Prevent Online Threats

Archive for October, 2006

Gen

Friday, October 27th, 2006

Details
Gena

It’s a very dangerous memory resident virus. It contains a lot of errors. This virus hooks INT 13h and overwrites the hard drive MBR and the floppy Boot-sectors. On an error it types the ‘trash’. It also contains the text:
by Gena 1992 . Drink “TAMARISI” !!! is a best of hilins !!!
Help me AIDSTEST.EXE !!!
Oh my got !!!
Ik Ik Ik Ik , man !
locked vector !!!
SIGNATURA PROLETARIATA. PARANOjA. AZOV !!!

Geliyor.135

Friday, October 27th, 2006

Details
Geliyor.1356

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are executed. Depending on the system date it patches its infection code and starts to disinfect the files instead of infection. It contains the internal text strings, several of them are encrypted:
geliyor. . .
Heey! O askerden geliyor..O’nu arìyorum gören varmì?
Hani O nerede göremedim ? Gelecek ay O geliyor. . .
Her canlì doşar büyür ölürD.T nisan 94 Ö.T mayìs 95

GeldWash.181

Friday, October 27th, 2006

Details
GeldWash.1819

This is a very dangerous memory resident parasitic virus. It hooks INT21h and writes ithemself to the end of EXE files that are executed. On June 11th it erases the disk sectors, and displays the message:
Fürs Vaterland ziehen sie ins Feld
Wer den Feind mordet, ist ein Held
Wie stolz sie auf die Orden sind !
Doch nur Dummköpfe gehorchen blind

GeldWash.149

Friday, October 27th, 2006

Details
GeldWash.1497

This is a very dangerous memory resident parasitic virus. It hooks INT21h and writes itself to the end of EXE files that are executed. Depending on the system date and time it erases the disk sectors, and displays the message:
Ihr Geld wasch ich sauber, schnell und prompt !
Ganz geil ich werde, wenn es von Drogen kommt !
Ihr korruptes Wirtschaftsschwein Hans W. Kopp !

GeeZee.46

Friday, October 27th, 2006

Details
GeeZee.464

It is a dangerous memory resident parasitic virus. It copies itself to DOS data area at address 0053:0000, hooks INT 1Ch, 21h and writes itself to the end of EXE files that are executed or opened. In 30 minutes after installing memory resident the virus clears the screen and halts the computer. The virus contains the string:
Gee_Zee 2

Geek.45

Friday, October 27th, 2006

Details
Geek.450

It’s a very dangerous memory resident parasitic virus. On execution it copies itself into the Interrupt Vector Table and hooks INT 21h. Then it hits COM- and EXE-files that are executed. On the 29th of every month it erases the disk sectors with a random selected number. It contains the internal text strings: “v07a”, “GEEK”, “dex”.

Gdynia.68

Friday, October 27th, 2006

Details
Gdynia.680

Gdynia.680 is a benign non-memory resident parasitic virus. It searches for COM files, then writes itself to the end of the file. Starting from February, the virus decrypts and displays the following message:
Windows 95 may be dangerous.
OS/2 is the best operating system!
I`ll prove it soonall

If this text is modified, the virus reboots the system. The virus also contains the text strings:
*.COM
* Gdynia 1996 * v1.0 *

GDIKill.128

Thursday, October 26th, 2006

Details
GDIKill.1288

This text was written by Alexey Podrezov, F-Secure Corp.
Being run it first goes to C:\WINDOWS\ folder. Then it checks current date and if the month is not March it passes control to original WIN.COM code. If the date is 14th of March, the virus just deletes GDI.EXE, outputs a message and passes control to original WIN.COM code.
If the virus starts from a dropper (it checks 1 byte flag for that), it looks for WIN.COM file and infects it. The virus author planned that his virus would infect other COM files in case WIN.COM is already infected, but there’s a bug in virus code and this doesn’t happen. Also there’s a routine in virus code that goes to \FONTS\ folder and deletes all files there. But this routine is never activated.

GD.53

Thursday, October 26th, 2006

Details
GD.539

It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. Depending on the system time the virus overwrites boot sector and the FAT of the C: drive and display the message:
Grave-digger!!!

Gawenda.41

Thursday, October 26th, 2006

Details
Gawenda.419

It is a harmless nonmemory resident parasitic virus. It searches for .COM files in current directory, for C:\COMMAND.COM, then writes itself to the end of the file. The virus does not manifest itself in any way, it contains the text strings:
Virus Gawenda (:
c:\command.com *.com

Ganja.43

Thursday, October 26th, 2006

Details
Ganja.437

It is a harmless nonmemory resident parasitic virus. It searches for EXE files, then writes itself to the end of the file. The virus does not manifest itself in any way. It contains the text strings:
=GANJA #1= / (C) 1995 [TAC] INC.*.EXE ..
This Program is too Stoned to operate correctly!

Gandalf.24

Thursday, October 26th, 2006

Details
Gandalf.240

These are harmless nonmemory resident encrypted parasitic viruses. They search for COM files in the current directory, then write themselves to the end of the file. The viruses contain the text strings:
“Gandalf.240″: [Gandalf.Gray]*.COM
“Gandalf.444″:
[MARTYR:2] - Greets to MarY PoPPinS + SMAUG - [VC.UK] *000018*

Game Famil

Thursday, October 26th, 2006

Details
Game Family

These are dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of EXE-files that are executed. In some cases, if the PC is in graphic video mode, the viruses erase the CMOS memory. They also contain the internal text strings:
9 November
GamE-FuckingeR 1.0 (c) The Dniester Moldavian Republic.

Gambler.28

Thursday, October 26th, 2006

Details
Gambler.288

It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of .COM files that are executed. It erases the disk sectors, and contains the text string:
GAMBLER

Galya.50

Thursday, October 26th, 2006

Details
Galya.500

This is a dangerous, memory-resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM files that are executed or opened. On December 17th, it erases disk sectors, decrypts and displays the following message:
Today is GALYA’S birthday


Spyware Removal Spyware Protection Tools