Virus Database


Wawah.787

Description Wawah.787

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. The actual virus length is 787 bytes, but while infecting a file it writes from 1043 till 1059 bytes. On 10th of any month the virus decrypts and displays the message:
- G 124 HA - Assembled by WaWaH

Check other viruses! Be aware! Use Antiviral Software

GV Family

Description GV Family

These are not dangerous memory resident parasitic viruses. They hook INT 9, 16h, 21h, 28h and write themselves to the end of COM-files that are executed. On pressing of Alt-Ctrl-V keys they display the messages:
"GV.2856":
+--------------------------------+
¦ Good Virus #1 Alpha Model ¦
¦ [GV1] ¦
¦ (c) 1994 by Stormbringer [P/S] ¦
¦ ¦
¦ Infection Mode: ¦
¦ [N]one ¦
¦ [I]nfect Files ¦
¦ [D]isinfect Files ¦
¦ ¦
¦ Encryption Commands: ¦
¦ [E]ncrypt File ¦
¦ De[C]rypt File ¦
¦ ¦
¦ Press [ESC] To Exit Menu ¦
+--------------------------------+

"GV.2865":
+--------------------------------+
¦ Good Virus #1 1.01 ¦
¦ [GV1] ¦
¦ (c) 1994 by Stormbringer [P/S] ¦
¦ ¦
¦ Infection Mode: ¦
¦ [N]one ¦
¦ [I]nfect Files ¦
¦ [D]isinfect Files ¦
¦ ¦
¦ Encryption Commands: ¦
¦ [E]ncrypt File ¦
¦ De[C]rypt File ¦
¦ ¦
¦ Press [ESC] To Exit Menu ¦
+--------------------------------+

When the 'D' key is pressed they disinfect the infected files on their execution. When the 'E' or 'C' keys are pressed they encrypt/decrypt the file which is selected by the user. The viruses display the messages before encryption:
+-[Enter Filename Below]-+
¦ > ¦
+------------------------+
+----[Please Enter 16 Byte Password (Extra Chars Ignored)]----+
¦ > ¦
+-------------------------------------------------------------+

They also contain/display the internal strings:
"GV.2856":
Good Virus #1 Alpha (c) 1994 Stormbringer [P/S] Now Loaded.
Press CTRL-ALT-V For User Menu. Infection Set To NONE.
Error Opening File!
GV1
GoodVir1

"GV.2865":
Error Opening File!
GV1 v101

Gvirus.653

Description Gvirus.653

It's a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the ends of the .COM-files that are executed. The virus contains the string "COMMAND.COM" and infects this file on installation. After one month of infection the file displays: "Schon mal was von G-Virus gehört ?". It also contains the internal text string: "G-VIRUS V1.2".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com