioibvi "Vesna.1700": vsdrmswechaiioadscibutvranclavdowiatsdwsidvi "Vesna.1614" is the encrypted virus. It displays the messages:
éÑß¡á "_¿_½á!
Unpress key TURBO to continue...
Format drive c: completed
PRESS RESET TO CONTINUE
Å"_á "¿__ ¬"_Ñ!
çñÑß_ í_½ êú"__ ä.
æ½___, __... _¶óá¬... "Ñ_Ññá_ "_¿óÑ_ éÑñÑ¡ÑÑó"_ ï"_¿ßÑ!
VESNA (c) 1994,96 -=* Uni Tula *=-

In March, "Vesna.1700" displays a message, waits for a keystroke, and then reboots the computer:
Bad command or file name
DOS not support!
You have virus!
Press any key to reboot...

This virus also contains encrypted text strings:
*.exe *.com
ch*.* *.°°°
TULA
c:command.com

Vesna.1833
On the 28th of November, this virus displays:
TYPE "HAPPY BIRTHDAY GARRY" !

On Friday the 13th, it displays the following messages:
Friday 13th !
You have virus !
My name is GARRY ...
I fuck your PC !

Check other viruses! Be aware! Use Antiviral Software

Olivia.3378

Description Olivia.3378

This is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. Duplicate infection is possible. In some cases, the virus writes the "jump-to-virus" instruction to the middle of COM files. The virus checks the names and do not infect the following files:
4DOS, COMMAND, WIN, EMM386
The virus uses anti-debugging tricks and disables several anti-virus resident monitors. On April 10th it launches its trigger routine. This routine checks the CD-ROM installed and displays the following message:
please put a love music CD into your CD-ROM
and pass any key to continueall
Then it summons several system CD-ROM access functions (plays CD-ROM?). Then the virus displays some text (possibly in Chinese) including the text:
By André '97/1/30
In addition to listed above, it also infects Windows32 PE executable files. The virus writes its code to the end of the file in the newly created section, and modifies PE header. The virus does not spread itself from PE files. It just summons some Windows Kernel function (displays a text?), and returns to the host program. The virus has bugs and corrupts PE files while infecting them. When infected files are executed, Windows displays a standard error message, and terminates the infected application.
When an infected DOS file is executed, the virus hooks INT 21h and infects files that are accessed. When ARJ, RAR, PKZIP, LHA, BACKUP, MSBACKUP, CPBACKUP, CHKDSK or XCOPY utilities are executed, the virus disables its infection and semi-stealth routines. When VT* or PV* files are executed, the virus temporarily hooks INT 10h for an unknown reason.
The virus calls its trigger routine to play a CD disk on April 10. Before playing the CD, it displays the following message:
Put a Audio-CD into the CD-ROM, and it any key...
The virus also contains the text:
Olivia Virus 6.00.95a

Omega.440

Description Omega.440

It is a very dangerous nonmemory resident parasitic virus. It searches for .COM-files, then writes itself to the end of the file. On Friday, 13th the virus displays the Omega character (EAh ASCII), and erases the hard drive sectors.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com