Tue 04th Jan 2000
Benny and Darkman finnished their newest creation Win2000.Installer. A runtime/direct action Win2000 virus, infecting files with ACM, AX, CNV, COM, CPL. DLL, DRV, EXE, MPD, OCX, PCI, SCR, SYS, TLB, TSP, VWP, WPC and MSI (Microsoft Windows Installer) extension. Features cavity infection and retro structures. Win2000.Installer is the first native Win2000 virus, released almost one and a half month before Win2000 is due to be released. Win2000 is also the first virus able to infect the MSI (Microsoft Windows Installer) extension.

Descriptions:
Win2K.Inta (AVP)
Inta (F-Secure)
Win2K/Inta (Network Associates)
W2K.Installer.1676 (Symantec)

News articles:
First Windows 2000 virus detected (CNN)
Windows 2000 virus: Stunt or preview? (CNN)
First Windows 2000 Virus Found (F-Secure)
First Windows 2000 Virus Debuts (IDG.net)
First Windows 2000 virus detected (Infoworld)

Fri 31th Dec 1999
29A would like to wish everybody a very happy new year.

Tue 28th Dec 1999
Prizzy finnished his newest creation Win32.Crypto. A resident Win32 virus, infecting files with EXE extension and KERNEL32.DLL. Inserts compressed droppers into ACE, ARJ, CAB, RAR and ZIP archives. Features a multi-layer polymorphism, Random Decoding Algorithm (RDA), anti-debugging techniques, retro structures and the OneHalf technique, making the OS dependent of the virus, by encrypting files with DLL extension with a strong encryption. Win32.Crypto is the first virus to use the OneHalf technique in the Win32 environment.

Descriptions:
Win32/Crypto (Network Associates)
W32.Crypto (Symantec)

Fri 24th Dec 1999
29A would like to wish everybody a very merry christmas.

Wed 22th Dec 1999
Bumblebee finnished his newest creation I-Worm.Plage 2000. A resident Win32 worm, replies unread messages and attaches itself to the replies. Features stealth and various other techniques.

Descriptions:
I-Worm.Plage (AVP)
Plage2000 (F-Secure)
W32/Plage.worm (Network Associates)
W32.Plage.Worm (Symantec)

News articles:
CA warns ‘Plage2000’ is in the wild (MSNBC)
Computer Associates Warns of 'Plage2000' Worm; CA Details Worm Threatening eBusiness Infrastructures (Excite News)
CA warns 'Plage2000' is in the wild (Excite News)
CA warns 'Plage2000' is in the wild (ZDNet)

Wed 22th Dec 1999
The Mental Driller finnished his newest creation Win32.Nazka. A per-process resident Win32 virus, infecting files with CPL, EXE or SCR extension. Features retro structures and a new and interesting way of doing polymorphism.

Sun 12th Dec 1999
Tcp finnished his newest creation Win32.Resurrection. A resident Win32 virus, infecting files with EXE extension. Features a new method of residency and a new and complex infection method.

Descriptions:
Win32.Resur (AVP)

Wed 1st Dec 1999
Bumblebee finnished his newest creation Win32.Anvil of Crom. A runtime/direct action Win32 virus, infecting files with DLL or EXE extension. Features polymorphism, anti-debugging techniques and SEH.

Fri 19th Nov 1999
Raquel and VirusBuster got married today, we wish them the best of luck in the future and many happy years together.

Fri 19th Nov 1999
We have come to start seeing an end of the upcoming fourth issue of 29A, a project which will take us a little less than a year to finish. To show our gratitute to those of you who have been so patient with us, we've decided to release a little something from the upcoming issue of 29A. We know it aint much, but we still hope it will make the waiting a little easier.

Navrhar disassembly

Descriptions:
Navrhar (AVP)

Sun 14th Nov 1999
Lord Julus finnished his newest creation Win32.Thunderpick v 2.0. A runtime/direct action Win32 virus, infecting files with EXE or SCR extension. Features polymorphism, anti-debugging techniques and retro structures.

Mon 8th Nov 1999
Benny finnished his newest creation Win32.Vulcano, he's currently looking for beta-testers, if you're interested in beta-testing Win32.Vulcano, please mail Benny at benny@post.cz.

Fri 5th Nov 1999
Lord Julus's newest creation Win32.Thunderpick is in its beta phase.

Thu 4th Nov 1999
GriYo's second simbiosis project is in its beta phase, more information about this will follow.

Wed 3rd Nov 1999
A new type of macro virus has surfaced. Macro.Office.Corner is the first virus known to infect MS Project projects aswell as Microsoft Word documents. However it is "only" runtime/direct action. The upcoming fourth issue of 29A will feature P98M.Project.A, the first resident virus known to infect MS Project projects, together with a tutorial on MS Project infection, both by jackie twoflower /LineZer0 /Metaphase-.

Macro.Office.Corner source code

Descriptions:
Macro.Office.Corner (AVP)

29A labs