Prevent Online Threats

Vesna Famil

Details
Vesna Family

These are benign non-memory resident parasitic viruses. They search for *.COM, *.EXE, CH*.* and *.°°° files, then write themselves to the end of the file.
Vesna.1000
These viruses infect only .COM files. “Vesna.1000.a” runs itself with a video “noise.” On Friday the 13th, it displays:
Friday 13th ?
Friday 13th all
Friday 13th !
Good bye !

“Vesna.1000.b” on the 22nd of June, this virus searches for EXE files and corrupts them.
These virus contains the text strings:
“Vesna.1000.a”: AIDS
My name is GARRY
“Vesna.1000.b”: *TULA*
*KILLER*

Vesna.1614 and 1700
These viruses check the file name, and do not infect the files with the names from the string (two bytes per name - VS*.*, DR*.*, and so on): “Vesna.1614″: drwetbmsmvavaiscadutanatsdncvcdnwiioibvi “Vesna.1700″: vsdrmswechaiioadscibutvranclavdowiatsdwsidvi “Vesna.1614″ is the encrypted virus. It displays the messages:
éÑß¡á “_¿_½á!
Unpress key TURBO to continue…
Format drive c: completed
PRESS RESET TO CONTINUE
Å”_á “¿__ ¬”_Ñ!
çñÑß_ í_½ êú”__ ä.
æ½___, __… _¶óᬅ “Ñ_Ññá_ “_¿óÑ_ éÑñÑ¡ÑÑó”_ ï”_¿ßÑ!
VESNA (c) 1994,96 -=* Uni Tula *=-

In March, “Vesna.1700″ displays a message, waits for a keystroke, and then reboots the computer:
Bad command or file name
DOS not support!
You have virus!
Press any key to reboot…

This virus also contains encrypted text strings:
*.exe *.com
ch*.* *.°°°
TULA
c:\command.com

Vesna.1833
On the 28th of November, this virus displays:
TYPE “HAPPY BIRTHDAY GARRY” !

On Friday the 13th, it displays the following messages:
Friday 13th !
You have virus !
My name is GARRY …
I fuck your PC !

Related Posts

  • Vesna.160
  • Vesna.1614
  • VM Famil
  • Mag Famil
  • Tic Famil
  • Leave a Reply


    Spyware Removal Spyware Protection Tools