Virus Database


DAN viruses

Description DAN viruses

DAN.585
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. The virus deletes the ANTI-VIR.DAT and CHKLIST.MS files. On January, 18th the virus erases CMOS. The virus contains the text string:
ANTI-VIR.DAT CHKLIST.MS

DAN.1500
It is not a dangerous nonmemory resident polymorphic parasitic virus. It searches for .COM files, then it writes itself to the end of the file. On August, 1st it displays the message:
Virus 786 Version 3.00Zeta [786v3Z]
Escrito por Vixer [DAn]
Digital Anarchy Group of Argentina
Made in Argentina
Test de Swap, no polimorfico

The virus also contains the text strings:
*.C?M
nti-vir.dat
Aqui no estoy!

DAN.AntiEnter.1092
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM files that are executed. After infection the virus deletes the files:
C:CHKLIST.MS C:CHKLIST.CPS C:ZZ##.IM anti-vir.dat ANTI-VIR.DAT

Depending on its internal counter the virus "skips" ENTER keystrokes. Depending on the system date the virus displays the message:
Virus ANTI-ENTER v1.0ß
(c) 1995 El Cancerbero [DAN]
ARGENTINA

DAN.Chiche.1436
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus overwrites the MBR of the hard drive with a program that depending on the system date displays the message:
Un regalito para el JUAN XXI

The virus also contains the text strings:
Virus Chiche Ver. 0.99ß (C)Bugs Bunny [DAN] Digital Anarchy 2/11/94
Fuck! Telefonica Argentina

DAN.DiskFull.1871
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. Depending on its internal counter the virus erases the disk sectors, and displays the message:
Disk Full.
Press any key to continue
This program was written in Argentina
Copyright 1994-1995 Cancerbero [DAN]

The virus deletes the files:
C:CHKLIST.MS
C:CHKLIST.CPS
C:ZZ##.IM
anti-vir.dat
ANTI-VIR.DAT

The virus also contains the text string:
Greetings to all [DAN] members

DAN.Killer
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. The virus contains the text string:
Killer by Cancerbero

DAN.Mosca
These are dangerous memory resident polymorphic parasitic viruses. They hook INT 21h and write themselves to the end of .COM files that are executed. While execution of .EXE file "Mosca.1278,1372" create companion .COM file, and infect that file. "Mosca.1372" also infects the files that are opened, and while Get/Set File Attribute DOS call.
The viruses has the bugs, and the infected files can halt the system while executing. These viruses contain the text strings:
"Mosca.849": Mosca v1.0ß por WMÆ [DAN]
"Mosca.1278": Mosca v2.0ß por WMÆ [DAN]
"Mosca.1372": Mosca v2.1ß por WMÆ [DAN]

DAN.Octubre
It is a very dangerous memory resident encrypted parasitic stealth virus. It hooks INT 21h and writes itself to the end of COM and EXE files (except TB*.*) that are executed or closed. While installing memory resident the virus searches for COMSPEC= string in the Environment, and infects the command processor. The virus deletes the files CHKLIST.MS and ANTI-VIR.DAT. On December 18 in 1995 or on October 6 in any other year the virus erases the disk sectors and displays the message:
Feliz aniversario Digital Anarchy!!

The virus also contains the text strings:
Virus OKTUBRE Ver. 1.0ß By Bugs Bunny [DAN]
(c) 26/12/94 Digital Anarchy BsAs Arg.

DAN.SFT
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. After infecting the virus deletes the files:
C:CHKLIST.MS C:CHKLIST.CPS C:anti-vir.dat C:ANTI-VIR.DAT

The virus contains the text string:
- SFT Virus v1.0ß - Written by Cancerbero [DAN]

DAN.WMA
These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed, "DAN.WMA.709" infects only EXE files.
"DAN.WMA.709" contains the text string:
߯߯s__i¢_s h_¢h_ p_r wmÆ

"DAN.WMA.995" is encrypted virus. On 1st of January it displays the message:
Androide 1ß by WMÆ [DAN]

DAN.WMA.Dumb
It is a very dangerous memory resident parasitic virus. It copies itself into the system memory at address 8D00:0000, and does not alter the MCB blocks. As a result PC may halt while loading an average size application. Then the virus hooks INT 21h and write itself to the end of COM files that are executed or opened.
When an infected program is executed with "help" argument, the virus displays:
Dumß ß¥ WMÆ
[filename] fuck
trashes HD

When an infected program is executed with "fuck" argument, the virus formats the hard drive sectors.
DAN.WMA.Jason
It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed or opened. On August, 11th the virus decrypts, and displays the message, then erases the MBR of the hard drive:
Jason Virus 2.0 Written By Jason.

Check other viruses! Be aware! Use Antiviral Software

Macro.AmiPro.Green

Description Macro.AmiPro.Green

This virus contains four macros (functions): Green_Stripe_Virus, Infect_File, SaveFile, SaveAsFile. They receive the control when an infected document is opened, then the virus searches for *.SAM files of the current directory and infects them.
While infecting a SAM file the virus creates an SMM file, and copies itself to there by the command DosCopyFile. Then the virus assigns the Green_Stripe_Virus macro for that file, the virus does it by the AssignMacroToFile command.
Then the virus hooks SaveFile and SaveAsFile macros. When the "Save As" command is performed, the virus infects that document. In case of "Save" command the virus replaces the "its" string with "it's" one within the file.

Macro.Excel.Compat

Description Macro.Excel.Compat

This is a polymorphic Excel macro virus. It contains one module with 11 functions inside: Macro1, Macro2, Macro3, Macro4, Macro5, Macro6, Macro7, Auto_Open, Auto_Close, Auto_Exit, Auto_Help.
The virus runs its infection routine on opening files, switching sheets, or on timer events. While infecting the virus polymorphic engine inserts into the virus code random generated comments. The name of virus module is also randomly generated.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com