PHP.Aristotle
- Language: PHP
- Author: synge
- Size: 2,624 bytes
Desc:cross infector, prepender .
View Source
W32.ActiveAngel.1
- Language: VB6
- Author: Genetix
- Size: 10,291 bytes
Desc:Prepends to random files in the current directory, has flashing colors payload.
View Source
W32.Nurofen.worm
- Language: VB.NET 2005
- Author: Genetix
- Size: 20,480 bytes
Desc:Worm MSN & ZIP/RAR spreading
View Source
Perl.StarPerl
- Language:Perl
- Author: Genetix
- Size: 6,239 bytes
Desc:EPO/Polymorphic(trash&var changing)/pl/cgi & perl module infection
View Source
TCL.Gentix
- Language:TCL
- Author: Genetix
- Size: 13,328 bytes
Desc:This is a concept for one of the first TCL virus
View Source
MSIL.Liar
- Language:VB.Net
- Author: Synge
- Size: 28,672 bytes
Desc:This is an mirc/p2p worm that uses encryption in part of it. It breaks off into sections to help avoid detection and has a time payload.
View Source
SO.Lovestar
- Language:SB/VBx
- Author: Necronomikon
- Size: 218,856 bytes
Desc:When Lovestar gets executed it drops a debug script of a converted sxw.file (StarOffice7 Textdocument),the macros in the sxw.file
gets executed,it infects the global Template of StarOffice and displays a lovelyric in one of 3 differnet languages (german/polish/english),
after that it drops a VBS to infect the global template of MSWord. The injected code opens the before dropped "lovestar.doc" for writting
and writes the read lovestar.sxw in it.
View Source
JS.Polycrypt
- Language:Javascript
- Author: Genetix
- Size:5,658 bytes
Desc:The main reason for this virus is to show you how polycryption works.. the problem was that all the code apart from the
polycrypted code is static, so this is why i added variable changing and body moving.
View Source
Rabbit.VBS.PurpleHaze
- Language:vbscript
- Author:Necronomikon
- Size:1,471 bytes
Desc:Its not a virus, a trojan or worm its the 1st malware Rabbit written in VBS.
View Source |
AV Report
MSIL.Yeha
- Language:C# .net 2.0
- Author:free0n
- Size:1,471 bytes
Desc:Network spreading worm that spreads by finding open network shares and by p2p. The worm has a payload which creates its own shared folder and admin user account..
View Source
MSIL.Snoopy
- Language:C# .net 2.0
- Author:free0n
- Size:1,471 bytes
Desc:A Prepender virus that also has it's own mass mailing that works by searching for email addresses in files. Also has a DNS MX lookup for finding mail servers.
View Source
Linux.Prometheus
- Language:ASM
- Author:impurity
- Size:1,352 bytes
Desc:Prometheus is the first x86-64 virus developed. It works by poisoning the .NOTE section. Pads and prepends original file. Adds point to viral code to .dtors
Runs on x86-64 linux // tested on AMD64 SELinux
View Source
MSIL.Loki
- Language:C# .net 2.0
- Author:free0n
- Size:36,864 bytes
Desc:First C# .net 2.0 poly virus. Infects files in the current program directory. Has the ability to encrypt itself and dynamically generate the decryptor on the fly. Payload runs a screen saver saying "You have been infected with MSIL.Loki by free0n"
View Source |
AV Report |
AV Report 2