Prevent Online Threats

DAN viruse

Details
DAN viruses

DAN.585
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. The virus deletes the ANTI-VIR.DAT and CHKLIST.MS files. On January, 18th the virus erases CMOS. The virus contains the text string:
ANTI-VIR.DAT CHKLIST.MS

DAN.1500
It is not a dangerous nonmemory resident polymorphic parasitic virus. It searches for .COM files, then it writes itself to the end of the file. On August, 1st it displays the message:
Virus 786 Version 3.00Zeta [786v3Z]
Escrito por Vixer [DAn]
Digital Anarchy Group of Argentina
Made in Argentina
Test de Swap, no polimorfico

The virus also contains the text strings:
*.C?M
nti-vir.dat
Aqui no estoy!

DAN.AntiEnter.1092
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM files that are executed. After infection the virus deletes the files:
C:CHKLIST.MS C:CHKLIST.CPS C:ZZ##.IM anti-vir.dat ANTI-VIR.DAT

Depending on its internal counter the virus “skips” ENTER keystrokes. Depending on the system date the virus displays the message:
Virus ANTI-ENTER v1.0ß
(c) 1995 El Cancerbero [DAN]
ARGENTINA

DAN.Chiche.1436
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus overwrites the MBR of the hard drive with a program that depending on the system date displays the message:
Un regalito para el JUAN XXI

The virus also contains the text strings:
Virus Chiche Ver. 0.99ß (C)Bugs Bunny [DAN] Digital Anarchy 2/11/94
Fuck! Telefonica Argentina

DAN.DiskFull.1871
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. Depending on its internal counter the virus erases the disk sectors, and displays the message:
Disk Full.
Press any key to continue
This program was written in Argentina
Copyright 1994-1995 Cancerbero [DAN]

The virus deletes the files:
C:CHKLIST.MS
C:CHKLIST.CPS
C:ZZ##.IM
anti-vir.dat
ANTI-VIR.DAT

The virus also contains the text string:
Greetings to all [DAN] members

DAN.Killer
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. The virus contains the text string:
Killer by Cancerbero

DAN.Mosca
These are dangerous memory resident polymorphic parasitic viruses. They hook INT 21h and write themselves to the end of .COM files that are executed. While execution of .EXE file “Mosca.1278,1372″ create companion .COM file, and infect that file. “Mosca.1372″ also infects the files that are opened, and while Get/Set File Attribute DOS call.
The viruses has the bugs, and the infected files can halt the system while executing. These viruses contain the text strings:
“Mosca.849″: Mosca v1.0ß por WMÆ [DAN]
“Mosca.1278″: Mosca v2.0ß por WMÆ [DAN]
“Mosca.1372″: Mosca v2.1ß por WMÆ [DAN]

DAN.Octubre
It is a very dangerous memory resident encrypted parasitic stealth virus. It hooks INT 21h and writes itself to the end of COM and EXE files (except TB*.*) that are executed or closed. While installing memory resident the virus searches for COMSPEC= string in the Environment, and infects the command processor. The virus deletes the files CHKLIST.MS and ANTI-VIR.DAT. On December 18 in 1995 or on October 6 in any other year the virus erases the disk sectors and displays the message:
Feliz aniversario Digital Anarchy!!

The virus also contains the text strings:
Virus OKTUBRE Ver. 1.0ß By Bugs Bunny [DAN]
(c) 26/12/94 Digital Anarchy BsAs Arg.

DAN.SFT
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. After infecting the virus deletes the files:
C:CHKLIST.MS C:CHKLIST.CPS C:anti-vir.dat C:ANTI-VIR.DAT

The virus contains the text string:
- SFT Virus v1.0ß - Written by Cancerbero [DAN]

DAN.WMA
These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed, “DAN.WMA.709″ infects only EXE files.
“DAN.WMA.709″ contains the text string:
߯߯s__i¢_s h_¢h_ p_r wmÆ

“DAN.WMA.995″ is encrypted virus. On 1st of January it displays the message:
Androide 1ß by WMÆ [DAN]

DAN.WMA.Dumb
It is a very dangerous memory resident parasitic virus. It copies itself into the system memory at address 8D00:0000, and does not alter the MCB blocks. As a result PC may halt while loading an average size application. Then the virus hooks INT 21h and write itself to the end of COM files that are executed or opened.
When an infected program is executed with “help” argument, the virus displays:
Dumß ß¥ WMÆ
[filename] fuck
trashes HD

When an infected program is executed with “fuck” argument, the virus formats the hard drive sectors.
DAN.WMA.Jason
It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed or opened. On August, 11th the virus decrypts, and displays the message, then erases the MBR of the hard drive:
Jason Virus 2.0 Written By Jason.

Related Posts

  • Harpy.121
  • DSCE-based viruse
  • MME-based viruse
  • MME-based viruse
  • Mirror viruse
  • Leave a Reply


    Spyware Removal Spyware Protection Tools