Vesna Family
Description Vesna Family
These are benign non-memory resident parasitic viruses. They search for *.COM, *.EXE, CH*.* and *.°°° files, then write themselves to the end of the file. Vesna.1000 These viruses infect only .COM files. "Vesna.1000.a" runs itself with a video "noise." On Friday the 13th, it displays: Friday 13th ? Friday 13th all Friday 13th ! Good bye !
"Vesna.1000.b" on the 22nd of June, this virus searches for EXE files and corrupts them. These virus contains the text strings: "Vesna.1000.a": AIDS My name is GARRY "Vesna.1000.b": *TULA* *KILLER*
Vesna.1614 and 1700 These viruses check the file name, and do not infect the files with the names from the string (two bytes per name - VS*.*, DR*.*, and so on): "Vesna.1614": drwetbmsmvavaiscadutanatsdncvcdnwiioibvi "Vesna.1700": vsdrmswechaiioadscibutvranclavdowiatsdwsidvi "Vesna.1614" is the encrypted virus. It displays the messages: éÑß¡á "_¿_½á! Unpress key TURBO to continue... Format drive c: completed PRESS RESET TO CONTINUE Å"_á "¿__ ¬"_Ñ! çñÑß_ í_½ êú"__ ä. æ½___, __... _¶óá¬... "Ñ_Ññá_ "_¿óÑ_ éÑñÑ¡ÑÑó"_ ï"_¿ßÑ! VESNA (c) 1994,96 -=* Uni Tula *=-
In March, "Vesna.1700" displays a message, waits for a keystroke, and then reboots the computer: Bad command or file name DOS not support! You have virus! Press any key to reboot...
This virus also contains encrypted text strings: *.exe *.com ch*.* *.°°° TULA c:command.com
Vesna.1833 On the 28th of November, this virus displays: TYPE "HAPPY BIRTHDAY GARRY" !
On Friday the 13th, it displays the following messages: Friday 13th ! You have virus ! My name is GARRY ... I fuck your PC !
Check other viruses! Be aware! Use Antiviral Software
Olivia.3378
Description Olivia.3378
This is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. Duplicate infection is possible. In some cases, the virus writes the "jump-to-virus" instruction to the middle of COM files. The virus checks the names and do not infect the following files: 4DOS, COMMAND, WIN, EMM386 The virus uses anti-debugging tricks and disables several anti-virus resident monitors. On April 10th it launches its trigger routine. This routine checks the CD-ROM installed and displays the following message: please put a love music CD into your CD-ROM and pass any key to continueall Then it summons several system CD-ROM access functions (plays CD-ROM?). Then the virus displays some text (possibly in Chinese) including the text: By André '97/1/30 In addition to listed above, it also infects Windows32 PE executable files. The virus writes its code to the end of the file in the newly created section, and modifies PE header. The virus does not spread itself from PE files. It just summons some Windows Kernel function (displays a text?), and returns to the host program. The virus has bugs and corrupts PE files while infecting them. When infected files are executed, Windows displays a standard error message, and terminates the infected application. When an infected DOS file is executed, the virus hooks INT 21h and infects files that are accessed. When ARJ, RAR, PKZIP, LHA, BACKUP, MSBACKUP, CPBACKUP, CHKDSK or XCOPY utilities are executed, the virus disables its infection and semi-stealth routines. When VT* or PV* files are executed, the virus temporarily hooks INT 10h for an unknown reason. The virus calls its trigger routine to play a CD disk on April 10. Before playing the CD, it displays the following message: Put a Audio-CD into the CD-ROM, and it any key... The virus also contains the text: Olivia Virus 6.00.95a
Omega.440
Description Omega.440
It is a very dangerous nonmemory resident parasitic virus. It searches for .COM-files, then writes itself to the end of the file. On Friday, 13th the virus displays the Omega character (EAh ASCII), and erases the hard drive sectors.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|