Category : System Diagnostics for your computer
Archive   : 30A11.ZIP
Filename : VIRSCAN.INF

 
Output of file : VIRSCAN.INF contained in archive : 30A11.ZIP
The Norton AntiVirus Information File
Copyright Symantec Corp. 1993-94
All Rights Reserved

Version #9409
ö °ÌÌã!111ZZyšÊð7777Mkk‹‹‹‹¦Ëë ...GG¨Ãèè=nnŒŒŒŒŒ­ÁÁÁÁÁÁÁÁÁÁÁÁÁÁÁÕÕýý--KKKKKKKKkk³ÊÊððððð"""""k`kkkkkkÁÁÁÁÁÁÁÁÁÁÁÁÁÁÁÁÏÏÏÿ      !!!!Ga~~šÍëë
J„„«««««Äæù K k { { Ÿ ´ ´ ´ Æ Ù ú 

0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
F
R
y
Ÿ
î
À
À
î
î
î
î
î
î
î
î
î
î
î
î
î
î
î
î
î
î
î
î
   I ` ` q x Š ® Ë ü ü ü ü ü ü ü ü ü ü  ( ( ( = = _ f f f ’ © Ã × é 

/
<
n
Š
Š
¬
¬
Ä
Ä
Ä
Ä
Û
é
A]mm””«««««¾¾¾¾¾¾ð"???p†††¥ÁÁÁÁÁÁÁÓÓÓññññññññññññÓÓ###ÓÓÓÓÓÓÓÓ2\\\\\„‘‘‘‘········äü//LLLLLWz¯¯ÅÅó&&&&&&&&&&&&&&&&&&&&&&&&&&&6[[{{¦ÐÐÐÐÐÐÐÐñø5nn¢ÁÙý&8MVVVVrˆˆ–––¡¡¡¿áÎ7Î7 1PPpšÄÄÜæ'''''8FFFlŒ§ÃÃÃ××ìù&&IIIpppppp¤ÀÜÜÜûûûûûûUU}}}}˜˜¿áááááá-Uu‡›Õööööööö!2O}¨¨»ÅÅÅÅÅÅÛù?hŠ
Š
Š
ŽŽŽ½Øú'''5\\uŒ¢³Ý,,,,,,,,,,Vvv•••••••••¶¶¶åååååååååÿÿ<Xszz˜˜Ÿ¬½ãã88ee±ÄÄÄçöö           / C C C C X X X X X X X X X X X X X X X X X X X X X X ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ ‡ X X X X X X X X X X X X — — — — — — X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X X C ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã ã C C C C C C C C C C C !!!!!C C C C C C C C C C C C C C C C C C M!M!C C m!m!m!m!C š!š!C C C C C C Ä!ì!ì!ì!ì!ì!ì!
"
"+"+"+"C C C C I"I"I"I"I"C C h"Œ"§"Æ"ã"# #+#E#E#c#####¹#Ñ#â#â#â#â#$$$$$$$$$$$$$$$$$$$$$$$$$$Z$Z$Z$Z$~$Ž$²$Ç$ß$ð$ð$ð$%%%1%^%^%% % %¯%¯%¶%¶%Ý%
&.&O&O&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&k&Œ&Œ&­&Ñ&Ø&Ø&Ø&Ø&Ø&Ø&'''A'A'A'A'A'A'R's's'‹'’'µ'è'ø'((K(7(7(}((ª(Ò(Ò(Ò(à(ç(÷(÷(÷(÷(÷(÷(÷(÷(÷(÷()>)O)O)‰)‰)½)Ç)Ù)Ù)Ù)ú)***.*J*e*l*l*l*l*l*l*l*l*l*|*›*§*Î*Î*Î*æ*ø*++0+K+K+c++©+Í+Í+ú+ú+ú+ú+ú+,(,(,>,X,X,„,„,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,˜,Å,Å,í,-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-]-B-B-B-n-n--—-°-Ü-Ü-í-....,.=.=.p.p.Œ.§.´.´.´.´.´.´.´.´.´.Û.
/
/
/
/
/
/
/
/./././././././././T/T/T/o/o/o/o/o/o/o/o/o/†/§/Ä/Ù/Ù/ä/ä/ñ/000"0+0J0J0y0œ0œ0®0¾0Û0û0û0û0 1 1 1 1 1 1111111M1M1i1ƒ1š1š1³1Ö1Ö1Ö1Ö1Ö1Ö1ì1þ12"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2"2S2f2f2f2f222°2·2Ã2Ã2Ã2Ã2Ã2Ã2Ã2Ð2×2ð233333,3,3,333K3^3l3„3»3Ë3í3444+4+4+4+4L4L4l4–4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4¸4Ë4Ò4ó4555$51515^5^555·5Ó5Þ566[6[6z6„6´6Á6Û6ç6ç6ç6î6î677u7u7‘7˜7À7Î7Î7Î7Î7Î7Î7Î7Î7Î7Ü7ð78(8(8(8(8I8I8I8I8I8I8I8Y8f8f8u8‹8‹8¡8­8­8­8­8»8»8Ô8â89 999@9@9@9@9@9@9@9P9P9P9P9}9š9«9«9«9Á9á9ø9:=:M:c:“:±:Í:Ú:ê:ê:ê:ê:;K;p;p;p;p;p;p;Œ;§;µ;Ó;Ó;Ó;Ó;ð;<4<4ó=ó=>F>F>e>‡>ª>ª>ª>ª>¶>Ó>è>???,?,?,?;?;?;?;?;?;?;?^?f?f?f?f?f?f?f?f?f?f?f?f?v?v?v?v?v?v?v?Ž?›?¾?Î?è?è?è?è?è?è?è?@@:@:@:@:@:@f@€@€@€@”@”@”@¸@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@ñ@A6A6ADAZAyA„A„A„A„AžA«A¹AÝAñAB8B8B8B8B8B8B8BbB†B™B™B™B³B³B³BÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBÂBüBCCCCCC'C'C'C'C'C'C'C'C'C'C'C'C'C'C'C'C'C'C'C'C'COCOC^C^C^C^C^CŒCŒCŒCŒCŒCŒC±CËCËCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþCþC"D"D"D"D"D"D"D"D"D"D"DþC:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:D:DQDbDbD†D†D†D†D†D†D†D†D†D†D†DžD½D½DÜDõDEEEEEE%EHEHE`E‡E“E¾EÑEõEFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF'F;F^FtF…F›F¢FËFËFËFËFËFËFËFËFËFßFßFßFìFìFìFìF G!G!G5GdG‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡G‡GœGÈGÝGÝGÝGúGúGúG HHH/HeHHHHHHHHÂHÏH#óHóHIè1IYIzI“I­IÈIäIúIúI"JEJtJ•Jp°JâJþJKLKrK…K¤KØ&ÊKëK LL4LäIcL}L±LÑLñLM,M,MV Á ††\--Á----†W>oP¤NKO>TONNN“N¤N¤N¤N¤NO•JêNêNòOP6PKPoPÆP§PºPuQ©Q>TLK©TMÀTV½V¸4†¸4¸4¸4¸4¸4¸4¸4¸4W¸4¸4© — — +33ÛÛÛùB-'C
W\WW†1u8ì!Wä†C = Ü„p††c:1¿WÈG†^=†W-W“WW- † ÐW&&«««
/ÇN1ÇN.O.O|O±O±O±O±O\P½O½OØOÛP÷P÷P'QRQRQÃQÛQœQÎQ·ïQçQ¶Q§R§RT)TTÏW–T–T˜,˜,˜,˜,˜,:@˜,˜,˜,:@:@>7˜,˜,:@˜,˜,˜,˜,˜,˜,˜,˜,˜,] XAXuX«XâXY9YoY¥YÖYZ:ZkZ›Z›ZÅZêZ"["["[Z[’[¿[õ[&\]\]\˜\È\B]W^5†éM>7>7>7>7>7>7>7>7>7>7>7W‚Q‚QÀT‘R-U-U‘R?U¤UhUhUhUhUhUhU‰UúT³UËUáUþCþCþCüB'CþCþCþCþCþCþCþCþCþChUCMVMVMVMVMVW`V`V`VqV„V„V•V•V¯VÇVWWÚVöVW)W¸4"2Û0_W“W“WX £WºW R/RDRDR[RjRR‘R RVÕRõRSRU?S–U—SæS[SgS…S¯S¿SÉSÙST TS¡S¡S‘R'¸4¸4¸4¸4¸4¸4¸4This virus does little besides replicate.This is not a virus. It is a Trojan Horse program. You should delete this file. See "Trojan" in the Glossary section of your manual.This is not a virus. It is a program designed to release a virus on your system. You should delete this file. See "Dropper" in the Glossary section of your manual.This is a first generation sample of the virus. A first generation sample is one where all the second generation viruses are the same but differ from the first generation virus sample.This is a damaged version of the original virus.This is a harmless joke program.This is a simple virus that does nothing but replicate.The first time an infected file is run the virus moves itself into memory. From memory the virus infects programs as they are run.748, ThereseBetween 3:10pm and 3:13pm every day, the virus interferes with keyboard input.Thirteen minutesThe virus may attach garbage bytes to infected programs. A cold boot may be required after running an infected program.4870 OverwritingThe virus destroys program files by overwriting the first 4870 bytes with its viral code.The virus changes an infected program's date and time stamp.7th Son, Seventh SonThe virus changes an infected program's date and time stamp. Infected programs contain the text "Seventh Son of a seventh son" and "*.COM".1971When the virus is active, it plays one of eight different tunes. It does not infect programs smaller than 8192 bytes.The virus changes an infected program's date and time stamp. When activated, the virus clears and reprints blocks of the screen.The virus changes an infected program's date and time stamp. It activates on the 13th of each month. When double letters are typed it triples the letter. For example, "book" becomes "boook".The virus produces a slow clicking sound. The virus targets the antivirus package PC-cillin. It contains the text "HATI-HATI !! ADA VIRUS DISINI !!"Adolf HitlerThe virus changes an infected program's date and time stamp. Contains the text "Adolph Hitler".CompanionThe virus may display the message "Your computer is infected with" and "AIDS VIRUS II" and play music. As a companion virus, simply delete all infected files.The infected program stops after displaying the message "A kuku, Nastepny komornik!!"A variant of the Akuku virus containing the text "Sorry, I'm copmpletly dead". Note that "completely" is misspelled.AlaOne hour after the virus is activated, the following message appears: "SOFTWARE COPIES PROHIBITED BY INTERNATIONAL LAW..."The virus changes an infected program's date and time stamp. Infected programs contain the text "Albania".The virus changes an infected program's date and time stamp to 17DEC89 7:21pm. Infected programs contain the text "C:\COMMAND.COM" and "*.COM".The virus changes an infected program's date and time stamp. Contains the text "One Night Virus (C) Alex Hacker" and "*.COM".The virus changes an infected program's date and time stamp. Contains the text "The Kite Virus (C) Alex Hacker" and "*.EXE".The virus occasionally displays a boxed text and plays a tune. The text is encrypted and says, in part, "Alexander - Constanta, Romania".Red-X, Ambulance CarThe virus may display a moving ambulance while emitting the sound of a siren.1392The virus overwrites a program's first 1089 bytes with viral code, placing the original code at the end, and then adds 303 more bytes to the end of the file. Infected programs contain the text "... Nouvel Band A.M.O.E.B.A".AndreIn addition to infecting programs when they are accessed or run, the virus infects programs that are copied or accessed, using the DOS DIR command.The virus changes an infected program's date and time stamp. Infected programs contain the text "*.COM".The virus changes an infected program's date and time stamp. The virus infects one additional COM program each time an infected program is run.Infected programs contain the text "Anthrax" and "Damage, Inc". The virus writes a copy of itself to the last few sectors of the hard disk. Any data located there is destroyed.SuxInfected programs contain the text "[Anti-MIT]". When active on December 1st, the virus destroys all of the data on the hard disk and displays "MIT Sux!"PandaFluRunning an infected program causes all COM programs located in the C: drive root directory to be infected. Infected programs contain the text "FLUSHOT3.COM" and "C:\PANDA\MONITOR.COM..."Anti-PascalThe virus changes an infected program's date and time stamp. Files with PAS and BAK extension are deleted.AP-400/-440/-480, AntiPascal IIIf the virus cannot locate a program to infect, it deletes files with BAK, PAS, or BAT extensions.834The virus alters the hard disk in a way that causes an incomplete boot up.ARCV is a group of viruses written by "Association of Really Cruel Viruses".Greek, ArmaWhen active between 5 and 7 P.M., the virus attempts to use the local COM ports to make a phone call to local time information in Crete, Greece.1590On November 20th the virus prints a long message in Spanish, which includes the phrase "Spain Jaws && Sharks" in English.The virus changes an infected program's date and time stamp.The virus corrupts data files by deleting 700 bytes from them. Infected programs contain the text "(C) AsTrA, 1991..."The virus changes an infected program's date and time stamp. The virus infects programs only on AT(286) computers and above.The message "OK" or "I like to travel" appears when infected programs are run. The virus changes an infected program's date and time stamp. It contains the text "ATAS(Kiev)" and a version number.The virus contains the encrypted text "ATAS Corporation (C)1992" and a version number.TrojectorThe virus contains the text "TROJECTOR II,(c) Armagedon Utilities, Athens 1992".USSR, AttentionWhen a key is pressed, a click sound is emitted. When some infected programs are run, the message "Invalid drive or file name" appears.The virus changes an infected program's date and time stamp. The virus infects programs only on AT(286) computers and above.Infects programs when they are run or opened. Contains the text "Ava".905, BadsecWhen the virus is active, the fonts on EGA and VGA monitors are changed. A cold boot may be required after running an infected program.When the virus is first run it prints "Bad command of file name" and returns to the DOS prompt.BBInfected programs may not run properly.Infected programs contain the text "The bad boy halt your system..." A cold boot may be required after running an infected program.The virus changes an infected program's date and time stamp.When the virus is active on January 5th, it erases the MBR, and displays flashing vertical bars and the message "Virus BARROTES por OSoft".V-512, 666Infected programs contain the text "666".USSRInfected programs simply stop after emitting a clicking noise. The virus may display a box with the phrase "Skagi 'bebe' >" and when the user types "bebe" the virus prints "Fig Tebe !"439Infected programs' size increases by 439 bytes.Beer-2794When active, the virus plays a tune, and a message in Russian appears.Best Wishes, WishesIf COMMAND.COM is infected, it does not function properly. Infected programs contain the text "This program ... With Best Wishes!"MudThe virus plays tricks with the screen. Contains the text "Mexican Mud (c)1992 MaZ" and "+Sweden+".Death RattleThe virus plays tricks with the screen. Contains the text "DEATH RATTLE V1.00" and "+S+W+E+D+E+N+".FellowshipInfected programs contain the text "This message is dedicated to all fellow PC users on Earth..."Monday the 1stWhen the virus is active on any Monday the 1st, the boot record of any floppy disk in drive A: is overwritten. Contains the text "BEWARE ME - 0.01, Copr (c) DarkGraveSoft - Moscow 1990".The following messages appear: "At last ... ALIVE!!!!!" "I guess your computer is infected by the Big Joke Virus..."NedWhen an infected COMMAND.COM runs, the virus reboots your computer continuously. Contains the text "KMIT-NB Date 12/28/1990 BIOS".Infected programs contain the text "BIT ADDICT..."BljecThe virus changes an infected program's date and time stamp. This virus infects by adding itself to the start of the host file. This family of viruses often hang the infected machine.Digital F/XThe virus changes an infected program's date and time stamp. Contains the text "Digital F/X" at the beginning of the virus code. When the virus runs, this text is executed as code and will hang pre-80286 computers.SadThe virus changes an infected program's date and time stamp. If active in September the virus destroys data and prints the text "Sad virus - 24/8/91".Black Monday Borderline, MondayInfected programs contain the text "Black Monday 2/3/9KV KL MAL".The virus destroys COM and EXE programs by overwriting them. Prints the message "The Eternal Blaze Virus has been unleashed...Beware!"Blood 2The message "File infected by BLOOD VIRUS version 1.20" appears.Trivial-Blood LustInfected programs contain the text "Hi! This is the virus Bloodlust striking!..."V-5792, 5792, PaThe virus infects three EXE programs, displays the error message "Error in *.EXE file", and then returns to the DOS prompt. When infected program is running, the message "Pa,pa slodki bobasku..." appears.Malanesian BomberWhen the virus is active on August 31st, a beep is emitted and the message "! I AM STEALTH BOMBER !" appears.Infected programs' size increases between 340 and 350 bytes.BFD-451When active, the virus overwrites the boot record of floppy disks. The virus locates itself in the unused header space of EXE programs.The virus starts deleting EXE programs when it runs out of COM programs to infect.WarrierA cold boot may be required after running an infected program.ShieldThe message "I greet you user. I am COM-CHILD..." sometimes appears.When active on Fridays before 3:00 P.M., the virus changes files to read-only. Contains the text "BRYANSK 1992, BITE 0.01 (C)".The virus damages infected programs by overwriting them with viral code. Contains the text 'FLOW LIKE A RIVER - STRIKE LIKE A THUNDER".TravellerInfected programs contain the text "Traveller (C) BUPT 1991.4..."Burger is a family of overwriting viruses based on source code published in a book.Infected programs contain the text "GS/02".Infected programs' size increases by 927 bytes. The virus uses the encryption system from the Cascade virus family, but is internally quite different.The virus overwrites a disk's boot record in an attempt to eliminate boot sector viruses. Infected programs contain the text "Virus Es en memoria!".When the virus is active in November or December after the 14th, the virus halts the computer. Contains the text "COMMAND.COM".BlackJack, Falling LettersWhen the virus is active from September through December of the years 1980 - 1988, the characters displayed fall into a pile at the bottom of the screen.17Y4, Jo-Jo, YapThe original 1701 and 1704 versions of this virus are widespread, therefore many minor variants exist. They differ little from the originals.FAT ChanceWhen active on January 15, April 15, and August 15, the virus plays a slot machine game and the message "CASINO DE MALTE JACKPOT..." appears. If you lose, your file allocation table is lost.Contains the text "Cry Havoc, and let slip the Dogs of War! [Catphish] FirstStrike Kraft!"Infected programs contain the text "EXECOMC:\COMMAND.COM CLEAN".No information available.Infected programs contain the text "***CCCP-75!***" and "DoomsDay".When the virus is active, a picture of a dog's head may be displayed in the upper left half of the screen, which eats its way to the right.The virus may disable extended memory, print the message "Sorry. I need MHz today! (CFSK)" and hang the machine.The virus changes an infected program's date and time stamp to 00-00-80 00:00. It may print a picture of a cartoon character peering over a wall with the text "WOT!! No Anti - Virus Software..."Faust, SpyerInfected boot records contain the text "Welcome to the New Dungeon", "Chaos", and "Letz be cool guys".Infected programs contain the text "COMEXESYSBAT ChCC".Checksum 1.00, CkSumA cold boot may be required after running an infected program.Files with COM extensions are infected when they are copied. Contains the text "CHEEBA Makes Ya High Harmlessly" and some profanity.No information available.When the virus is active, a hidden program named CINDEREL.LA is created, after a certain number of key presses. The virus can infect programs with or without file extensions.Proto-TInfected programs contain the text "Civil War, (c) 1992 Dark Helmet" and "*.COM".When an infected program is run, the message "EXEC failure" appears and then the DOS prompt returns.Infected programs contain the text "C:\IO.SYS C:\IBMBIO.COM" and "Close..."When the virus is active, the computer's screen clears unexpectedly.Worm 16850The virus creates a COM program with the same file name as an EXE program. The COM program is hidden from a normal directory listing.Infected programs' size increases by 572 bytes.VCLIf the virus cannot infect more files, the message "**CODE ZERO**" appears.Infected programs contain the text "Coffeeshop".ASP-472Infected programs contain the text "ASP".BomberThe virus builds a complex path of execution to its own code in order to avoid detection. Although polymorphic, the virus is not encrypted.Como-LakeInfected programs contain the text "...by a software group resident near Como Lake (North Italy)..."The virus creates a COM program with the same file name as an EXE program. The COM program is hidden from a normal directory listing.Syslock, 3551, 3555When the virus is active, the message "I want a COOKIE" sometimes appears.When a program is successfully infected, the message "COSSIGA ?! NO GRAZIE!..." appears.Infected programs contain the text "COSTEAU End.MZ".CPW.1459Contains the text "Esta programa fue hecho en Chile en 1992 por CPW". It avoids infecting, and may delete, specific antivirus products. A cold boot may be required after running an infected program.Chile,CPW.1527Contains the texts "CPW fue hecho en Chile en 1992" and "VIVA CHILE" in an encrypted form. Targets several antivirus programs.1193, CopyrightA false copyright message appears. The virus changes an infected program's date and time stamp.The virus creates COM files with the text "The Creepy Crawly".When active on Mondays the 28th and January 28th, the virus overwrites the hard disk with characters. Infected programs contain the text "Crazy Eddie".Crazy, ImpThe virus removes itself from infected programs when it is read into memory.Creeper TormentorThe virus searches for the text "Tormentor" in memory.2480, V2480, Crew-2480The message "European Cracking Crew" appears. The virus infects programs that have a date stamp of January through May, are larger than 10,240 bytes, and have COM extensions.The virus monitors for specific letters in the command line. If found it renames all files in the directory to "CRIMINAL" and prints a message calling the user a criminal guilty of software piracy.Krivmous, OnlyInfected programs contain the text "Only God knows!" The poem "There was a crooked man" may appear.MicroElephantWhen an infected program is run, the message "Bad Command or file name" appears and then the DOS prompt returns. Infected programs contain the text "Microelephant V4" and "by CSL".When the virus is active, the message "This file infected with COMVIRUS 1.0" appears.Nowhere Man, VMessiahWhen an infected program is run, the message "Out of memory" appears and then the DOS prompt returns.Infected programs contain the text "da,da". Infected programs over 65536 bytes in size do not run properly.Kennedy, Dead KennedyWhen active, the virus displays varying messages.A variant of the original Dark Avenger.1800 based on the author's source code, which he released in January of 1990.V-1800, EddieThe virus contains the message "Eddie Lives...somewhere in time". Randomly overwrites disk sectors.V2000, TravellerInfected programs contain the text "Copy me - I want to travel".V-2100Infected programs contain the text "Eddie Lives".When the virus is active on October 15th, the computer's screen clears if not in graphics mode, and data on drive C: is corrupted. Contains the text "(c) Dark End".Darth Vader 1-5Programs with COM extensions are infected only when they are copied. Infected programs do not run properly. Contains the text "Darth Vader".Infected programs' size increases by 1876 bytes.Columbus DayWhen the virus is active between October 13th and the end of the year, the messages "DATACRIME VIRUS" and "RELEASED: 1 MARCH 1989" appear.Datalock 1.00, V920, Datalock-1043Infected programs contain the text "DataLock version 1.00". If the date is after August 1990, the virus locks files with the .DBF extension.SYPIf the virus is active on a date divisible by 10, the data on the hard disk is destroyed.The virus corrupts data in files with the DBF extension. The FAT and root directory on drives D: through Z: are damaged when attempts are made to write to a DBF file that is more than three months old.The virus overwrites the first 80 sectors on drive C: and the message "DEICIDE! BYE BYE HARDDISK..." appears.Infected programs contain obscene text.On the 17th of any month, the virus replaces the master boot sector code so the message "DEMOLITION is here!" prints on the next boot up.When an infected program is run on Tuesdays, the message "Error eating drive C:" appears, and then the virus overwrites 160 sectors of the hard disk. The virus changes an infected program's date and time stamp.Destructor, Destructor V4.00Infected programs contain the text "DESTRUCTOR V4.00..."Mexican, Devil's Dance-BWhen the virus is active, screen colors may change after 2000 keystrokes. After 5000 keystrokes, the message "Have you ever danced with the devil..." appears.Kewl DewdzThe message "Kewl Dewdz!" appears. A cold boot may be required after running an infected program.1024When the virus is active on the hour, diamonds explode and bounce around the screen.A variant of the Diamond virus based on printed source code.Programs with COM and EXE extensions are overwritten with other code and do not function properly. Infected programs contain the text "C) DIGGER".When the virus is active at 9 P.M. the message "9pm" appears. A cold boot may be required after running an infected program.DirVirPrograms with COM extensions are infected when the DOS DIR command is used. The DOS CHKDSK program reports file allocation errors on a drive with infected programs.Creeping DeathChanges directory entries to point to itself. Using the "CHKDSK /F" command will destroy all program file linkage. Will not infect with DOS 4 or above.Creeping DeathChanges directory entries to point to itself. Using the "CHKDSK /F" command will destroy all program file linkage.No information available.The original sample contains a message from the author, "Annihilator" in Sweden. Later generations do not contain the message.A cold boot may be required after running an infected program. Infected programs contain the text "(C)1990 DM".Null Set, ScionThe virus may encrypt sectors on the current disk and display the message "Your disk is dead! Long live DOOMSDAY 1.0". The virus also contains a poem and says it was written in Orlando, Florida (USA) on 13MAY91.These viruses contain the message "DOOM II (C) Dr. Jones, NCU..." A cold boot may be required after running an infected program.B3When active on June 26th, the virus overwrites data on the hard disk.Dot Killer, 944, Point KillerWhen the virus is active, any period (.) entered from the keyboard is erased from the screen.The virus changes an infected program's date and time stamp. Letters on the screen may drop.Vienna, DOS-62, UnescoInfected programs contain the text "(C) DOCTOR QUMAK". A cold boot may be required after running an infected program.Dr WThe virus creates a file called C:\DRWATSON.COM and adds the line "@drwatson" to C:\AUTOEXEC.BAT. May display the message "Tracing mode has been destroyed".V-1385A cold boot may be required after running an infected program.1308When the virus infects files, lost clusters may occur on infected diskettes.Oi DudleyNo information available.When the virus is active, running programs from a write-protected disk results in the "write protect error".When an infected program is run, questions about the anatomy of the human ear appear.A virus based on Ear, but without the anatomy quiz.Infected programs contain obscene text.V-651The virus changes the seconds field in an infected program's time stamp to "62". Contains the text "Eddie lives".The virus only infects programs when they are copied. The virus changes the seconds field in an infected program's time stamp to "62".If a program with an EXE file extension is infected, the program is irreparably damaged. May format the drive and display the message "++ Hi! I am Eliza. Good Luck! ++".When the virus is active, characters entered from the keyboard are sometimes repeated. Contains the text "My name is Emmie, I am Eddie's sister."The virus infects programs when the DOS DIR command is used. The text "end of" will be found at the end of infected files.Contains the text "Enola Gay is now flying to SoftPanorama!" A cold boot may be required after running an infected program.The virus changes an infected program's date and time stamp. Running an infected program results in the error message "Exec failure" or "Bad command or file name".E.T.C.The virus changes an infected program's date and time stamp. Infected programs contain the text "E.T.C. VIRUS, Version 3.0, Copyright (c) 1989 by E.T.C. Co".Dutch 424When the is virus active in the year 1992, the message "Europe/92 4EVER!" appears.When active, the virus emits beeps.The virus places itself into the free space in EXE headers so infected files do not increase in size.Experiments-755Infected programs contain the text "----Small experiments path 2.1----".Frodo SoftInfected programs contain the text "(c) Frodo Soft".F-WordThe virus changes an infected program's date and time stamp.V337Infected programs' size increases by 337 bytes.Topo, Pisello, MosquitoThe virus infects all programs, except those run from drive A:. Function keys may not work properly. Contains encrypted text.384The virus uses the early DOS FCB methods of handling files. The virus changes an infected program's date and time stamp.The virus changes an infected program's date and time stamp. Infected programs contain the text "R.Feist".On Infected computers, the clock may return to a default date. Infected programs contain the text "PSQRVW".903, Fich, CHV 2.1Infected programs contain the text "FICHV 2.1 vous a Eu".The virus changes an infected program's date and time stamp to "8-17-88 2:08a".789When active on Friday, the virus hides files.No information available.Swedish 709Infected programs' size increases by 709 bytes.May attempt to print the message "Copyright 1992 by Fisher . PUNK-ROCK && BEER FOREVER".European Fish, StealthThe virus causes flickering of the screen. When the virus is resident, the computer's memory contains names of fish.The virus only infects programs that are larger than 500 bytes. When the virus is active after June 1990, the screen flickers at seven-minute intervals.OmicronWhen the virus is active between 16:00 and 16:59 on the second of any month, the screen may be "flipped" upside down.880When the virus is active on November 11th, the message "FLOWER..." appears.Infected programs contain the text "*.exe". The virus sometimes corrupts the data as it is written to disk.Infected programs contain the text "Freddy Krg". Infects COMMAND.COM in a way similar to the Lehigh virus.Freew-692When the virus is active in 1993, the message "Program terminated normally" appears. Contains the text "Freew".South African, Virus BWhen the virus is active on Friday the 13th, an infected program is deleted when it runs.4096, 4K, Century, Stealth, IDFWhen the virus is active on Sept. 22, the message "FRODO LIVES" appears. A cold boot may be required after running an infected program. Can corrupt data files. The virus does not function with DOS 4 or higher.Frog's AlleyWhen the virus is active on the 5th day of any month, the message "(V) AIDS R.2A-Welcome to Frog's Alley!,(c)STPII Laboratory-Jan1990" appears.TypoThe virus inserts typos that appear in the printout, but it does not affect the screen or data files.ZK 900, Death MarchThe virus plays a funeral march and then causes the computer to reboot. The virus changes an infected program's date and time stamp.When active on the 29th of any month, the virus overwrites a sector on the current drive. Infected programs contain the text "GEEK".Gergana II/IV/222/310/450/512/182BThe virus reinfects previously infected programs and destroys programs smaller than itself. The virus changes an infected program's date and time stamp.Prints "Runtime error 213" and hangs the computer. Contains several file names and the text "users.bbsfiles.bbs".The virus displays the names of the programs it has infected. May print a long message in German that starts "Dies ist ein Demonstrations-Computervirus !"A cold boot may be required after running an infected program. Infected programs contain the text "Glo" and "Virus 3 M.00".Grand YorkThe virus damages the sectors in boot and partition records.Contains a message in Russian.Infected programs contain the text "GOTCHA!"When the virus is active from January through June, it just spreads. From July through December, it interferes with printing functions, sends the contents of the screen to the printer, and creates a hidden file named "G OT YOU".Dutch 1039, 1012+27, 1039A cold boot may be required after running an infected program. Sometimes the message "GRAPJE!" appears.1575, 1577, 1591, FindAbout two months after initial infection, a green caterpillar may appear and move across the screen. The program's time and date stamp are changed.267+The virus increases file size by one byte with each infection.The virus corrupts data files. Contains encrypted text in German, including the phrase "Grune Partei der Schweiz".The virus changes an infected program's date and time stamp. When COMMAND.COM is infected, the computer will fail to boot. The message "Bad or Missing Command Interpreter" appears.When COMMAND.COM is infected the computer will fail to boot. When the virus is active, the message "Bad command or file name" appears, and then the DOS prompt returns.When the virus is active, the message "HA!" appears in large characters.The virus overwrites the hard disk.Hafen, HafenstrasseInfects EXE files and "drops" the Ambulance virus into COM files.The virus changes an infected program's date and time stamp. Infected programs contain the text "HAIFA VIRUS V1.12".The virus changes an infected program's date and time stamp. This is a variant of the Haifa virus.Hallo, HalloechenThe virus infects programs larger than 5120 bytes. It does not infect programs with a date other than the current month or year. Keyboard input appears garbled.Happy HalloweenWhen active on October 31st, the virus creates a 10,000 byte file with no file name. The error message "Runtime error 150 at 0000:0AC8" appears.When the virus is active, the message "Thank you for running the Happy virus..." appears. The virus changes an infected program's date and time stamp.Happy New Year, Nina-2Fails to correctly infect COMMAND.COM in some DOS versions causing boot failures. Contains the message "Dear Nina, you make me write this virus; Happy new year!"When the virus is active, the message "Your PC is alive and infected with the Harakiri virus!" appears.HaryWhen the virus is active, the message "WeLcOmE tO hArY aNtO" appears. The virus changes an infected program's date and time stamp.KlaerenThe virus cannot infect files larger than 4096 bytes. Infected programs contain the text "Klaeren..."May type the message "Headcrash Industries celebrate 001F hex".1376Infected programs contain the text "HELLWEEN???!!"HellraiserWhen the virus is active, programs smaller than 65536 bytes return to the DOS prompt. The message "Program too big to fit in memory" appears.923When the virus is active, the message "Hey, YOU!!..." appears, and then the DOS prompt returns.Gomb, GMBInfected programs contain the encrypted text "HARD HIT && HEAVY HATE the HUMANS".The virus changes an infected program's date and time stamp. Contains the text "Hi".The message "Hi! boy. Do you know 'hide-and-seek'?..." appears.When the virus is active on the 29th of any month, the message "Highlander 1 RULES!" appears 21 times. A cold boot may be required after running an infected program.When the virus infects COMMAND.COM, the theme song from the Hitchcock TV program is played five to ten minutes after the computer starts up.No information available.May display the message "This is HORROR!" and erase sectors on the hard drive. A cold boot may be required after running an infected program.Naughty HackerThe virus scrolls the screen and emits a buzzing noise. Pressing keys produces a clicking noise. Contains the text "Sophia" and "(c) Naughty Hacker."Infected programs do not function properly and then the DOS prompt returns. Infected programs contain the text "*HOUSEVIRUS*".HungarianWhen the virus is active on November 7th, the message "Format ..." appears, and then the hard disk is formatted.The message "HYDRA..." appears. The virus changes an infected program's date and time stamp. May delete COMMAND.COM or EXE files.When the month and day number are the same (1/1, 2/2, etc) the virus destroys the hard drive boot sector, plays music, and displays boxes with the message "USSR ViruSoft (c) v1. 1990".1 in 10When the virus infects a program on a 10MB hard drive, it marks one unused FAT entry as bad.IerThe virus changes an infected program's date and time stamp. The message "Mulier pulchra est... St. Ieronim" appears.The virus changes an infected program's date and time stamp. The message "Mulier pulchra est... St. Ieronim" appears.When the virus is active, the message "DON'T COPY IT and now ... I AM ILL!!" appears and beeps are emitted.The virus changes an infected program's date and time stamp. Infected programs contain the text "INCOM".No information available.Every third infection displays a message in Russian. A cold boot may be required after running an infected program.No information available.Infected programs' size increases by 160 bytes.The virus will infect only under DOS 3.3. Corrupts COMMAND.COM.LabelThe virus infects programs with the COM extension when they are accessed using the DOS DIR command. Infected programs contain the text "Int 13".1381, Internal ErrorWhen the virus is active 90 days after the original infection date, the screen information is garbled and the message "INTERNAL ERROR 02CH..." appears.Searches directory trees on all logical drives for EXE files to infect. Contains the text "\*.EXE". A cold boot may be required after running an infected program.Invol, vansiOn the 19th of any month the virus, the virus will destroy the FAT on the C: drive and display a message thanking the user for his or her "involuntary cooperation."Ionki 231The virus changes an infected program's date and time stamp. May print a message in Russian.Infected programs contain the text "????????COM" and "IPER".August 16thInfected programs contain the text "=!= IRON MAIDEN". After August 16th, 1990 the virus may erase two random disk sectors.3880After being active for 24 hours, the virus overwrites the boot record.Itti-AThe message "EXEC failure" appears, and then the DOS prompt returns. A cold boot may be required after running an infected program.BubblesThe messages "Bubbles Virus" and "[IVP]" appear.JW2The message "BEWARE THE JABBERWOCKY!" appears.Christmas in JapanWhen the virus is active on December 25th, the message "A merry christmas to you" appears.The virus changes an infected program's date and time stamp.June 7Infected programs contain the text "Jeff is visiting your hard disk."The non-standard Jerusalem viruses are resident infectors of COM and EXE programs.PLO, Israeli, Friday 13th, 1813When the virus is active on Friday the 13th, running programs are deleted. After 30 minutes the computer slows down and the screen scrolls up two lines.Captain TripsThe virus plays tricks with the screen display.Frere JacquesWhen the virus attempts to infect programs, the computer simply stops and data is lost. When the virus is active on Friday the 13th, the virus plays the "Frere Jacques" tune.Jeru.AntiCAD.4096.BMay play music and display the message "by Invader, Feng Chia U., Warning: Don't run AC".Anti-CAD, Taiwan, Invader, PlastiqueThe virus targets the AutoCAD program. It activates when ACAD.EXE is running or when Ctrl+Alt+Del is pressed. The virus overwrites data on floppy disks and hard disks and garbles the CMOS information.2080, 2086, Fu ManchuWhen the virus is active and you press Ctrl+Alt+Del, the message "The world will hear from me again!" teletypes across the screen before the computer reboots.Moctezumas Revenge, CiudadoWhen COMMAND.COM is infected, boot failures occur. The virus may infect DOS hidden system files.MummyVariants contain a version number and the encrypted text "Kaohsiung Senior School Tzeng Jao Ming presents". A cold boot may be required after running an infected program.PcVrsDs, PCVWhen the virus is active on Monday the 23rd of any month, the virus formats the beginning of the hard disk and deletes programs when they are accessed.Jerusalem.SundayInfected programs contain the text "Today is SunDay! Why do you work so hard?..." This message is never displayed due to a bug in the virus.Argentina, Suriv 1, April 1.COMWhen the virus is active on April 1st, the message "APRIL 1ST HA HA HA YOU HAVE A VIRUS" appears.April 1.EXE, Suriv 2When the virus is active on April 1st, the message "APRIL 1ST HA HA HA YOU HAVE A VIRUS" appears.Jerusalem, Israeli, SurivWhen an infected program is run on Friday the 13th, a black window appears within 30 seconds.Jeru.Zerotime.AustralianMay cause the system to slow down. A cold boot may be required after running an infected program.Something, Water, 621When the virus is active on Friday the 13th, the message "Something wonderful has happened, your PC is alive..." appears.WabikThe virus overwrites EXE programs, and silly messages like "Water detect in Co-processor..." appear.Joker 2The virus infects programs smaller than 9000 bytes. A cold boot may be required after running an infected program.Infected programs contain the text "Release date 12-22-1990..." The virus only infects programs when they are run.The virus infects programs larger than 1201 bytes. When the virus is active on July 13th of any year, a bouncing ball appears.Pretoria, JuneWhen the virus is active on June 16th, the virus changes all the root directory entries to "ZAPPED".Infected programs contain the text "Jr".Contains the text "AND JUSTICE FOR ALL" A cold boot may be required after running an infected program.When the virus is active, the message "VDV 91" appears. Infected programs contain the text "I don't like mondays..."KamikazeInfected programs contain the text "kamikaze". A cold boot may be required after running an infected program.Campana, Telecom, TelephonicaInfected programs contain encrypted text complaining about high telephone rates and bad service in Spain including the text "(C) 1990 Grupo Holokausto". The virus drops the Kampana boot virus.RedstarWhen the virus is active on October 23rd, the message "Karin hat GERBURTSTAG" appears.May print a garbled message ending with the clear text "- 4 KELA".USSR, V257The virus changes an infected program's date and time stamp. The message "????????COM Path not found" appears.Turku, TwinsAfter the virus is active for 30 minutes, keystrokes are repeated. The text "OOOOOOOOOOOOOOOO" appears and beeps are emitted.Turku, Samsoft, Saddam, MubarkAfter the virus is active for 30 minutes, keystrokes are repeated. The text "OOOOOOOOOOOOOOOO" appears and beeps are emitted. Variants of the original contain various text messages.Keyboard Bug, KBD Bug, KeyBug 1596The virus interferes with keyboard input. A cold boot may be required after the DOS COPY command is used.483, Keiv 483Infected programs contain the text "Kiev 1990".When the virus is active on Friday the 11th, the message "Sam Kinnison 1954-1992..." appears. The virus interferes with keyboard functions.Infected programs contain the text "Copyright 1991-1999.KIT VIRUS (version 2.0)".Kiwi 550Infected programs contain the text "I'm KIWI-586.(C) Vegetable-Soft.DOS AIDSTESTP".KLF-356Infected programs contain the text "KLF" and "The KLF3".May corrupt COM files it tries to infect. Contains the text "Ko".The message "-=+ Kode4 +=-, The one and ONLY!" appears.An overwriting version ot the Kode4 virus.Dr Qumak IIContains an encrypted message, including the text "IT IS DOCTOR QUMAK II!"Attempts to run programs from a write-protected disk result in write protect errors. When the virus is active on May 20th of any year, the message "Today is my birthday" appears.TurboThe virus changes an infected program's date and time stamp. Infected COMMAND.COMs will not function. When the "Print Screen" key is pressed it displays the message "Turbo Kukac".Kuku-448The message "Kuku!" appears in colorful boxes all over the screen.Infected programs contain the text "Larry on a Screen".No information available.The virus changes an infected program's date and time stamp. A cold boot may be required after running an infected program. Contains the text "[ lazy ]".USSR-516Infected programs' size increases by 516 bytes. The virus does not modify the host file beginning as other viruses do. It redirects execution to itself later in the host.Leech2, ToplerThe virus infects programs larger than 10240 bytes. When it infects programs with a time stamp of 12:00, the time disappears.Lehigh UniversityThe virus only infects COMMAND.COM. After four infections, it overwrites the first 32 sectors of the hard disk.SovWhen the virus is active on Friday the 13th, the message "That could be a crash, crash, crash!" appears.News Flash, Leprosy 1.00When the virus is active, the following message appears "NEWS FLASH!! ...infected with LEPROSY 1.00..."The virus changes an infected program's date and time stamp. The error messages "Exec failure" and "Too many files open" appear.Tormentor 205The virus changes an infected program's date and time stamp. The error messages "Exec failure" and "Too many files open" appear.No information available.MysticThe virus changes an infected program's date and time stamp. Infected programs contain the text "-MYSTIC-COPYRIGHT (C) 1989-2000..." and "SsAsMsUsEsL".Infected programs contain the text "(C)Rom1Soft(LipPI)1991".Little GirlSometimes the following message appears: "File was destroyed by virus Little girl ver 2.00". Attempts to run programs from a write-protected disk may result in write protect errors.Infected programs contain the text "Little Brother" and "EXE COM".Little PiecesWhen the virus is active, the following message appears: "One of these days I'm going to cut you into little pieces".MerdeA cold boot may be required after running an infected program. Contains the text "Loki".No information available.Reboot PatcherThe time stamp on some infected programs disappears. The virus may modify programs so that they reboot the system when run.The virus may modify EXE programs in such a way that running them will erase sectors on the hard drive. Contains the text "LoveChild in reward for software sealing". Note that "stealing" is misspelled.Lowercase, LCVInfected programs' size increases by 864 bytes.The virus changes an infected program's date and time stamp. It interferes with printing.Infected programs contain the text "*.COM".The virus only infects COMMAND.COM and changes the program's date and time stamp. May play a series of beeps.LyceeThe time stamp on some infected programs disappears or is changed to 00.LyceeThe time stamp on some infected programs disappears or is changed to 00. After a period of no keyboard activity the virus a red box on the screen with a Russian message that ends "133-20-60".When the virus is active, the message "MacedoniaToTheMacedonians" appears.334The virus changes an infected program's date and time stamp. Contains the text "Made in England".The virus infects all programs with the EXE extension. The message "Madismo Strikes Again!" appears and the virus changes the program's date and time stamp.Infected programs' size increases by 323 to 491 bytes.No information available.2560Infected programs' size increases by 2048 to 2560 bytes.MagnitogorskInfected programs contain a derogatory message to a known antivirus writer. The virus infects programs larger than 2048 bytes.In addition to infecting programs when they are accessed or run, this virus infects programs when they are accessed using the DOS DIR command.Infected programs contain the text "Welcome into the virus..."Malign-575In addition to infecting programs when they are accessed or run, this virus infects files when they are accessed using the DOS DIR command. The virus changes the seconds field in an infected program's time stamp to "01".Maltese AmoebaWhen the virus is active on March 15th and November 1st, the first four records of the hard drive are overwritten. Infected programs contain a poem and a message about the University of Malta.The virus interferes with printing.Infected programs contain the text "Soy un Manuel Virus de tipo C".When active on February 2nd, the virus overwrites all programs in the current directory the with the text "= [Marauder] 1992..."Infected programs contain the text "MATURA '92".Jews2When active, the virus emits a static-like sound. At 30 seconds to the hour, it plays music and beeps. Contains the text "Jews-2 Virus. MSU 1991".An infected program's time stamp disappears. A cold boot may be required after running an infected program.GuruInfected programs contain the text "Software Failure. Task Held. Guru Meditation #456789:#34567?????"No information available.A cold boot may be required after running an infected program.The virus changes an infected program's date and time stamp. Sometimes the message "????????COM Path not found" appears.The virus sometimes displays a bouncing ball.The virus changes an infected program's date and time stamp. It remains resident in the first memory segment, so total available memory is not affected.Infected programs contain text saying the virus was written by Cracker Jack, in Milan, Italy.TrivialThe virus changes an infected program's date and time stamp.The virus changes an infected program's date and time stamp.The virus may corrupt the data in dBase files with the extension DBF.Occasionally the virus displays a mirror image of what was previously on the screen.LockUp, LK, Mithrandir IIIThe virus changes an infected program's date and time stamp to 24MAR23 2:17a.The virus alters output to the printer and the NumLock key, and may display a bouncing ball.Ghost-1447The virus changes an infected program's date stamp to 13JUL82. Contains the text "MINSK GHOST,1991".08/15, Many FingersWhen the virus is active after November 11th, 1990, the following message appears: "CRITICAL ERROR 08/15: TOO MANY FINGERS ON THE KEYBOARD ERROR".1063On computers with monochrome monitors that have 80-column and 25-line displays, the virus deletes files when infected programs are run.Agiplan, Agi-planThe virus starts corrupting data after being active for several months. May display the message "Load error" and contains code to erase data on all disk drives.The virus changes an infected program's date and time stamp. Infected programs contain the text "(C) MPS-OPC 1991 v#.#".Infected programs contain the text "Mr.Virus Ver. 1.10".The virus changes an infected program's date and time stamp. The virus causes reboots.PalestinianThe virus changes an infected program's date and time stamp. Contains a political message.Overwrites all EXE files in the current directory and may corrupt the C: drive. Displays the message "The Midnight Serial Killer is roaming in your computer...Beware! [JD]".Infected programs contain the text "This program was written in MSTUm 1990".Mutation Engine, DAMEThe MtE (Mutation Engine) is an encryption technique used by virus writers to make a virus polymorphic. Polymorphic viruses make detection more difficult.MFaceAttempts to run programs from a write-protected disk result in write protect errors. When the virus is active, multiple smiley faces sometimes appear.The virus contains two of the Tiny viruses and may release them. Contains the text "MultiVirus(R), Release 1.0". The virus changes an infected program's date and time stamp.When active, the virus displays multiple messages. A cold boot may be required after running an infected program. Infected computers may experience boot failures.A group of viruses based on released source code. Most variants contain messages and some display them.PatriciaContains a message to virus researcher Patricia Hoffman.Arka, ArkanoidA cold boot may be required after running an infected program. Infected programs contain the text "THE MVF-FILEVIRUS..."Contains the text "MX".Contains the text "*.COM Nazgul". A cold boot may be required after running an infected program.The virus changes an infected program's date and time stamp. The message "PARITY ERROR ADDR (HEX)..." appears. A cold boot may be required after running an infected program.1963, OverwriteInfected programs' size increases by 1963 bytes.GnoseWhen active on November 21st, the virus beeps and displays a message. The message includes the phrase "Happy Birthday, Necros!"Infected programs contain the text "Nina".The virus interferes with printing by changing 0 to 9, 8 to 1, etc.Infected programs contain the text "Mutant Ninja Version 2.0..."A cold boot may be required after running an infected program. In addition to infecting programs when they are accessed or run, this virus infects files when they are accessed using the DOS DIR command.1024-B, NomenThe virus corrupts data and programs by swapping FAT entries. Contains the word "Nomenklatura".Milous, CadkillAt noon the virus beeps 6 times. Contains the text "byMH&&MHsoftware" in an encrypted form.Infected programs' size increases by 586 bytes.855, November 17thInfected programs contain the text "SCAN.CLEAN.COMEXE". When the virus is active on November 17th, the virus overwrites the hard disk.440When the virus is active between January 01, 1980 and September 30, 1980, the message "No Bock today error. System halted" appears. A cold boot may be required after running an infected program.Evil GeniusWhen the virus is active on the 18th of any month, the hard disk is overwritten. Contains the text "Evil Genius V2.0".The virus changes an infected program's date and time stamp. The message "This file Has Been Infected by Number One! XXXXXXXX.COMinfected" appears.The virus changes an infected program's date and time stamp. Contains the encrypted text "(c)Nygus v2.0".1961, Yankee 2, BanditzThe virus plays the "Yankee Doodle" tune after infecting a program.Reset, Friday-13th-440When the virus is active on Friday the 13th, an omega symbol appears, and then the hard disk is overwritten.4915A cold boot may be required after running an infected program. Infected programs contain the text "ondra.dat".Attempts to avoid detection by toggling a bit in the decryptor on each infection.Infected programs' size increases by 696.Infected programs contain the text "Orion System".MusicSometimes the virus plays three melodies repeatedly.When the virus is active on Friday the 13th, running programs are deleted.Otto6Infected programs contain the text "OTTO6 VIRUS..."May print a message in Russian.Infected programs' size increases by 1589 bytes. There is a large block of zero byte "padding" near the end of the virus.TCCThe virus may modify the starting cluster on files, making them useless. An infected COMMAND.COM may not run. Contains the text "IBMBIO COMIBMDOS COMAUTOEXECBATCOMMAND COMSYSEXECOM".Generic 1When the virus is active, the message "PARITY CHECK 2" appears. A cold boot may be required after running an infected program.Pascal 3072Infected programs' size increases by 3072 to 3199 bytes.Pascal 7808Infected programs' size increases by 7808 bytes.VHP-547, Vienna-547A cold boot may be required after running an infected program. Random characters may appear.The virus finds a program, renames it to PATHHUNT, infects it, and then returns the original file name. May damage DBF files.FluA cold boot may be required after an infected program is run.Flu-2There are a group of polymorphic viruses based on PC-FLU.1677, Plaice, PC Byte BanditThe virus changes an infected program's date and time stamp. Infected programs contain the text "PCBB". A cold boot may be required after running an infected program.The virus attacks the Central Point AntiVirus product by deleting a critical file. Sometimes a reboot occurs.Sorry, G-VirusThe virus may ask a question, and if the answer is not "4711", the program will not run.Sorry, G-VirusInfected programs from the Perfume.Sorry variant contain the text "G-Virus".Beta, CloudInfected programs' size increases by 1117 to 1168 bytes. Contains an encrypted poem.When the virus is active, the message "The PHANTOM Was HERE-Sorry..." appears. The virus may shift the image to the middle of the screen.Live After DeathOne out of 256 infections that result in FAT entries being swapped.Infected programs contain the text "PIF-PAF B v1.0 Nincs kegyelem!"After the virus is active for 15 to 30 minutes, a high-pitched noise is emitted.Polish 529Infected programs' size increases by 529 bytes.Amstrad, Cancer, Polish PixelThe virus changes an infected program's date and time stamp. Infected programs contain the text "=!= Program sick error:Call doctor or buy Pixel cure description".Play TetrisInfected programs contain the text "PLAY TETRIS, HI-HI-HI..."New 800The DOS CHKDSK program reports file allocation errors on all infected programs. Infected programs contain the text "(c) Damage inc. Ver #.#,Plovdiv,1991".Polish TinyAfter the virus infects a program, the DOS prompt returns. The virus changes an infected program's date and time stamp.No information available.Infected programs contain the text "pLuTto_B".Infected programs' size increases by 1,919 bytes.No information available.When the virus is active, the message "A le' jobb kazetta a POLIMER kazetta! Vegye ezt!" appears.Polish TinyAfter the virus infects a program, the DOS prompt returns. The virusAfter the virus is active for 15 to 20 minutes, a program may be erased when run. Infected programs contain the text "POSSESSED! Bwa! ha! ha! ha! ha!..."No information available.The Backtime virus causes the computer clock to run backwards. Contains the text "BackTime".The Blinker virus causes the screen to blink. Contains the text "Joker".A variant of BackTime that contains the text "Joker".Sometimes the Shaker virus causes the screen display to "shake". Contains the text "Shaker".When the virus is active on Fridays between 10:00am and 11:00am, the virus changes file names to 'PREGNANT' if they are accessed using the DOS DIR command. Infected programs with the time stamp of 12:00a are erased.When the virus is active, the message "Press any key" appears.When an infected program is run, a reboot occurs. Infected programs contain the text "Prime Evil! (C) Spellbound, Line Noise 1992".The virus interferes with printing. Infected programs contain the text "PrintMonster30".In addition to infecting programs when they are accessed or run, this virus infects files when they are copied. Contains the text "THIS IS YOUR PROBLEM !"Contains the text "File protection". May disable the mouse driver. A cold boot may be required after running an infected program.Infected programs contain the text "[PROTO-T by Dumbco, INC.]". A cold boot may be required after running an infected program.1024PrScr, Print ScreenWhen the virus is active, pressing the PrtScr key displays CMOS information on the screen instead of sending the screen display to the printer.1210When the virus is active on May 1st through May 4th, the virus interferes with disk writes, so that data is not saved to the disk.The PS-MPC family of viruses are generated by a virus production utility.No information available.QQ-1513The virus changes an infected program's date and time stamp. Infected programs contain the text "Bad command or file name".The virus causes the screen display to "shake".Infected programs contain the text "t=1024 /write=off /win /quiet".Dutch 555The virus changes an infected program's date and time stamp.The message "Pray for death-RABID '91" appears.R10When the virus is active, the hard drive is overwritten with 0FFh bytes starting at sector 0. The DOS CHKDSK program reports file allocation errors on all infected programs.Zodiac, R11, LOLWhen the virus is active, the hard drive is overwritten with 0FFh bytes starting at sector 0. The DOS CHKDSK program reports file allocation errors on all infected programs.When the virus is active after the 12th of the month and the time is 5 P.M., sometimes the hard drive boot record is formatted and messages in German appear.A cold boot may be required after running an infected program. Infected programs contain the text "891221".The virus displays a message in Polish.Fake VirXWhen the virus is active on Friday the 13th, the message "VirX 3/90" appears. A cold boot may be required after running an infected program.Joe's Demise, LaterInfected programs contain the text "This program requires MS-DOS 3.00 or later".777, Revenge AttackerWhen the virus is active after all files in the current directory have been infected, the virus overwrites the hard drive and displays 7's on the screen. Infected programs contain the text "777- Revenge Attacker V1.01".A cold boot may be required after running an infected program. The virus creates zero-byte files in the current directory.When active, the virus emits beeps.Beeper, Russian Mirror, USSRThe virus overwrites the hard disk in a way that causes an "Invalid drive specification" error message. When infected programs are run, a beep noise is emitted.The virus infects programs when they are copied.Infected programs' size increases by 1710 to 1725 bytes. Contains the text "(C) Dialogue, Rust. 1990".Infected programs contain the text "!!RYAZAN."No information available.MLTIThe virus changes an infected program's date and time stamp. Infected programs contain the text "(C) 1990 RED DIAVOLYATA".Infected programs contain the text "CopyRight by Vadim V.N.1989."A cold boot may be required after running an infected program. Sometimes the error message "Too many files open" appears.The virus adds about 3480 bytes to infected files plus a polymorphic decryption routine that ranges in length from about 350 to 1500 bytes. Adds 100 years to file date. Contains the encrypted text "Satan Bug virus".When the virus is active on Saturday the 14th, the virus overwrites the C: drive, B: drive, and the A: drive.No information available.Ontario.1024, SBCInfected programs' size increases by 1024 bytes. The virus is based on the Ontario.512 virus, but with full stealth and polymorphism added.V-1014Infected programs' size increases by 1014 bytes.Infected programs contain the text "Screaming Fist".V-948The virus overwrites COMMAND.COM when infecting it, making it invalid.The virus changes an infected program's date and time stamp.The virus changes an infected program's date and time stamp. The virus cannot infect files smaller than itself, but the data in these files can be corrupted.When the virus is active for 60 minutes, a multi-colored screen is displayed. Infected programs contain the text "S E M T E X..."Infected programs contain the text "...(c) 1990 by Sentinel".Infected programs contain the text "[Shadow]..."Infected programs contain the text "!seviL etybwodahS".Infected programs simply stop after displaying the message "Shake well before use !"When the virus is active, the message "...SHHS The BOOT SECTOR Infector..." appears.Infected program size increases by 6672 bytes.Infected programs contain the text "IWANTSHIRLEY..."The virus corrupts the files it infects. Contains code that will not run on older microprocessors.Infected programs contain the text "Signs Of Life".The virus clears the monitor, draws a face and causes the message "Hello, I'm Silly Willy!-..." or "ERROR: No SYSTEM found!" to appear.No information available.The infected program simply stops after displaying the message "ALIVE...Your system is infected by the SIMULATION virus..." This virus contains messages from four other viruses.No information available.A cold boot may be required after running an infected program.The virus causes a bouncing ball to appear when some programs or BAT files run. A cold boot may be required after running an infected program. Contains the text "Sistor && Co".The virus changes an infected program's date and time stamp. When active, the virus moves text around the screen.NV71Once the virus is active, it plays the "Silent Night" tune.The following message appears "SLOVAKIA virus version #.##...type the word SLOVAKIA:".When the virus is active, smiley faces appear and bounce around the screen. Contains the text "OVFyANKEE Doodle#and VACsin."The virus changes an infected program's date and time stamp. Contains the text "Socha".When the virus is active on Friday the 13th, the message "Something wonderful has happened, your PC is alive" appears.An infected program's time stamp is missing when the file is accessed using the DOS DIR command. Infected programs contain the text "INFECTED! *SPANZ*".The virus changes an infected program's date and time stamp.Contains the text "Nguyen Van Cuong". Infected programs' size increases by 852 bytes.When the virus is active, the program SCAN.EXE is run, the program is erased and the DOS prompt returns. The virus changes an infected program's date and time stamp. The virus also squeaks.Tiny HunterWhen the virus is active, programs that contain more than 340 bytes of hex "00" characters are reinfected.When infected programs run, the following message appears: "The program has been infected by:...By STAF..."Infected programs contain the text "Ich bin da!"A cold boot may be required after running an infected program.When the virus is active on February 13th at 1 P.M. or later, random data is written to all drives (starting with drive Z:), and the last two bytes in the file are "*.".The virus modifies the partition table in the master boot sector. It infects COM and EXE files. May beep continuously while replacing characters on the screen with dots. Contains the encrypted text >STARSHIP_1<".When the virus is active, the seconds field in an infected program's time stamp is changed to "42". The message "Stasi is watching you" appears.The virus only activates on 286 computers and above. May display a message containing the word "StinkFoot".TatouWhen the virus is active, the seconds field in an infected program's time stamp is changed to "62".QD335Infected programs contain the text "Striker #1".The virus infects all programs with the COM extension in the root directory of the C: drive. Contains the text "STSV".Do Nothing, SadamThe computer halts when the virus attempts to infect it. May overwrite sectors on the hard drive.1008Infects COMMAND.COM immediately and other files randomly. The computer may halt if booted from an infected COMMAND.COM.JerkThe virus infects programs with EXE extensions that are smaller than 65536 bytes. The message "...calls himself SUPERHACKER..." appears.JewsInfected programs contain the text "Jews NEVER surrender!"May delete a file rather than infect it. Contains the text "Susan".A cold boot may be required after running an infected program. Infected programs contain the text "(c) 1990 by SVC, Vers.#".The virus changes an infected program's date and time stamp. The virus only infects files on the A: drive. Contains the text "a:*.*".When the virus is active on December 25th, the following message appears: "TERMINATOR 1991. Made by SVS-009".Why Windows, Data Molester, HeadacheWhen the virus is active in February, it attempts to delete AUTOEXEC.BAT and CONFIG.SYS and corrupt the hard disk.The DOS CHKDSK program reports file allocation errors on all infected programs. Infected programs contain the text "Phnix".The virus changes an infected program's date and time stamp. Files smaller than the virus are corrupted.Holland GirlInfected programs contain the text "This program is infected by a HARMLESS text-Virus V2.1..."The virus will not infect programs if the environment contains "SYSLOCK=@".Sometimes the message "TABULERO" appears. Infected programs contain the text "pTpApBpUpLpEpRpOp..."The message "Hello, I am virus" appears. A cold boot may be required after running an infected program. The virus corrupts the infected file.When the virus is active on the 8th day of any month, the virus overwrites the first 160 sectors of drives C: and D:, resulting in the loss of the boot record and root directory.The virus avoids the system COM files. Contains the text "Tankard".May display the word "TECHNO" repeatedly across the screen while playing a tune. If a key is pressed the phrase "Don't touch the keyboard" is displayed and the virus goes back to printing "TECHNO".Valert (1554)When the virus is activated from September through December, the first ten characters written to disk are replaced with garbage characters.When the virus is active four months after initial infection, a graphic and message are displayed. If the message instructions are followed, "author credits" are displayed.1501, 918Infected programs contain the text "Terminator Attack Now". May display this message and overwrite disk sectors.2294Infected programs contain the encrypted text "TERMINATOR". May display this message and erase the CMOS and overwrite disk sectors.526The virus changes an infected program's date and time stamp. On December 25th it displays the text "TERMINATOR 1991. Made by SVS-009."Infected programs contain the text "Terror".The virus changes an infected program's date and time stamp. The virus displays a message requiring a response.When active, the virus overwrites programs. Contains the text "The Rat, Sophia".1253, V-1When the virus is active on December 24th, it overwrites floppy disks with program fragments.CDWhen the virus is active on Thursday the 12th, a window appears warning that the next day is Friday the 13th.Infected programs' size increases by 109 bytes.Infected programs' size increases by 1062 to 1098 bytes.Many variants of the virus have appeared based on published source code. When booted from an infected COMMAND.COM, the computer may halt.2330No information available.The virus changes an infected program's date and time stamp.When COMMAND.COM is infected, boot failures occur. Infected programs contain the text "*.com".Infected programs' size increases by 129 bytes.May display the message "I think you're tired to the bone. You'd better go home." Infected programs' size increases by 1740 to 1771 bytes.1993Infected programs contain the text "COMSPEC=(C)Todor..."Contains the text "I am the virus x". A cold boot may be required after running an infected program.The virus changes an infected program's date and time stamp. The computer halts when the virus attempts to infect a program.On the first day of any month, programs having names that begin with "B" are infected. On the second day programs having names that begin with "C" are infected and so on until the end of the month.Coffee shop, GirafeThe TPE (Trident Polymorphic Engine) is not a virus, but an object file that virus authors can link to their own code, making the new virus polymorphic.The virus changes an infected program's date and time stamp. Sometimes the message "Find me!" appears.After the virus is active for one hour, it produces a cascading text effect.SignedMay overwrite disk sectors and display "ThereCanBeOnlyOne .....Signed -Traveling Jack-E", the "J" in jack being a square root symbol.Sometimes the screen is cleared, then the following message appears: "-=>T.R.E.M.O.R was done by NEUROBASHER...", and then everything returns to normal. The virus disables the antivirus program that is included with MS-DOS 6.Zit.###, MinimalInfected programs are overwritten with viral code.When the virus is active, sometimes characters typed from the keyboard do not appear on the screen. Files for output to disk may not get written to disk. Infected programs contain the text "The Troi Virus".Infected programs contain the text ">>>Troi Two-->".The virus infects programs larger than 8k. Infected programs contain the word "Tu".Tula-419The virus changes an infected program's date and time stamp. Infected programs contain the text "Tula 1990.Sat".Infected programs contain obscene text.The virus can produce graphics and music. The virus changes an infected program's date and time stamp.RPVSInfected programs contain the text "TUQRPVS".Ontario-730Infected programs contain the text "!=TVu."The virus creates hidden COM files. When active, the virus further "hides" these infected files from utilities that can display hidden files.Infected programs contain the text "*.com". May erase FAT on the current disk.The virus changes an infected program's date and time stamp. Infected programs contain the text "Come On, no. 51, You Time is up" and "Ungame(C)Dr".A cold boot may be required after running an infected program. Infected programs contain the text "C:SYSTEM\COMMAND.COMMMAND.COM".Uruguay is a family of highly polymorphic "test" viruses. When the viruses are active sometimes the message "'Uruguay #' Virus..." appears and then tones are emitted.A cold boot may be required after running an infected program. Infected programs contain the text "V 1.0 Igor,1992 The Uruk-hai are upon you!"Infected programs' size increases by 707 bytes. Works only under DOS 3.30.1260, CasperInfected programs contain code to prevent detection. V2PX are polymorphic Vienna viruses.1260, CasperThe virus contains code to prevent detection.TP##VIRIf the virus finds an old version of itself, it reinfects the program with the newer version. The virus changes an infected program's date and time stamp. The virus version number is found at the end of the infected file.May play a tune. Contains the text "GCSBRO" and "ROMANIAN VAMPIRUS".SlayerThe virus is written in compiled BASIC. The text "BASRUN" and "BRUN..." appear in the virus.VCL is a group of simple viruses created with a menu-based program called the Virus Construction Lab. Of the samples that come with the lab, only one works.Polish 637The virus changes a disk write to a disk read.MantaThe VCS viruses are mediocre infectors of COM programs created with a program called the Virus Construction Set. The viruses delete the AUTOEXEC.BAT and the CONFIG.SYS files.The virus changes the seconds field in an infected program's time stamp to "56". Infected programs contain the text "***Vengeance is ours!***".Happy DayThe following message appears "HELLO!!! HAPPY DAY and SUCCESS from virus 1.1 VFSI-Svistov".When the virus is active on Wednesdays, all programs with COM and EXE extensions are infected at the same time. Infected programs contain the text "Victor V1.0 The incredible High Performance Virus".VHP, WienThe virus changes the seconds field in an infected program's time stamp to "62". Many variants exist due to published source code.ViolatorInfected programs contain the text "Activation Date: 08/15/90-Violator Strain B..."ToothlessThe virus changes the month field in an infected program's date stamp to "13".CrossInfected programs contain the text "V*I*N*D*I*C*A*T*O*R*1".If a program's size before infection is less than 3840 bytes, its size after infection is 7678. Infected programs contain the text "VIOLETTA".The virus displays several messages beginning with "VirDem Ver.:1.06 (Generation #) aktive..."The message "Infected" appears when an infected program is run. The virus only infects programs on the A: and B: drives.The virus infects COMMAND.COM as the Lehigh virus does. Contains encrypted text that the virus checks for modifications.Does not function on most machines. When Ctrl+Alt+Del is pressed it displays a message in Russian.ACDC, PoemWhen the virus is active on December 21st, a poem appears, and the C: drive is overwritten.No information available.Infected programs contain the text "Voronezh,1990 2.01".When the virus is active, the computer halts when a BAT file or DOS command is run. The virus displays a message telling the user to vote.The hex string '4503EB1808655650' appears near the beginning and the end of infected programs.The virus displays "Something's coming up...", then a high-pitched noise is emitted and the following message appears: "Vriest of g greets Vic ear Moeli".Infected programs contain the text "VVF 3.4".When the virus is active, a graphic man walks across the screen, and keyboard input is halted until he disappears. Infected programs contain the text "WALKER V1.00..."Infected programs contain the text "And the alone warrior is warrior..."VulnerA cold boot may be required after running an infected program. Infected programs contain the text >"Et tu vulneratus es sicut et nos..."The message "Were Here" appears when infected programs run in 1992.Whale is a huge full stealth virus that seldom activates.When the virus is active, the message "Wilbur sez HI!" appears.Winvir 1.4Infected programs contain the text "Virus_for_Windows v1.4" "MK92".Death to PascalWhen the virus is active, the message "Death to Pascal" appears, and all .PAS files in the current directory are erased.The infected program simply stops after the message "IT'S WITCHING HOUR..." appears.Different messages appear, based on how the virus is activated.The message "I'm WIZARD 3.0" appears one character at a time, and beeps are emitted.No information available.The virus destroys the programs it infects. An infected program's date and time stamp are changed. A cold boot may be required after running an infected program.WordsWhen programs are written to disk, the virus swaps words within the file.Infected programs' size increases by 217 bytes.A cold boot may be required after running an infected program. The virus changes an infected program's date and time stamp.When the virus is active on March 5th, the message "...The ARcV [X-1]..." appears.FungusInfected programs contain the text "X-Fungus by...Nugga! Greets SCP..."Christmas Tree, Apr. 1st, TannenbaumWhen active on April 1st, the virus destroys the hard disk master boot record. From December 21st through January 1st, a Christmas Tree is displayed.Mog, MacabiThe message "Maccabi Yafo Alufa !!!" appears. The virus changes an infected program's date and time stamp to 15FEB91 12:00a.TP##VIRThe virus plays the "Yankee Doodle" tune each time it infects a program.Wench, June 17thWhen active on June 17th, the virus displays two hearts that outline the screen and meet in the center, types "Yaunch && Wench" and frames the text in hearts.EUPM, AprilaprilWhen the virus is active in 1992, the hard drive is overwritten.When the virus is active on March 23rd, the following message appears: "Be Careful. YEKE Controls Your Computer".Infected programs contain the text "McAfee, geht nach Hause!..."When the virus is active, the message "Divide overflow" appears.MinnowThe virus places its code in unused areas of the infected program.Zero-to-0The virus infects two programs at a time by overwriting them with viral code. These infected programs no longer run properly. Changes zeroes on the screen to capitol O's. Contains the text "ScUD 1991!".PaletteThe virus changes the seconds field in an infected program's time stamp to "62". After the virus infects COMMAND.COM and a certain amount of time has passed, a smiley face appears and deletes all 0's on the screen.LozinskiWhen the virus is active, sometimes the message "Aidstest topaywka" appears. The virus changes an infected program's date and time stamp.Has a video effect. Contains the text "comexe".The virus changes an infected program's date and time stamp. When the virus is active, sometimes the message "ZZ Top is the best!!!" appears.After a computer boots from an infected floppy disk, the message "RED STATE, Germ offensive--AIRCOP" appears.AlamedaThe virus only spreads when Ctrl+Alt+Del is pressed. The virus writes to the last sectors of the diskette and may corrupt data.Stoned.Azusa, Hong KongThe virus overwrites parts of the hard disk's master boot record with viral code. The virus may interfere with printer port activities.Stoned.June_4th, Bloody!After the 128th time a computer boots from an infected disk, the message "Bloody! June 4, 1989" appears.PakistaniThe virus changes the infected disk's volume label to either "(c) Brain" or "(c) ashar".Brunswick,Stoned 3This variant of Stoned stores the original master boot sector on physical sector 16.After a computer boots from an infected floppy disk, the message "Hey man, I don't wanna work..." appears.Den ZukWhen Ctrl+Alt+Del is pressed, the message "DEN ZUKO" appears. The virus destroys data on floppy disks.Ohio, HackerThe virus searches for the "Brain" virus and removes it if it is found.OgreAfter an infected computer has been on for 48 hours, the message "Disk Killer--Version 1.00..." appears. The virus then encrypts the entire hard drive.CursyThe virus moves the original boot record to the last track of floppy disks. The text "EV" is written at the end of the boot record.Stoned.EmpireThe boot record of an infected disk contains a message about Desert Storm. The virus overwrites sector 10 of the floppy disk directory, destroying any data located there.The virus formats an extra track on the floppy disk and places itself in that space. Corrupts FAT. Displays a message in Swedish.Fish BootDisplays the message "Hello! I am FISH, please don't kill me..." May wipe out CMOS information.On the 18th of any month, the virus causes a clicking sound when keys are pressed. On hard disks, the original boot sector is on the last sector of the infected hard drive and may get overwritten.The virus damages the file allocation table. An infected floppy disk's programs and data files are damaged.The virus moves a floppy disk's original boot record to the last sector. Any data located there is lost.AntiCAD, Plastique, HM2The virus targets the AutoCAD program when ACAD.EXE is run or Ctrl+Alt+Del is pressed. The virus overwrites data on floppy disks and hard disks and garbles the CMOS information.When the virus is active on January 5th, the message "type Happy Birthday Joshi" appears and the computer halts until the user types in the message.The virus drops a character to make it appear that a keystroke was missed.KoreaThe virus moves the original boot record to the last sector of the root directory. Any data located there is lost.Thailand, Loa DoungThe virus plays a tune on each 128th disk access. The virus infects floppy disks when they are accessed using the DOS DIR command.Stoned.MichelangeloIf an infected system is booted on March 6th, the virus overwrites the hard disk with information from memory.The virus may cause the computer to halt when it starts. Booting from a new floppy disk causes that disk to become infected.Mistake, TypoThe virus inserts typos in all text going to the printer.After the virus is active for four months, it plays a tune when a floppy disk is accessed.BloomingtonThe virus overwrites the root directory on floppy disks. Any data located there is lost. Booting from an infected floppy disk displays the error message "Disk boot failure".Bouncing Ball, ItalianWhen the virus is active, a small ball appears and bounces around the screen.Bouncing Ball, Italian BWhen the virus is active, a small ball appears and bounces around the screen. This virus can infect the hard disk boot records. The virus functions only on 8086 and 8088 processors.India, PrtScThe virus moves the original boot record to the last sector of the root directory. Any data located there is lost.QueenslandWhen the virus triggers the MBR is erased and the message "Unauthorized Access - Micro Cop" flashes on the screen.Smiley WormThe virus changes the computer's time stamp to zeros. It hides the infected boot record on floppies to avoid detection.Telefonica, Anti-tel, CampanaThis boot sector virus is spread by the Kampana family of file viruses.New ZealandAfter an infected computer starts up, the message "Your computer is now stoned" appears. The virus is extremely common and many other viruses have been based on it.SwapAfter the virus is active for 10 minutes, the characters displayed fall into a pile at the bottom of the screen.The virus overwrites the root directory on floppy disks. Any data located there is lost. Booting from an infected floppy disk displays the error message "Disk boot failure".The virus copies the hard disk's C: drive boot record to the last sector on the hard disk, and then infects the C: drive's boot record.When a write-protected floppy disk is accessed, a slash / character or a flashing box appears as the virus attempts to infect the disk.The virus infects when programs are run or DOS "dir" command is used. After 20 infections it formats the first track on C:, A:, and B: and displays: "Your disk is formated by the LOREN virus."STB, NOPSThe virus is based on source code from a published virus tutorial. On 360k and 1.2 meg diskettes extra tracks are formated, while on 720k and 1.44 meg diskettes the last six sectors are marked as bad.D3,NewBugThis boot sector virus contains code to corrupt some specific EXE program. Exactly what EXE program is unknown and the virus does no other intentional damage. Floppy disks may be corrupted.Monitoba, StonhengeThe virus is a modification of the Stoned virus.Stoned.Whit, LzrwThe virus is a modification of the Stoned virus.CMOS KillerThis family of viruses attempts to modify CMOS information. EXE files are overwritten by virus code turning them into droppers.January 1This variant of the November 17 virus triggers on January 1st of any year by overwritting critical sectors on the current drive.This is a member of the Stoned.Empire virus family, which were reportedly produced at the University of Alberta.Quarry, QueryAn infected boot sector contains the string "QRry". If the month is December of any year, the virus overwrites portions of the current drive.Contains the phrase "YOU CAN CHANG SOMETHING OF THE PROGRAM" in clear text near the end of an infected program.Stoned.Empire.MonkeyThe virus encrypts and stores the original MBR. The original partition information is overwritten by virus code, thus using FDISK /MBR will leave the hard drive corrupted.After September 1, this virus will cause the beeper to emit a continuous tone and place messages on the screen. But it will not be spreading while the tone is being emitted. Before September, it just spreads.Contains encrypted text "Freddy KRueGer 2.1".Contains the text "M a d e i n C h e n g d e n" and the lyrics to the Michael Jackson song Thriller.Code in the virus to seek host files is visible as the text strings: "=EXt", "=COu", "MuZ", and "EuN".The virus zeros out the partition information in the master boot sector and stores the original sector in an encrypted form. Using FDISK /MBR will leave the hard drive corrupted.The virus contains the text "A pretty girl came into the world on 1-9-1968 I love her".Jack the RipperThe virus contains the encrypted message "(C) 1992 Jack Ripper".Form II, StirThis Form virus variant contains the text "STIR!".Infected files contain the text "sDos" near the start of the virus code.Cansu, SigalitThe virus will randomly display a large red "V" on the screen. The virus tries to locate and remove the Stoned virus, but fails due to a bug. Another bug causes the virus to corrupt data on 1.44M diskettes.Swiss ArmyContains a message in German about disbanding the Swiss army.MISiS, NIKAContains messages in Cyrillic text.AngelinaContains the text "Greetings for ANGELINA !!!/by Garfield/Zielona Gora".2448Often partially infect files by adding code to the end of the file but failing to modify the file header.Randomly displays one of these messages: "ZAGZIG UNIV", "HELLO SHSHTAY", or "GODBYE AMIN". The messages are encrypted in the virus. The string "COMexecomEXE" is visible in infected files.LyceeThe time stamp on infected programs is changed to 00. The program avoids infecting an eight-letter program that starts with "AI" and any program with "SCAN" in it.Fairzh,KhobarContains the encrypted messages "This is an [ illegal copy ] of KeyPress virus remover", "System Halted" and "Eternal Fair".The virus evidently does nothing but replicate.Contains messages indicating that it is DOS 7 and contains negative messages about DOS 6's antivirus.Pinchincha,1784Randomly plays one of three tunes.Displays a message to send your artwork via Fax.This companion virus spreads in a compressed form.LapseContains the phrase "Memory Lapse".Infected files contain the phrase "sayha watpu".Infected files end with the phrase "Wildfire".Contains an encrypted poem.Contains the text "peace man, peace" and displays a visual graphic of a face and two hands giving the peace sign.Contains the messages "-< The Andromeda Strain >- Version 1.00 By : Crypt Keeper" and "Mission Complete... Have fun with your virus(es).JoanneContains an encrypted message dedicating the virus to a girl named Joanne.TravellerContains the message "Traveller (C) BUPT IE 1991.4 Don't panic, I'm harmless!"TempestContains the message "[Tempest - à] Rangon, Burma".Contains the message "[Chromosome Glitch] v1.0 Copyright (c) 1993 Memory Lapse."TrekWarContains a poem about an astronaut and the text "[TrekWar]".This family of viruses contain the text "Drive Not Ready."Contains the text "DOS-1".GaneauThe virus will trigger only on March 20, 1994. It prints the message "Beware of the BUG !!!" and hangs the machine. It avoids infecting some antivirus software and QBASIC.EXE.WTFContains a message made of letters and extended character that asks what this world if coming to and says "SMAUG LIVES."Infected files end with the word "GOTCHA!"Contains the encrypted text "+ALLERBMU NORI+ (C)1991 by SMAUG" and says it was programmed in Germany.Infected files end with the text "Turbo Hamster Virus!"James BondInfected files have the text "James Bond is alive!" at the end of the file.Contains the encrypted text "You have the Joker ]I[ virus by Crypt Keeper" and several "joke" error messages.Contains the text "MUTAtOR (C) Mutation Inc."BootacheContains the encrypted message "*YAM*. Your PC has a bootache! - Get some medicine! Ontario-3 by Death Angel."512Contains the encrypted texts "Virus", "INFECTED", "RB91", and "G2".Contains messages asking for money.We Are PROContains the encrypted message "We are PRO".ARCV-4Contains the text "[ARCV-4] Apache Warrier, ARCV Pres."ICE-9Contains the text "[224] ICE-9".SimpContains the encrypted text "STIMP-VIRUS made in Poland."Infected files end with the text "[LockUp] VCL".Contains the encrypted messages "Wild Thing" and "It's Friday... Enjoy the weekend with your computer."Contains the text "WILLOW come in."ZZInfected files end with the text "*ZZ* v 1.0".OZInfected programs have the word "OZ" near the end of the file.T4, GriffeContains encrypted text saying it was produced at "BACTERIOPHAGE LABS".The virus sets up a one hour check routine. If a floppy is infected during that hour, the routine is reset. If no floppy is infected, the virus prints the message "PARITY CHECK" and hangs the system. The virus intercepts Ctrl+Alt+Del and emulates a reboot.Contains the encrypted text "Produced by Mr.Watshira Sae-eu KMIT-NB Date 12/28/1990 BIOS".TrackerModifies CMOS hour alarm field and may modify data written to disk.Infected boot sectors begin with 3 NOP (no operation) instructions. These appear as "".Contains the encrypted messages "Sweden 1994" and "The Junkie Virus - Written in Malmo". The virus contains no intentionally damaging code, but will corrupt .COM files over 64k. It disables the antivirus included with MS-DOS 6.Contains the encrypted message "[CHiLL TOUCH] You cannot touch these phantoms". Will corrupt .COM files over 64k. The virus contains code to format tracks on the hard drive, but the code is disabled.This is a group of viruses calling themselves the "Cybertech Virus".The virus contains message "GROG 4EVER! GROG v3.1 (C) '93 by GROG - Italy"James Bond The message "James Bond is Alive!" can be seen at the end of infected files.This family of viruses contain the text "Viking#", where "#" is the version number, which is visible at the end of infected files.Contains encrypted text calling it the "YB" virus.Contains encrypted text calling it the "K-4C Virus".The text "Junior" is visible at the end of infected files.The virus writes its code to the middle of the host file. An infected system runs very slow.The virus creates a "companion" .COM file for .EXE programs and infects .COM programs.The virus infects one .COM and one .EXE file in the current PATH when an infected file is executed. If the PATH variable is not set, the virus may hang the system. The message "KAOS4 / K”hntark" is visible near the end of infected files.IbexOn the seventh of any month, the virus will overwrite the first hard drive with garbage. A bug in the virus may make floppy boot sectors appear to be invalid under some versions of BIOS.These viruses contain the names of characters from an old television show.The virus often hangs the system. It may occasionally play music.Flashes the "subliminal" messages "grog4ever" and "razor" on the screen.Writes random information to the disk on the 11th of any month.RitzenContains a dedication to a Minister of Education and Science and complains about budget cuts.Contains an apology for the Proto-T.Ritzen viruses.Contains the encrypted text "dinamo".At 11:00 am on any Friday it may print the message "Runtime error 412".Prints the message "Nice to meet you! Copyright(c) 1-10-1993 By Ming. From Tuen Mun, Hong Kong Version 1.00"Infects files recursively in all directories, starting with the root.These viruses contain the encrypted text "RuBBit RuBBIt" and a version number.Contains the text "[Whisper presenterar Tai-Pan]". The virus infects by recursively searching the directory structure. It randomly writes garbage to files. Contains encrypted messages including "A teraz maly test ... Hi,hi. Piotr Panek Corp 1992 version v1.4". The virus disinfects an infected file when it is executed and infects another file in the same directory. Contains the text "Magyar V ndor '92 V rMiki. Ez a program fert z tt (volt)! Most Megyek, cs!" Contains the text "OUTWIT" and "(C) '93 by GROG - Italy S." Contains the text "Old Scribe by Nostradamus [NuKE'94]". Interferes with screen output. Contains the text "Kaakon and Kristin Blew It Up Again". Overwrites hard disk.This Trojan writes a boot sector that checks the date in CMOS. After five months there is a 1 in 4 chance on each reboot that 128 sectors of the hard drive will be overwritten and the CMOS zeroed out. The Trojan also modifies FORMAT.COM.ANTI-AngeThe virus infects application and application-like files, spreading only under System 6 Finder configurations. If you are running MultiFinder or System 7, Anti can infect one file only, but cannot spread.The virus infects application and application-like files, spreading only under System 6 Finder configurations. If you are running MultiFinder or System 7, Anti can infect one file only, but cannot spread.The virus infects only desktop files (invisible files used by the Finder). As with most desktop viruses, System 7 is immune to the CDEF virus. Though CDEF can attach to desktop files, it will not damage the system.When active between June 6th and December 31st, the message "You have a virus..." appears, it deletes viral code from system file and current application. Between Jan 1st and June 5th after 1991 the just virus spreads.The virus affects HyperCard stacks only. When active, the message "Dukakis for President" appears then deletes itself.Virus draws a bomb icon. The message "Frankie says No more piracy!" then appears and the computer stops. Frankie only infects application files (including Finder), and spreads under System 6 Finder on Aladdin emulator systems.The virus only infects HyperCard stacks. When active, the message "Hey, what are you doing?" appears. It plays a couple of folk songs, displays pop-up menus and after 15 minutes, the message "Don't panic" appears.INIT 17 activates on startup after October 31, 1993. The virus causes a message to display one time only. It infects System and application files and may cause crashes on the Plus, SE and Classic Macintosh CPUs.The virus activates on startup on any Friday the 13th (1991 or later). The virus changes Finder type and creator file information, renames files, or even may even delete them from your disks.Only infected system files or applications can spread this virus, infecting infecting any and all files that contain resource forks. INIT 29 attempts to infect floppy disks.INIT M can actively reproduce at any time. But the virus only activates on Friday the 13th when it does its damage by changing names, types and creator Finder information. It only affects Mac running System 7.0 or above.This virus infects the system file by adding an 'INIT' resource. When an infected system is started on March 2, 1988, the virus displays a peace message and deletes itself from the system file.The MBDF A/B infects applications and System files and spreads rapidly. The virus can cause systems to crash, particularly when commands are selected from menus when running System 7.0.1.Garfield, Top CatThe virus only infects application software, sparing system files and other documents. Some strains attempt to bypass early virus detection software.MDEF D only infects application software, sparing system files and other documents. Some strains attempt to bypass early virus detection software.MerryXmas affects only HyperCard stacks. It infects starting with the Home stack and spreads easily from stack to stack. Due to an error in HyperCard program code, an error message will be displayed on every new infection.The virus is the most prolific of all known Macintosh viruses with two basic strains and nine variants. nVIR first infects an active System file then becomes memory resident, infecting all files it comes in contact with.Scores infects System, notebook, and Scrapbook files (changes the icons of the latter two into generic document icons), and creates 2 invisible files. 4 to 7 days later, frequent system error messages will start occurring.T4-A, T4-B, T4-CThe T4 virus infects applications, the Finder and attempts to modify the System file startup (or boot) code and interferes with the loading of system extensions.CPro,FntFnder,Mosaic,4-cycle,VInfoThese Trojan horses secretly install viruses on your Macintosh. Some will attempt to format disks that are currently mounted. Others will erase the directory of your hard disk.The virus masquerades as a female voice sound driver that is MacinTalk compatible (Macintalk is a software-based speech synthesizer). It is actually a system extension that erases hard disks.The virus causes beeping and frequent system crashes. Fonts may become corrupted and improperly displayed. WDEF spreads rapidly, copying itself from desktop to desktop usually through the sharing of software and disks.ZUC B, ZUC CThe virus only infects application software, but can transmit and spread across a network. When an infected application is run the cursor may move across the screen in a diagonal motion or "jumping" has also been observed.The virus spreads only under Italian versions of the Macintosh operating system. It infects finder and selected applications. Upon triggering, it attempts to destroy the startup hard drive.The virus triggers on October 31 to rename your hard disk to "Trent Saburo." It infects System files and many applications files as they are run. Only applications whose first jump table entry in 'CODE' 0 points to 'CODE' 1 are at risk.NAV Test FileThis is a sample text file for which a unique definition exists in NAV. Its purpose is to demonstrate NAV virus file detection without the use of an actual virus file. Use the DOS command TYPE to read the file for more information.Deleting this definition from the def set will cause NAV for NetWare to create a new definitions file. Its automated update capability will then update all other NLMs with new definitions. If you are updating your NLM with this new def set, delete this def now.

  3 Responses to “Category : System Diagnostics for your computer
Archive   : 30A11.ZIP
Filename : VIRSCAN.INF

  1. Very nice! Thank you for this wonderful archive. I wonder why I found it only now. Long live the BBS file archives!

  2. This is so awesome! 😀 I’d be cool if you could download an entire archive of this at once, though.

  3. But one thing that puzzles me is the “mtswslnkmcjklsdlsbdmMICROSOFT” string. There is an article about it here. It is definitely worth a read: http://www.os2museum.com/wp/mtswslnk/