Archive for October, 2006
Friday, October 27th, 2006
Details
Gena
It’s a very dangerous memory resident virus. It contains a lot of errors. This virus hooks INT 13h and overwrites the hard drive MBR and the floppy Boot-sectors. On an error it types the ‘trash’. It also contains the text:
by Gena 1992 . Drink “TAMARISI” !!! is a best of hilins !!!
Help me AIDSTEST.EXE !!!
Oh my got !!!
Ik Ik Ik Ik , man !
locked vector !!!
SIGNATURA PROLETARIATA. PARANOjA. AZOV !!!
Posted in Virus Threats | No Comments »
Friday, October 27th, 2006
Details
Geliyor.1356
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are executed. Depending on the system date it patches its infection code and starts to disinfect the files instead of infection. It contains the internal text strings, several of them are encrypted:
geliyor. . .
Heey! O askerden geliyor..O’nu arìyorum gören varmì?
Hani O nerede göremedim ? Gelecek ay O geliyor. . .
Her canlì doşar büyür ölürD.T nisan 94 Ö.T mayìs 95
Posted in Virus Threats | No Comments »
Friday, October 27th, 2006
Details
GeldWash.1819
This is a very dangerous memory resident parasitic virus. It hooks INT21h and writes ithemself to the end of EXE files that are executed. On June 11th it erases the disk sectors, and displays the message:
Fürs Vaterland ziehen sie ins Feld
Wer den Feind mordet, ist ein Held
Wie stolz sie auf die Orden sind !
Doch nur Dummköpfe gehorchen blind
Posted in Virus Threats | No Comments »
Friday, October 27th, 2006
Details
GeldWash.1497
This is a very dangerous memory resident parasitic virus. It hooks INT21h and writes itself to the end of EXE files that are executed. Depending on the system date and time it erases the disk sectors, and displays the message:
Ihr Geld wasch ich sauber, schnell und prompt !
Ganz geil ich werde, wenn es von Drogen kommt !
Ihr korruptes Wirtschaftsschwein Hans W. Kopp !
Posted in Virus Threats | No Comments »
Friday, October 27th, 2006
Details
GeeZee.464
It is a dangerous memory resident parasitic virus. It copies itself to DOS data area at address 0053:0000, hooks INT 1Ch, 21h and writes itself to the end of EXE files that are executed or opened. In 30 minutes after installing memory resident the virus clears the screen and halts the computer. The virus contains the string:
Gee_Zee 2
Posted in Virus Threats | No Comments »
Friday, October 27th, 2006
Details
Geek.450
It’s a very dangerous memory resident parasitic virus. On execution it copies itself into the Interrupt Vector Table and hooks INT 21h. Then it hits COM- and EXE-files that are executed. On the 29th of every month it erases the disk sectors with a random selected number. It contains the internal text strings: “v07a”, “GEEK”, “dex”.
Posted in Virus Threats | No Comments »
Friday, October 27th, 2006
Details
Gdynia.680
Gdynia.680 is a benign non-memory resident parasitic virus. It searches for COM files, then writes itself to the end of the file. Starting from February, the virus decrypts and displays the following message:
Windows 95 may be dangerous.
OS/2 is the best operating system!
I`ll prove it soonall
If this text is modified, the virus reboots the system. The virus also contains the text strings:
*.COM
* Gdynia 1996 * v1.0 *
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
GDIKill.1288
This text was written by Alexey Podrezov, F-Secure Corp.
Being run it first goes to C:\WINDOWS\ folder. Then it checks current date and if the month is not March it passes control to original WIN.COM code. If the date is 14th of March, the virus just deletes GDI.EXE, outputs a message and passes control to original WIN.COM code.
If the virus starts from a dropper (it checks 1 byte flag for that), it looks for WIN.COM file and infects it. The virus author planned that his virus would infect other COM files in case WIN.COM is already infected, but there’s a bug in virus code and this doesn’t happen. Also there’s a routine in virus code that goes to \FONTS\ folder and deletes all files there. But this routine is never activated.
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
GD.539
It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. Depending on the system time the virus overwrites boot sector and the FAT of the C: drive and display the message:
Grave-digger!!!
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
Gawenda.419
It is a harmless nonmemory resident parasitic virus. It searches for .COM files in current directory, for C:\COMMAND.COM, then writes itself to the end of the file. The virus does not manifest itself in any way, it contains the text strings:
Virus Gawenda (:
c:\command.com *.com
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
Ganja.437
It is a harmless nonmemory resident parasitic virus. It searches for EXE files, then writes itself to the end of the file. The virus does not manifest itself in any way. It contains the text strings:
=GANJA #1= / (C) 1995 [TAC] INC.*.EXE ..
This Program is too Stoned to operate correctly!
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
Gandalf.240
These are harmless nonmemory resident encrypted parasitic viruses. They search for COM files in the current directory, then write themselves to the end of the file. The viruses contain the text strings:
“Gandalf.240″: [Gandalf.Gray]*.COM
“Gandalf.444″:
[MARTYR:2] - Greets to MarY PoPPinS + SMAUG - [VC.UK] *000018*
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
Game Family
These are dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of EXE-files that are executed. In some cases, if the PC is in graphic video mode, the viruses erase the CMOS memory. They also contain the internal text strings:
9 November
GamE-FuckingeR 1.0 (c) The Dniester Moldavian Republic.
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
Gambler.288
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of .COM files that are executed. It erases the disk sectors, and contains the text string:
GAMBLER
Posted in Virus Threats | No Comments »
Thursday, October 26th, 2006
Details
Galya.500
This is a dangerous, memory-resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM files that are executed or opened. On December 17th, it erases disk sectors, decrypts and displays the following message:
Today is GALYA’S birthday
Posted in Virus Threats | No Comments »