|
|
SayNay Famil Viruses Information
| Name: |
SayNay Famil |
| Category: |
Viruses |
| Description:
|
Details
SayNay Family
These are not dangerous nonmemory resident parasitic viruses. They search for .COM files, then write themselves to the end of the file.
These viruses drop their source assembler code into ASM file. To do that the viruses contain this source code in their bodies in encrypted form, and that is why the length of the virus is more than 5K.
To drop that code the virus checks the command line for "NAY" argument. If that argument is found, the virus displays the message:
Magic! ;)
and creates the SAYNAY.ASM and SAYNAY.BAT files. Then the virus writes the source code to the SAYNAY.ASM file, and writes the strings:
TAsm /M2 SayNay.Asm
TLink /T SayNay.Obj
Copy /B SayNay.Com+SayNay.Asm
to the SAYNAY.BAT file. As a result there are two files - the former contains virus' source texts, and the letter contains instructions how to compile the source text and build the virus. Being executed BAT file runs Assembler and Linker to make the "intermediate" virus code that contains the binary code, but not the source text. Then the virus appends the source text to binary code by COPY command, and the result file contains the virus with its source text in not encrypted form. Being executed the virus encrypts that source text, searches and infects .COM files. |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Macro.Word.BadBoy.
W95.Gar
PHP.Piru
Estier.212
Caesa
Trojan.Win32.Agent.a
Win32.Bolzano famil
Jorgito.63
Gwa
Catscrf.55
|
|