Virogen Family
Description Virogen Family
These are dangerous memory resident parasitic and companion polymorphic viruses. They hook INT 21h and on execution of a file or on selecting the logical drive (INT 21h, functions 0Eh, 4B00h) they search for .COM files (except COMMAND.COM) and write themselves to the end of the file. They also search for .EXE files and creates companion .COM files. Depending on the current date they corrupt the BIOS data area at address 0040:0016. They delete the CHKLIST.* and ANTI-VIR.* files. They contain the text strings: COMMAND.COM CHKLIST.* ANTI-VIR.* *.EXE *.COM
and "Virogen.1520,1535": (c)1993 - Virogen ASeXual Virus V1.00 "Virogen.1673": (c)1993 - Virogen
"Virogen.1673,1680" display: ASeXual Virus V0.99 - Your computer has been artificially Phucked!
Virogen.BombTrack It is a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. It deletes the CHKLIST.MS and CHKLIST.CPS files, depending on the system date it deletes all files of the current directory and creates there the subdirectories NEVERíne and BOMBTRA.CK. This virus also contains the text string: BOMBTRACK v1.00 - Coded by NEVERíne (BELGiUM)
Virogen.Drunk It is not a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. It deletes the CHKLIST.MS, CHKLIST.CPS and ANTI-VIR.DAT files. Depending on the system date it displays the message: Your computer is a little bit thirsty. So let us drink together and get [DRUNK]. Says Freddy Heineken of the mighty Dutch AA group. [DRUNK] vers. 1.0
Virogen.Offspring "Virogen.Offspring.711" infect .EXE files only. Depending on the system date these viruses display the message, print the screen (INT 5) and blinks by the NumLock, CapsLock and ScrollLock indicators. The messages are: "Offspring.711": (c)1993 VG Enterprises * Congratulations, You have recieved the privelge of being infected by the * * Offspring I v0.05. *
"Offspring.1294": (c)1993 negoriV * Thank you for providing me and my offspring with a safe place to live * * Offspring I v0.07. * "Offspring.1127": OFFSPRING V0.8 "Offspring.1130,1134": OFFSPRING V0.81 "Offspring.1555": O??spring Virus V0.89
They also contain the text strings: "Offspring.711": *.EXE "Offspring.1127,1130,1134": COMMAND.COM (c)1993 negoriV *.EXE *.COM "Offspring.1294": COMMAND.COM *.EXE *.COM "Offspring.1555": COMMAND.COM (c) ûirogen CHKLIST.* ANTI-VIR.DAT *.EXE *.COM
Virogen.PinWorm These are dangerous memory resident parasitic polymorphic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed. They delete the CHKLIST.MS and CHKLIST.CPS files and corrupt some anti-virus scanners. On the 1st of any month "PinWorm.2040,2150" create the subdirectory named PI_W_rM._g!
and creates the files there: I hope y ou have enjoyed your inf estation by the mighty P inworm p arasite Fuck you all! -_irogen
Other viruses manifest themselves with several manners: corrupt the system data, create trojan programs, create text files and write the messages to there. These viruses contain the text strings: "PinWorm.2150": PI_W_rMv1.00 - Coded by _irogen in April 1994 "PinWorm.2171": PI_W_rM_v1.00 - Coded by _irogen in April 1994
"PinWorm.2371,2566": Thank you for allowing Pinworm v1.7 to reside within your computer! You will be rewarded for your kindness by the gods which reign over the cyber world. You may thank the holy god of heart and kindness, ûirogen, for bringing this life into the cold and dead realms of your computer.
"PinWorm.2585,2780": Thank you for allowing Pinworm v1.6 to reside within your computer! You will be rewarded for your kindness by the gods which reign over the cyber world. You may thank the holy god of heart and kindness, _irogen, for bringing this life into the cold and dead realms of your computer. -----BEGIN PGP PUBLIC KEY BLOCK----- Version: 2.6 -----END PGP PUBLIC KEY BLOCK-----
Virogen.Simplex It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. It contains the text string: [_irogen SimpleX-ce]
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Day
Description Macro.Word97.Day
This is a silly but very dangerous macro virus. On opening an infected document the virus copies its body into the global macros area (NORMAL.DOT). Other documents get infection on their opening. When any document is being opened, the virus checks the system date, and starting from 2nd June 1999 writes into the AUTOEXEC.BAT file a set of commands that delete all data on C: and D: drives. The virus body contains the comment: it is a good day to die
Macro.Word97.Desecration
Description Macro.Word97.Desecration
This is Chinese (Taiwan) specific macro virus contains five macros in one module "Desecration": AutoOpen, FileSave, FileNew, FileOpen, Desecration. The virus infects the global macros area on opening an infected document (AutoOpen). Other documents get infection on their open, creating and saving (FileOpen, FileNew, FileSave). The virus does not manifest itself in any way. The code of virus contains the comment: Desecration By RUiNER /Sign Of Scream
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|