to
all the virii creators and virii creating groups:would you like your virus
to be known? or would you just like to help me out? then please!
send me the virus in a compressed format(zip,tar). contact me
first and i will give you instructions on where to send the file!
my icq number is 1778355. if you see me on there, just
send the file! thank you very much for your help!
WM.Drokz by Nightmare Joker[SOS] |
Drokz, the smallest WM
viruses ever, between 26 and 42 bytes. (added january 13) |
WM97.IIS v1.1 by Flitnic[SOS] |
That is a class- virus
without any stealth, whois able to change all his
variables on each normal.dot-infection. The first
infection will be very slow but all following will be
very fast! (added january 07) |
XF.BlackFriday by Foxz[NVT] |
A polymorphic XF virus. (added january 07) |
HTML.ZULU by Zulu |
VBScript virus that
infects HTML files. It only needs one "Yes" to
the Active X question of Internet Explorer, after that,
it will infects HTML files at startup using a
".VBS" (Windows Scripting Host) file. Does
nothing besides duplicate and show message the first of
each month. Easy to modificate (some payback maybe?) and
could be used with one of the Cuartango holes in Internet
Explorer for easy infection. (added january 05) |
Word97.It's Zippy.C Virus v1.2 Class by ?? |
polymorphic & SR1/2. (added december 21) |
Word97.It's Zippy.B Virus v1.1 Class by ?? |
polymorphic & SR1/2. (added december 21) |
Word97.It's Zippy.A Virus v1.0 Class by ?? |
polymorphic & SR1/2. (added december 21) |
Sayin 1.0 by LordX |
virus my in vb6. Writes
Garbage To Comctl32.dll rendering Win 3.11, Win 95,
Win98. (added december 21) |
Friday the 13 Virus by ?? |
When the virus is active
on Friday 13th an infected program is deleted when run. (added december 17) |
One-Half Virus by Vyvojar |
Virus infect EXE/COM
files and partion. It hides the length of files and
content of partion. It tries to be polymorphic, but
decryption loop isn't very good. It has an unique
destructive action: after each bootup, the virus encrypts
two tracks on HD and when they're accesed the virus
decrypts them again. Normally the disk works ok and the
user doesn't see anything, but when the virus is removed,
nothing decrypts data back and a part od a disk is
destroyed. For user it's better to not destroy the virus. (added december 15) |
Cross.Wonder V2.0 by the weird genius |
Encrypted cross type! (added december 13) |
Cri-Cri by gryio |
This is a polymorphic and
full-stealth infector of .COM and .EXE executables and
floppy boot sectors. Cri-Cri was my first virus. (added december 9) |
Gollum by gryio |
The virus drops a VXD
(virtual device driver) that will infect all .COM and
.EXE files executed inside a MsDos box. This virus is
encrypted and uses some retro structures. (added december 9) |
Hantavirus by gryio |
Hantavirus was designed
as an experimental especiment for Windows 95 plattaform.
The virus goes memory resident by allocating some shared
memory (using VMM services exported to Win32). In order
to intercept accessed files the virus hooks Windows calls
to VWIN32 int21h dispatcher. The main virus body is
hidden inside a complex polymorphic decryptor that
contains calls, conditional jumps and lots of garbage
code. (added december 9) |
Marburg by gryio |
Marburg is a direct
action Windows 95 .EXE and .SCR files infector (portable
executable files). This is the first Windows 95
polymorphic virus. (added december 9) |
Parvo by gryio |
Parvo is a polymorphic
Win32 virus which is using a new way of spreading. The
virus infects a few specified files at the computer, ie.
file infection aint the main method used to infect other
computers. (added december 9) |
Sucksexee by gryio |
Sucksexee (aka Implant)
is based on Cri-Cri virus but much more enhanced. This
time the virus infects .COM, .EXE, .SYS, floopy boot
sectors and hard drive Master Boot Record. Sucksexee is a
polymorphic and full-stealth retrovirus that uses lots of
advanced features like slow mutation, extra track on
floppies, recursive partition... (added december 9) |
Word97.Furby v1.2 3/4 Class Virus | Tiny polymorphic and love
the registry. (added december 8) |
Satellite V1.5 by the weird genius |
The 1st encrypted WM97
Macro virus. I've called it WM97.Satellite. This one also
checks if a document has been changed and will ask the
user to save the changes he made to his document. When I
look at it now I thing it's pretty lame as I already
improved it significantly using other methods. But
anyway, here it is, have fun. No payload, just
replicating. (added december 7) |
KÓB by Scorn |
The KÓB virus is my
first polymorphic virus; it's for that it's an
overwriting one. The viral code is encrypted and the
encryptation routine mutates with changing the registers
and adding some useless instructions. Morever, the virus
can't be find by F-Prot 3.0 KÓB infects three EXE
archives files in the current directory. First day of
each month, the virus displays the message. "Mort au
FN!" with beeps and halt the computer. (added december 7) |
Padania | Memory Resident Win95 PE
Infector. Similar methods to Mark J. (added september 10) |
GWAR/Messev | Messev drops GWAR. GWAR
is a Win95 Compatable MBR bug. (added september 6) |
INCA | The First Ever Win95
Multipartite Virus!! Two layers of poly and IRC
spreading. (added september 6) |
Paykiller-21 | no info available. (added september 6) |
Shiver[DDE] | Office 97 Cross
Application Macro Virus (Excel/Word). (added september 6) |
Titanic | activates every April 15 (added september 5) |
DNA.Dropper | It releases the DNA COM
infector and runs the virus immediatly. DNA only spreads,
no harmfull payloads. Source code included. This was
written by The Wierd Genious (added september 2) |
mIRC Worms | here is a little goodie i
found for you guys for the new month! (added september 1) |
Hostile Java Applets | You must be evil to put
this up on your webpage. These are java applets that can
cause some damage to a computer. (added august 31) |
Hare Virus | Not new, but i just felt
like uploading this. (added august 30) |
Linux Virus | Oh my god! its a linux
virus =O (added august 30) |
Strange Days | Virus which uses the
Class infection method. (added august 29) |
Sly 1 Bootv | A stealth boot infector. (added august 29) |
Groovie.B | A new strain of the
Groovie Word97 Virus. (added august 29) |
HellPhoria | A new EXE infector. (added august 29) |
Creed v1.2 | A non-resident prepender,
with limited stealth/retro. Infects
DOS/Win3x/Win95/WinNT/Os2Warp. (added august 29) |
IIS | Virus which uses the
Class infection method. (added august 29) |
Back Orifice Client\Server | Black Oracle server client, what this does is if someone is running the server on there computer(which is un-noticable) you have full access to there computer. utilizes windows winsock to connect to a person via there IP. |
CIH *All Versions* | infects win32 executables, playload: flash bios overwritten, data overwritten. |
CIH *TNN Version* | Author claims his version is much *nicer* because is does not overwrite bios or trash hard drives |
Mole | Win32 direct infector that "digs" its way into PE files. |
Woobie | Polymorpic Word 97 macro virus that runs from the "form" and "clas" sections of Word. |
Groovie | Word 97 Macro Virus Stealth, Multipartite Code and SR-1 Comatible. |
Net.666 | Win32 File Infector. Prototype "spy" program that use's TCP/IP controls. Also known as Semisoft.b |
Strang Brew | JAVA Class virus. Runtime infector of java class files. |
MarkJ | Memory Resident PE infector. |
MarkJ *TNN Version* | Version of MarkJ only TNN version. |
Ravage BSV | Win95 Compatable mbr virus. |
Cerebrus | Non-memory Redsident Win32 virus. Infects NE and PE files. |
vbVirus | A parasitic virus written in VB5. |
Memorial | Memory Resident, Semmi-Polymorphic virus that will infect Win 95 files and DOS exe and Com files. |
AVP antivirus | The Best Virus scanner protector ever made, also detects backdoors / cih and stuff. |
AVP Key genarator | To create a key for the avp 3.0, after that u can download upgrades for free. |
Je kunt me ook vinden op icq onder nummer:1778355 ik ben nu