Virus signature information file for Virus scanners
;---------------------------------------------------------------------------
;% VIRSCAN.DAT, Virus signature information file for Virus scanners.
;% Revision: 911114 (yymmdd)
;% (C) Copyright 1989-1991 by Jan R. Terpstra, all rights reserved.
;% For info about this DATAFILE, contact:
;% P.O. Box 66, 1462 ZH, Beemster, The Netherlands or FIDONET 2:512/10.0
;%
;% For info about the scanning PROGRAM contact the author of the program.
;
; The info in this file is published under the following conditions: ;
; ;
; - you may freely distribute this file in UNMODIFIED FORM to anyone other ;
; person or organisation via any means of transmission. ;
; - you may modify this file for YOUR OWN PRIVATE or NON-COMMERCIAL USE. ;
; - you may NOT distribute modified copies of this file. ;
; - Using this file for any commercial activity (sale, magazine & newspaper ;
; publication as well as any form of paid services to third parties) is ;
; only allowed after obtaining a written permission from the editor. ;
; ;
;NOTICE: This file carries a sanity check. Do NOT change the control info ;
; or any of the info above the sanity check line at the end of the ;
; file. ;
; If you need to add your own info to this file, do so BELOW the ;
; sanity control info line at the bottom of this file. ;
;---------------------------------------------------------------------------;
; Revision history: ;
; ;
; yymmdd description ;
; ------ ------------------------------------------------------------- ;
; 890815 First release of this file ;
; 911114 Complete revision this file, major work by RiZwi ;
;---------------------------------------------------------------------------;
; ==> You may NOT distribute modified copies of this file!!! <== ;
; ;
; This file contains a VERIFIED list of Virus signatures and should be ;
; used as input for a suitable Virus scanner. The MASTER copy of this file ;
; and various Virus scanners are maintained and available for FileRequest ;
; or download on: ;
; ;
; Bamestra RBBS, The Netherlands (FIDO 2:512/10.0) ;
; phone: ++31 2998 3602 or ++31 2998 3603 (HST/CM) ;
; P.O. Box 66, 1462 ZH, Beemster, The Netherlands ;
; ;
; If you find a Virus and want the info added to this file, leave a message ;
; on or send FIDO netmail to Sysop on Bamestra RBBS, 2:512/10.0 ;
; A working copy of the suspected Virus for verification is appreciated. ;
; ;
; Several Bulletin Boards over the world have copies of this file and Virus ;
; scanning programs available for download or file-request: ;
; ;
; VirusSIG.ZIP - latest VERIFIED version of VIRSCAN.DAT ;
; TBSCAN*.ZIP - Fast Virus scanner with lots of options ;
; TBSCNX*.ZIP - Resident version of TBSCAN ;
; HTSCAN*.ZIP - Another good Virus scanner ;
; ;
; Most Bulletin Boards get a fresh copy of this file within 48 hours after ;
; the Master Copy on 2:512/10.0 is updated. ;
; ;
; If you appreciate our efforts to keep this list up to date, then please ;
; consider a donation to a local AIDS or cancer research foundation. ;
; For commercial users: Contact the editor before use! ;
;---------------------------------------------------------------------------;
; ;
; Instructions for use: ;
; If you find a new Virus that is not in this list, you can add its ;
; signature to this list BELOW the sanity check control line. ;
; ;
; NOTE: Signatures for BOOT record Viruses wil sometimes trigger alarms in ;
; .EXE or .COM files and vice versa. Please check for proper usage of ;
; BOOT versus .COM and EXE signatures before you yell "Virus!". ;
; ;
; DO NOT DISTRIBUTE MODIFIED COPIES OF THIS FILE! ;
; Some unofficial versions of this file with wrong information, were ;
; distributed by some individuals. These wrong versions have caused some ;
; panic because perfectly healthy programs were accused of being infected ;
; by a Virus. Again: DO NOT DISTRIBUTE MODIFIED COPIES OF THIS FILE! ;
; ;
; Format of a Virus signature entry (3 lines, no comments in between): ;
; ;
; <Virus name> (max. 30 characters) ;
; <affected items> (COM, EXE, BOOT, HIGH, LOW, separated by blanks) ;
; <Virus signature> (hex string, no seperators, max 80 characters) ;
; ;
; Lines starting with a ';' are ignored by the Virus scanners. ;
; ;
;NOTICE: This file carries a checksum control. Do NOT change the checksum ;
; and add your own info BELOW the cheksum line at the bottom of this ;
; file. ;
;---------------------------------------------------------------------------;
; Signatures collected by Jan R. Terpstra (SysOp Bamestra BBS) with special ;
; thaks to Dave Chess, Yuval Tal, Righard Zwienenberg, Bill Arnold, Mark ;
; Blom, John McAfee, Frans Veldman, Kenneth Walls, Carl Bretteville, Alan ;
; Solomon and Michael Weiner. ;
;---------------------------------------------------------------------------;
;
;*** BOOTSECTOR INFECTORS **************************************************
Aircop Virus
BOOT
DD2EFF2EC001530EE8B1FF0EBB4C00E8ADFF5BCD12
;
Anthrax Virus
BOOT
A58ED8BA270451535052CB8EC1B104BEB00583C60EAD3C80
;
Azusa Virus
BOOT
A450B8CA0050CB31C0CD1331C08EC0B80102BB00
;
Blood2 Virus
BOOT LOW
A5FF2E0F7C33C0CD130E1F33C08EC0B80102BB007C803E0A0000
;
Boot record zapped by XA1
BOOT
5B83C30D8CC88ED8E81500EBFE
;
Brain, Shoe or Ashar Virus
BOOT
F4A113042D0700A31304B106D3E08EC0BE007C
;
Brunswick Virus
BOOT
A6C35152565706E8D4FFE8E7FF74252EC606290100B80103
;
Den Zuk Virus
BOOT
FA8CC88ED88ED0BC00F0FB?8*3C?
;
Disk Killer (OGRE) Virus
BOOT
D2F7361A0088163F01A34101C3A14101
;
EDV Virus
BOOT
DB8ED8C7078118813F8118740D2D00103D00B875ECB800A8
;
Empire virus
BOOT LOW
A5B8010331DB41E823FFA0A801403C16720230C0A2A801
;
Evil Empire-A/B Virus
BOOT LOW
AAE2F9E9F7FECD1A3A16AF01751ABEE30189F7B91B00
;
Evil Empire-C virus
BOOT LOW
8CC88ED88EC0BF0500B99A01FC8A0504??AAE2F9E9FBFE
;
Falling Letters Virus.
BOOT
31C0CD13B80202B90627BA0001BB00208EC3BB0001CD139A00010020
;
Filler Virus
BOOT
26813F5224740BCD13
;
Flip Virus BOOT
BOOT
FBB80300E81F0006B8420050B8C007
;
Form Virus
BOOT
B9FF00FCF3A506B89A0050BBFE01B80102
;
Golden Gate Virus version C
BOOT
A717800FADBDAD5507173384
;
Golden Gate Virus version C2
BOOT
A717DDAFF001233907173385
;
Ghostballs Virus
BOOT
7D83EA247211800EF77D0156579090905F5E8026F77DFE
;
Invader Related Virus
BOOT
1304B106D3E08ED8833E400EFE751AB8??0F1E
;
Joshi Virus
BOOT
022D2100BF0000BE007C03F003F8B979012BC8
;
;Keydrop Virus
;BOOT
;AC26803D007403268A05AA8AC4E2F061F894702C7072B7CFBCD13
;
Lao Doungo Virus
BOOT
A5A5A34E00B8CF7CA34C00061FF6C2807539BB007EBA8001
;
LDV Virus
BOOT
A406B8330150CBBB4C008B0F8B5702
;
Liberty-Boot Virus
BOOT
3F2833D2CD13C333C08ED8A14C002EA30A08A14E002EA30C08
;
Mardi Bros Virus
BOOT
FA8CC88ED88ED0BC00F0FBE82700FA31C08ED8A113042D0700
;
MichelAngelo Virus
BOOT
AD3B47027435B80103B601B103807F15FD7402B10E890E0800
;
MicroDot Virus
BOOT
010000C706D9010800C606DB0102B9040051
;
Nichols Virus
BOOT
DD0DDF0FDD0FFF0A000ABA00
;
NoInt virus
BOOT LOW
AB004848A31304B106D3E08EC036A38C00B8DA00A34C00
;
Ohio Virus
BOOT
B106D3E08EC0BE007C33FFB90410FCF3A406B8000450
;
Pentagon Virus
BOOT
806C723CCD0342FC8045FCFE000F586C43FC8242738045CAFCE2FB00
;
PingPong or Typo Boot Virus
BOOT
8ED8A113042D0200A31304B106D3E02DC0078EC0BE007C8BFEB90001
;
PingPong/286 Virus
BOOT
7D807426BEBE81B90400807C0401740C807C04047406
;
PtrSc Virus
BOOT
DBB801038A365F01B90100CD6DE824005A595F5E5B
;
Smiley Worm Virus
BOOT
01E82400E83B008BF1CB07BB007C53B9030051
;
Stoned Related Virus
BOOT
750E33C08ED8A03F04A8017503E80700
;
Stoned/Alberta Virus
BOOT
A42EFF2E0D0031C090CD1333C08EC0B80102BB
;
Swedish Stoned Virus
BOOT LOW
A4072BF68BFEB90002F3A4B8F3000650CB2BC0CD132BC08EC0
;
Telephonica Virus
BOOT LOW
9E74645152B408CD137220FEC68836EA008AD186E9
;
Tequila Virus (Part.Table)
LOW HIGH BOOT
B106D3E08EC006B82A0250B805028B0E307C418B16327C
;
Twelve Tricks Trojan
BOOT
8CC88ED0BC007C8BF48EC08ED850
;
V-1 Related Virus
BOOT
CA03562D751726813ECC03314C750E36C7068001000036
;
Yale Virus
BOOT
BB40008EDBA11300F7E32DE0078EC00E1F81FF56347504FF0EF87D
;
Zapper Virus
BOOT
FC02721780FC04731222D2750E33C08ED8A03F04A8017503
;
;*** FILE INFECTORS ************************************
;
10 Past 3 Virus
COM
C7060001????C60?0?010?33C08ED8813EAC01464275
;
144 Virus
COM
44017416B440CDB4B8004233
;
337
COM
03F0B80057CD215251B4408BCEFECDBA0001CD21B80157
;
382 Virus
COM EXE
EB002EC7064B020000B419CD212EA27B02B447B2008D367D02CD21F8
;
483 Virus
COM EXE
00E82E00B440B91800BAE303CD50B002
;
512 Related Virus
COM
CF8EC33B158E1D8B154A8EDA8BF18BD7B1??F3A58EDB
;
789 virus
COM
D5A17505B80D909DCF2EFF36
;
923 Virus
COM EXE
832E170303B440B90300BA1603CD21C38B1E0803B8
;
1008 (Suomi) Virus
COM
DDBFA80390EB03*38B87EE03EB02*281C34400EB04*43101EB03
;
1024PSCR Virus
COM EXE
00012EA30300B4400E1FBA0004B90004E8E8007230
;
1067 Virus
COM EXE
B80242E88C00B440B92B0490BA0001CD217214
;
1210 (Prudent) Virus
EXE
2F040175D00E0E1F07BED3042BC92E8A0446410AC0
;
1392 (Amoeba) Virus
COM EXE
2F01C3E80700E83A00E86600C3BF0001A10301
;
1554 Virus
COM EXE
9B00FFFF7203A39B00A19B003DFFFF741FB000
;
1575 Virus
COM EXE LOW HIGH
1FB800015033C0CBBE0600AD3D920174DD3D79
;
1591 Virus
COM EXE
0E8CC805??50B8000150CB
;
2730 Virus
COM EXE
9177917AA4B7570056000000
;
3445 Virus
COM EXE
5983E91F8CC8*5F7E303C183D200
;
4096 Virus
COM EXE LOW
875EECFCC383C30381FBCC0272E95BE8890AE421
;
5120 Virus
COM EXE
FBA10C002EA30001A10E002EA302018C1E2200
;
a Virus created by the VCS
COM
AAE2FAC35E81EE030156E8E3FF
;
Adolph Virus
COM
F8F9B912B8BE1FD933FFF5F9F8FC
;
Agiplan Virus
COM EXE
AE263A2575F9BA0042263B550175F0B6BA263A75FB75E883F900
;
Aids (Taunt) Virus
COM
2A546869732046696C6520486173204265656E20496E66656374656420427920
;
Aids II (Companion) Virus
COM EXE
5589E581EC0202BFCA050E57BF3E011E57
;
Akuku Virus
COM EXE
89540433D2B97603B440CD2172608BD683C214B440B90400CD21
;
Alabama Virus
COM EXE LOW HIGH
C606F900013CD375062EC606F90000BB40008EDB33DB8A4717240C3C0C7541
;
Ambulance Car Virus
COM
BDF0FFBA0000B91000E83F0042E2FAE81600E87B00
;
Amstrad Related Virus
COM
B44E%1CD2172??BA??0?B8023D%1CD21%6061F%1BA??0?%1B9FFFF%1B43FCD21
;
Anthrax Virus
COM EXE
A58ED8BA270451535052CB8EC1B104BEB00583C60EAD3C80
;
Anti-Pascal I Related Virus
COM
33D2B80242CD21507230B9*2908D940601B440CD217222
;
Anti-Pascal II Related Virus
COM
1F3B06070174??50B000E8C0FFB440BA00018B0E??01CD21
;
Armagedon Virus
COM
3DDADA7503E999000E1F
;
Attention Virus
COM
31D2B440CD218BD1B979010E1FB440CD21
;
Bad Boys II Virus
COM
016014B803121ECD2F268C1E17011F
;
BadGuy Related Virus
COM
EB02EB??B42ACD213C0174??EB??90
;
Bebe Virus
COM
B8004233C933D28B1E1C00CD21B4408D160000B90E00
;
Best Wishes Related Virus
COM EXE
B8004231C931D2E8??00B440C7C2*25981C1*2E8??00
;
Black Monday Virus
EXE COM
AC009C0650EA0000000033C08ED88F0602008F060000FB
;
Blood Virus
COM
B202B40ECD21B41ABA0C0003D5CD21BA040003D5B44E
;
Boys Related Virus
COM
CD217303E9BD005E5683C625AD3D00FD
;
Burger Related Virus
COM EXE
909090BC00FE505351525556571E06169CBE80008D3E??03B92000F3A4B80000
;
Burger Related Virus
COM EXE
0226A???0226A2??02%1B419CD212?A2??0?B447%20401%18AD0
;
Cara Virus
COM
A4061FC606B2020190E84F00B86221E85D00B86320
;
Carioca Virus
COM
B490CD2180FC017513B905002E8B360301BF0001
;
Cascade Related Virus
COM
F6872A0101740F8DB74D01BC
;
Catman Virus
COM EXE
8ED8BE4C00BF0004FF34FF7402FF741C
;
Christmas in Japan Virus
COM
53B4408B8E040481C158028BD581C20005CD21
;
Christmas (XA1) Virus
COM
FA8BEC5832C08946028146002800
;
Cinderella Virus
COM LOW
CF9C80FCFB750432E49DCF80FCFC750E9D1E075FBF0001
;
Crackpot-208 Virus
COM
EB03%1EB??B42ACD21%13C0174??%1EB??90
;
Crackpot-1972 Virus
COM EXE
BBB401*88A27*732260601*98827*A43*981FB6809*B7EBD*CC3
;
Crash Virus
COM EXE LOW HIGH
A4C38CC02E03441A051000502EFF7418CB061E8CD8488EC0
;
Crazy Eddie Virus
COM EXE
B80242CCB440CC33D2B80042CC8BD6B118B440CC
;
Crew 2480 Virus
COM
A48BCE81E904005F5E5681C61C00B800003904770F
;
CSSR 528 Virus
COM
7303EB25903D0300751F8BDE
;
Dark Avenger Virus
COM EXE
49CD21*5CD2181EBE700727B8CC1F913CB
;
Darth Vader Related
COM EXE
505351%256578?%FB82012CD2F268A1DB81612CD2F
;
Datacrime (1168) Virus
COM
8B36010183EE038BC63D00007503E9FE00
;
Datacrime II Virus
COM EXE
5E81EE030183FE00742A2E8A94
;
Datacrime IIb Virus
COM EXE
2E8A0732C2D0CA2E880743E2F3
;
Datacrime B (1280) Virus
COM
8B36010183EE038BC63D00007503E90201
;
DataLock Virus
COM EXE
680001C3B4BECD213D3412C31EA12C00508CD8488ED8812E
;
dBASE Virus
COM
FB750A86E09DCFE9CE06E9810381FF0AFB742E3D004B
;
Define Related Virus
COM EXE SYS
BA9E00CD2193B440*4CD21C3
;
Deicide Virus
COM
B95000BA0000CD26B409BA0301CD21EBFE8AD0B40E
;
Demon Related Virus
COM
BAB201B44EB90B11CD21%17302EB11E84900
;
Destructor V4.00 Virus
COM EXE
BAA204E8CFFD72CBE858FF2EC7460C00012E81660E00002E8166030000
;
Devil's Dance Virus
COM
AD03F3A426C706000003015E1E068CC048
;
Diamond Related Virus
COM EXE
4A8EC233FFB9??008B55022BD13BD0723CFA26294D03895502
;
Dir Virus
COM
B4402E8B1E7D03B90600BA9503CD21B802422E8B1E7D0331C931D2CD21
;
DisCom Virus
COM EXE
6B008CC88ED88EC0B43FCD21498BFABE0500F3A67507B43E
;
Do Nothing Related Virus
COM
C21ECD707219A36F??B442B0028B1E6F??B90000
;
Doom-II Virus
COM EXE
B9AF04BF29012EA00B012E803E0A014574052E033E0301
;
Dot Killer Virus
COM
03BA0001B440CD21E8BF02B440B90300BAA704CD21B801
;
Dutch 555 Virus
COM EXE
884600C60600004DB92300290E
;
Dutch 1039 Virus
COM
52B44232C08B1E8C0133C933D2CD21B9F40481E90001B440
;
Eight Tunes (1971) Virus
COM EXE
B7003B445B7219B8907EE8C800B80835CD21895C5D
;
E.T.C. 3.00 Virus
COM
B9FFFFE2FEA1FC00A30001A1FE00A30201
;
Europe/92 Related Virus
COM
E800005EB8FF4BCD21720A83C62DBF000157A5A5C3
;
Fellowship Virus
COM EXE
FB039C0650EA0000000033C08ED88F0600008F060200FB
;
Fichv 2.1 Virus
COM
B80325BA5501CD21BB3101BA3A0090B91C03BE6B01BF6B01CC
;
Fish (6) Virus
COM EXE
8F06DB0E2E8326DB0EFE2E803EDA0E0075112EFF36DB0E
;
Flash Virus
COM EXE
4ACD218CDA03D3428EC2B455CD2156BF000183EE080E1FB9D002
;
Flip Virus COM/EXE
COM EXE
0EBB*21FB9*2B2??81C1*2EB
;
Flip Virus - RAM Resident
LOW HIGH
505152B402CD1A80FD1075
;
Formiche Virus
COM EXE
BCD21746313431244C75F8
;
Formiche Virus Resident
LOW HIGH
BFAA552EC40637018CCACF
;
Friday the 13th Virus
COM EXE
1E8BECC746100001E80000582D??00B104D3E88CCB03C32D100050
;
Frogs Related Virus
COM
E8E404A1%505000126A3*2268C
;
F-Word Related Virus
COM
B43FCD2129C85875DDFFE0B440EBF3
;
G-Virus 1.3 Virus
COM EXE HIGH
5F83EF03E800005E81EE87002E89845900
;
Gergana Related Virus
COM
16AD013BCA74E1B8024233C933D2CD21A3AB01B4
;
Gotcha! Related Virus
COM EXE
E800005B81EBC?039CFC2E80BF39010074128CD80510002E03871D
;
Guppy Virus
COM
B8024233D233C9CD2197B440B19889F283EA40CD21
;
Halloechen Virus
COM EXE
4B00C7065B005555BA4900C706FB003000E8A1FEFF064A01
;
Happy New Year Related Virus
COM EXE
E81CFD72EF50B91000F7F15052B940068D940001B440E806FD
;
Holland Girl Related Virus
COM EXE
0301%133C933%2C0AC3C1A740403C8EBF781F9A34675
;
Hero Virus
COM
33D2CD21B440B91800BAFA03CD21
;
Hungarian 482 Virus
COM EXE
D2CD21B9E20190BA0000B440CD21B801
;
Hybryd Virus
COM
B440B91A058BD681EA8D02CD21??505683EE51908BFEB99202
;
Hymn Virus
COM EXE
33D2B9490790B440E877FE722733C875238BD1B80042E869FE
;
Icelandic/Saratoga Virus
COM EXE
A3030003D8438EC333F633FF0E1FB9D007
;
Icelandic III Virus
EXE
6803A32400A16A03051000A31C0090
;
InCom Virus
COM
528BFA8B4D028BDF2BD983C31783E92C301F43
;
Int 13 Virus
COM EXE
B80242B9FFFF8BD1CD9EB43FB2538BFAF7D9CD9E
;
Internal (1381) Virus
EXE
3FB91C008B1E27008D160900CD217211813E1B004D5A7409A11700
;
Itavir Virus
COM EXE
9B00908A16D70B80FA02741B1E52B41CCD218A075A
;
Jeff Virus
COM
A4C6069D02B8B89BFF8EC0B93F0033D232E48BD9268A0701C2
;
Jerk (Talentless) Virus
COM
A4B41ABA3E0501EA89969402CD21B419CD218886F804BBFFFF
;
Jerusalem Related Virus
COM EXE LOW HIGH
26C6%3CB580510008EC00E1FB9
;
JoJo (1701) Virus
COM
6DB42CCD2180FD13720AB8CD20A3000153E9C702
;
Joker Virus
EXE
1B35CD21891EA9478C06AB471E0E1FBA7A01B81B25
;
July 13th Virus
EXE
A012003490BE1200B9B1042E300446E2FA
;
June 16th (Pretoria) Virus
COM
C933D2E85BFFE81200B440BA0001
;
Justice Virus
COM
B440B9DA049C0EE870FC723881FEDDDD750A2EC7063D000155EB0F
;
Kamikaze Virus
EXE
BAEB008EDA8C063E0033ED8BC4051300
;
Kemerovo Virus
COM
BA0100B80242CD2172D15A5283EA04B90001B440CD21
;
Kennedy (333) Virus
COM
9452028BFAB90300CD21803DE97405E87E00F8
;
Keypress Virus
COM EXE
A4F8C3061FC706BE020000B81C35CD21891EEA028C06EC
;
Kiev Related Virus
COM
0153B440BAD50101DAB903008BDFCD215B72
;
Klaeren Virus
COM EXE
9CFF1EEB045351E800005B81EBAF03B9A5038037??43E2FA
;
Leech Dropper
COM EXE
A0FF0730044681FEFF0772F7595AB440E85B00
;
Lehigh Virus
COM
505380FC4B740880FC4E7403E977018BDA807F013A75058A07EB07
;
Leprosy Virus
COM EXE
B43BCD21463B36ED027CE1803EF00200740AB8BA0250
;
Leprosy B Virus
COM EXE
01B440CD21E80100C3BB31018A2732260601882743
;
Leprosy C or D Virus
COM EXE
5633F6E8??000BC0740?E81?0046%802B43BCD214683FE037?E?EB005E
;
Liberty Virus
COM EXE
93E8CD0072C2BB13012E813F4D5A7505
;
Liberty-Boot Virus
COM EXE
3F2833D2CD13C333C08ED8A14C002EA30A08A14E002EA30C08
;
LoveChild Virus or Trojan
COM EXE
1003CD13FECE79F7B603FEC5EBF14C6F76
;
Lower Case virus
COM
370481E92704FCF3A4C3BF00018B363A01B900D0D1E9FC
;
Lozinsky (AidsTest) Virus
COM
B90100BAC900CD217303E988002EA0B7032E3806C900747DB80242
;
Magnitogorsk Related Virus
COM
BE3E0003F7B9C20?2E00042EF6AD070046E2F5
;
MG Related Virus
COM
CDFF7213B8004231D28BCACDFFB440B90300BA????CDFF
;
MGTU Virus
COM
B4408D0E0D028D1600012BCA8BD581C20001CD21B440B904008D160901
;
Minimal Related Virus
COM
0001B92D00B440CD21B43E
;
Mirror Virus
COM EXE
CD215A59B80157CD21B43ECD21B82135CD21
;
Mix I Related Virus
COM EXE
33C08EC02680261704BF26800E1704
;
Mix II Related Virus
COM EXE
E83500E81B00BA0000B9E808B4409C9A60142B02
;
MLTI Virus
COM
B440B93E030E1F33D2CD21FA5A1F7200B43ECD21FA
;
Murphy Related Virus
COM EXE
0000B8??4B%1CD21%17203E92?015E56%18BFE33C0501FC4064C002E8984??F?2E8C84??F?
;
Mutant Related Virus
COM
CD2105??00813E??0144497413
;
Naughty Hacker Related Virus
COM EXE
53B82012%3268A1DB81612%35B83C711
;
Nina Related Virus
COM
3D004B750D505351521EE80A001F5A595B58EA60142602B8023D
;
Nobock (440) Virus
COM
B80242CD218D95CC09B9B80190B440CD215A59
;
Nomenclatura Related Virus
COM EXE
4401B440B90300CD21C333C08EC0BE1505BF9000B9
;
Number One Virus
COM
E878F9073C536D696C653EE832E0
;
Old Yankee Related Virus
COM EXE
81EE*203F38904BE*281
;
Ontario Related Virus
COM EXE
562E8A84E801B9E801F6D02E300446E2F8C3
;
Oropax Virus
COM LOW
8200C7069C007D098C0E9E00C7068400EE088C0E8600FB2E803E070100
;
Paris Related Virus
COM EXE
59B4408D16A0028D3686028B1CCD218D36B0028904
;
Parity Virus
COM
88A5B4028B855B022D03008985B502B440BAB40203D7B90300CD21
;
PCV Virus
COM EXE
33DBBE1C00B94F072E8A9708002E0010
;
Perfume (765) Virus
COM
EF408EC70E1FB90004FCBF0000F3A481EC0004
;
Phantom Virus
COM
00C3B440E80D00C3B43EE80700C3B43FE80100
;
Phoenix related virus
COM EXE HIGH
00014?03??8B??33??B?*25?33??224?4?4?7?F85?31??224?4?4?7?F8
;95B?00014?03??8B??33??B?*25?33??224?4?4?7?F85?31??224?4?4?7?F8
;
Plague Related Virus
COM EXE
BB34018A273226060188274381FB8303
;
Polimer Virus
COM
8B0E6C018CD80500108ED8B440CD21
;
Polish 217 Virus
COM
0300B440CD21E825008BD681C20001B9D900
;
Poss-A Virus
COM EXE
A5070E1F8B166700803E6E000B750F8916990281EAA3FF
;
Poss-B virus
COM EXE
A5E8C4011F2E8B0E160A2E803E5B000B750481E98E0933D2
;
Rape Related Virus
COM
CD69%233D2B440B9??0?90CD69%25A59%AB80157CD69
;
Raubkopie Virus
COM EXE
BE12018BFEB98102D1E9
;
Revenge Attacker Virus
COM
C933D29CFF1E0901B4408B1EB901B9670581E90001BA0001
;
Russian Mirror Virus
COM
2EA3BE015B53B9E201BA0000B440CD21B800425B53B90000BA0000CD21
;
RVPS Virus
COM
C2015B53B440CD215BB43ECD21*7BCFEFFE99832CD21%1E955FF
;
Saddam Virus
COM
6B7226EBEDA1E40225E0FF051F00A3E402B43DB0028CCA8EDA
;
Saterday 14th (Durban) Virus
COM EXE
9D02A4E2FD06B82135CD211F891E5302
;
Scotts Valley Virus
COM EXE
5E8BDE909081C63200B912082E
;
Sentinel Related Virus
COM EXE
89EC5DC202005589E583EC128C5EF?55E81?F?
;F?89EC5DC202005589E583EC128C5EF?55E81?F?
;
Shake Virus
COM
5E50E800005EB80342CD213D34??7503
;
Slowdown Virus
COM EXE
DE909081C61B00B990062E8034
;
Solano 2000 Virus
COM
175858BF00012E893E2101582EA32301
;
Spyer Virus
COM EXE
1F8BD8B80242B9FFFFBAD6FFCD217303E90A01052A003D03007703
;
Staff Virus
COM
E80AFFBA8F02E820FFE801FFB80057CD215152B000
;
Sparse Virus
COM
061F17BB000106538CC64E8EDE8C0601008CC6
;
StarDot-600 Virus
COM EXE
6803B43BCD21B42ACD21FEC08B16410383E2073AC2
;
StarDot-801 Virus
COM EXE
268B1E6C04891E720407
;
Suriv 1.01 Virus
COM
81F9C407721B81FA0104
;
Suriv 2.01 Virus
EXE
81F9C407722881FA0104
;
SVC 3.1 Virus
COM EXE
33D2B92804B80040E84CFE3D2804751833C933D2B80042E83DFE
;
SVC 4.0 Virus
COM EXE
33D2B99906B80040E8F7FD72203D9906751B33C933D2B80042E8E6FD
;
Sverdlov Virus
COM EXE
5EEB02*283EE082E8A840C00B97D07BF2D0003FE
;
SVir Virus
EXE
E788261900A11D00A32100A11B00A32300C7061B000000
;
Syslock Related Virus
COM EXE
D1E98AE18AC13306140031044646E2F25E5958C3
;
Taiwan Related Virus
COM
B90800BE??03BF00F8FCF3A4B9??028B36??01
;
Telecom Virus #1
COM EXE
DB7420B6??BE5500B9740EB6??03F58A1C80F3??32D80ADCB2??B2??
;
Telecom Virus #2
COM EXE
B20083FB007418BF5500B2??B9740E03FD8A1D80C3??32D8881D
;
Tequila Virus (Signature A)
EXE
B96009%48A17%44643%281FB*272??%2BB*2%4E2??%2E9
;
Tequila Virus (Signature B)
EXE
B96009%48A14%44643%281FE*272??%2BE*2%4E2??%2E9
;
Terror Related Virus
COM EXE
50B859ECCD213BE8753E0E1F582E8E06??0?E8D5FF7410B90D00
;
Test Related Virus
COM
3C31742E3C35740B3C397424EBEEE8A101721D
;
The Rat Virus
COM EXE
FFB440E833FFB80042BA8000E837FFB98001BA100A
;
Tiny Related Virus
COM
3D004B75??5053%7B8023D
;
Tiny (163) Virus
COM
8984AB01B4408D940501B9A300CD217215
;
Tony Related Virud
COM
1B5033C933D2B80042CC59B440CC2E8B0E16012E8B
;
TP Worm
COM EXE
E9D3DD558BEC8B5604B80043CD21720FF64606027409F6C1017404B8000DF9E9A1DD
;
Traceback (3066) Virus
COM EXE
7106E82806B419CD2189B451018184510184088C8C5301
;
Traceback II (2930) Virus
COM EXE
2906E8E005B419CD218884E300E8CE048A95E2000E1F7509
;
Tumen Related Virus
COM EXE
4D5A74??5131D2B9*2B440CD2131C931D2B80042
;
Turbo 448 Virus
COM LOW HIGH
B80242B900008BD1E81F00BA0001B9C001B440E81400
;
Turbo Kukac Virus
COM
83EE03BAC10281EA000103F28B1C8B4C02
;
Twelve Tricks Trojan Dropper
COM EXE
BE640231944201D1C24E79F7
;
Typo Related Virus
COM
D681C2050033C9B44FCD2173EF
;
USSR 311 Virus
COM
B80157B9705A8B55FACD21B43ECD21B801435932ED8BD7CD21
;
USSR 492 Virus
COM
032BC8BA2A02B440CD217248B440B9EC01BA0001CD21
;
USSR 516 Virus
COM
B80242E8FFFEA3A900B90402B440E8F4FE722E2BC8752A
;
USSR 529 Virus
COM
0503B440CD217215B8004233D28BCACD21
;
USSR 600 Virus
COM
B44051BB58038A0734BB880743E2F7595B53BA5803CD21
;
USSR 707 Virus
COM
B8004233C933D2E8A100B440B903008BD783C217E89400
;
USSR 711 Virus
COM
2E8B0EB20083E10F83C1058CC88ED833D2B80040CD217234
;
USSR 948 Virus
COM EXE
8B4C04B80042CD212BD28BCEB440CD215A59B80157CD21
;
USSR 696 Virus
COM
BA0001B9B802B440CD2159880EB5031F33C933D2B80042CD21
;
USSR 905 Virus
EXE
8B161200F6D63AD674B4B8024233C933D2CD21
;
USSR 1049 Virus
COM EXE
B440EB02B43FE8090072023BC1C332C0B4422E8B1E3E00
;
USSR 2144 Virus
COM EXE
C43F50268B05D1E83598122E038415005883C304E2EA2EC684B70030
;
V-1 Related Virus
COM
CA03562D751726813ECC03314C750E36C7068001000036
;
V270 Related Virus
COM EXE
BE00015631FFB90B01F3A4BD2301B9E600FA87EC5B5831D85049E2F8
;
V651 (Eddie 3) Virus
COM EXE
B440CD2172F52BC875F18BD1B80042CD2172E8A1A002
;
V800 Related Virus
COM
E800005E83C619??8BFE33D2
;
V801 Related Virus
COM EXE
2EF606D4030174078ED0531E1EEB0550
;
V1963 Virus
COM EXE LOW
0E07BB04098BFBABB080AB8CC8ABB85C00AB8CC8ABB86C00AB8CC8AB
;
V2000 Virus
COM EXE LOW
B413CD2F5A1F2E8994A7072E8C9CA9072E
;
V2100 Related Virus
COM EXE LOW
EE0AA5A55E33D2B92408B440CD21721733C87517
;
Vacsina Related Virus
COM EXE
B801438E5E0E8B56062E8B0E??00
;
VACSINA EXE2COM conversion
COM EXE
03C8894FFB%28B0E160103C8894FF7%28B0E1001894F%28B
;
VComm Virus
EXE
02B440CD21E83E00A19?02A33?02A19?02A33?021E
;7?02B440CD21E83E00A19?02A33?02A19?02A33?021E
;
VFSI (Happy Day) Virus
COM
588BD0350F0005020003C88CD8488ED8B80040CD215A59B80157CD21
;
Victor Virus
COM EXE LOW HIGH
BCF308B42CCD2189167200B42CCD218ACA80E10FD3067200
;
Vienna Related Virus
COM
AC3C3B74??3C007403AAEBF4**1F89**B05CAA89
;
Vienna Related Virus
COM
8BD681C60000FCB90300BF0001F3A48BFAB430CD213C007503
;
Virus-90
COM
C5030133C033DBB909008D561289D6030043
;
Virus-101
COM EXE
B303B4??03F3B4??8CC8B7??8CDBB5??39C3B4??7411B4??BE0010
;
VP Virus
COM
E2B97D03CD218CC28EDAB457B0018B1E20038B0EDC028B16DE02CD21
;
Voronezh Virus
COM EXE
31C9B800425B53CD218B0E58078D164007B440CD21
;
Vriest Virus
COM
8BD82EFE0E260251521E0E1FB440B90005BA0001C70627020000CD21
;
VVV-252 Related Virus
COM
8BD8B4408B0EFC00030EFA008B16F800CD21
;
Warrier Related Virus
COM EXE
8BD7E8D50080ECFD2E3B060200720ABA00038BCAB440
;
Warrior Related Virus
EXE
028944FEB900045A5281E20F00B440CD219C
;
Whale Virus
LOW HIGH
252E890E64255B2E8B0783C3025389C132ED2E302743E2FA
;
Whale Mutant #1
COM EXE
2907E2FA5B59EB2A5BFC53C30E1FE8F7FF81EBA323B9C111
;
Whale Mutant #2
COM EXE
371083C301E2F8585B5956BE6625F8FF14F85E43E82900
;
Whale Mutant #3
COM EXE
37261383C303E2F78BCB598BD959B460EB1D56E80200
;
Whale Mutant #4
COM EXE
3786F283C301E2F55AFB5B59FF166625E803004033DE
;
Whale Mutant #5
COM EXE
37964083C303E2F78CC0588BD859B450EB1E56FDE80200
;
Whale Mutant #6
COM EXE
49434975F7FF3666258F0699255B59EB03E82F00FF16
;
Whale Mutant #7
COM EXE
4983C30249C35AE8F4FF742EEBF9520E1FE8230081EA
;
Whale Mutant #8
COM EXE
49F61F83C30249C35DE8F4FF7430EBF9550EF81FE82300
;
Whale Mutant #9
COM EXE
5B415956BE6625FF14F85E42505A90E80100F85B81EB9F23
;
Whale Mutant #10
COM EXE
5B5955FF3666255D3EFFD55DE80000B984235B81EBB623
;
Whale Mutant #11
COM EXE
5B59B440E8BA01EB0C5B530E1FC3E82A0075FBEBEBE8F1FF
;
Whale Mutant #12
COM EXE
5BB44059E8BA01EB0C5B0E1F53C3E8290075FBEBEBE8F1FF
;
Whale Mutant #13
COM EXE
67254EFF14E8020033DE81F676185B5E81EB9F23B98523
;
Whale Mutant #14
COM EXE
852381EBA923FE0F43E2FB558BEB81C58E0033C03E807E0001
;
Whale Mutant #15
COM EXE
91FF166625EBEE5BB985230E81EB9F231F8A47FFFEC8
;
Whale Mutant #16
COM EXE
9383EB1DB9C3118A072847FF4B4BE2F7803E3324017416
;
Whale Mutant #17
COM EXE
93B9C31183EB1E8A170057FF4BF54BE2F6803E3324017415
;
Whale Mutant #18
COM EXE
CA8EDAE80300D7EBF65A81EA9D23F987DAB98A2CF881F10F0F
;
Whale Mutant #19
COM EXE
D7585B59FF166625E80300BB01565B81EB9F23B93489
;
Whale Mutant #20
COM EXE
DB1F81C361DCE81E00BA02008137060403DAE2F881C38D00
;
Whale Mutant #21
COM EXE
DB1F81C361DCE81F00B8020081379A239001C3E2F781C38D00
;
Whale Mutant #22
COM EXE
DB5B81EB9F23E81E00B802008137380101C3E2F881C38D00
;
Whale Mutant #23
COM EXE
DC5901CB0EB9C4111FFEC943812FFE0043E2F85689DE81C68D00
;
Whale Mutant #24
COM EXE
DC5958935891B43FFEC4E8810158EBD28CCB8EDB5A52C3
;
Whale Mutant #25
COM EXE
DCB986230E33C81F8037E801C32BC875F781C38F00FE0F
;
Whale Mutant #26
COM EXE
DCB9C1118B0743430107E2FA81C39200807F010174E106
;
Whale Mutant #27
COM EXE
DDEB2AE80100C359BB61DC01CB0EB9C3101FFEC5290F
;
Whale Mutant #28
COM EXE
DFE82B0087D381C361DCB9C311E8E0FFF6063324FE74E1
;
Whale Mutant #29
COM EXE
E6FF75FB585BFB59FF3666258F069A25FF169A25E80000
;
Whale Mutant #30
COM EXE
F9595B87CBE8B501EB078CC88ED8E80200EBF7582D9C23
;
Whale-B Mutant #31
COM EXE
FE0743E2FB5B59FF166625E800000E1F5B81EB9F23B985
;
Whale-B Mutant #32
COM EXE
FF16662590E800009C9D0E50581F265B240581EB9F2324
;
Whale-B Mutant #33
COM EXE
E8000095930E93951FFC5B161781EB9F23FC36B988239C802F03F8
;
Whale-B Mutant #34
COM EXE
920E921F365B575081EBA023585FB9842350280F5158435991
;
Whale-B mutant #35
COM EXE
9543E2F89D5B555D59FF166625FCE8000095930E93951FFC
;
Whale-B mutant #36
COM EXE
FB81EB9F23FCB98523528037415A4390E2F750FE8F8E00
;
Wisconsin Virus
COM
B4402E8E1E2B012E8B1E31018BCF33D2CD21
;
Wolfman Virus
COM EXE
1800CD21B802428BCACD21B440590E1FBA0001CD21B4
;
Word Related Virus
COM EXE
5B89871?008B870000A300018A870200A2020153B84230B96719BB917633D2CD21
;
WWT Related Virus
COM
01B44EB90100CD217302EB1?%EE80F00BA8000B44F
;
Yankee Doodle Related Virus
COM EXE
53BB??00F8B803C?CD215B7?
;
Yaunch Virus
EXE
5C012BDB8A058A2032C48805473BFA730A4383FB0A72ED
;
Zero Bug Virus
COM
5A45CD602EC606250601902E803E2606
;
Zero Hunt related Virus
COM
A483EB0426891E020026C7060000F5E9BFCFCFC53690
;
Zero Translator Virus
COM LOW HIGH
5657B800B88ED8BB00008A073C307502B04F88074343
;
ZK-900 Virus
COM EXE
BD0D270E1F8CC1B82135CD2126817F025A4B74722E8C868002
;
;
;
; DO NOT DISTRIBUTE MODIFIED COPIES OF THIS FILE!
;This file carries a sanity check. Do NOT change the checksum! Add your own
;info BELOW the cheksum line at the bottom of this file.
;TITCVD538
;
;
;*****************************************************************************
; This John Ross virus is added by me after getting the signature from
; Frans Veldman. It's just the first detection of this new virus. If you
; have been infected via B190BETA.ZIP (BNU.COM) - run TBSCAN *.* -A -REN
; to find it. No other scanners today (911204) detects this new virus.
; I got my BBS infected by it - and without the fast and good help of
; Frans Veldman I might have lost *many* of my 60.000 files...! As soon
; there is a new release of TBSCAN.DAT out with the final signature, I'll
; UL it to Salt Air. This one is just for a fast help.
;
; Best wishes - Peter Laur / Murphys PCBoard BBS - Sweden
;*****************************************************************************
JR Virus
COM EXE
AC32C4AAE2FAC3%FB440CD21
;
Comments
Post a Comment