Virus Database


Exile.255

Description Exile.255

It's a dangerous memory resident parasitic virus. It copies itself into the Interrupt Vectors Table, hooks INT 21h and writes itself to the beginning of COM-files that are executed. On installation depending on host file's data it erases the disk sectors and displays:
I'm Vindictive Exile!

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Mercy

Description Macro.Word.Mercy

This is the encrypted Word macro virus. It contains six macros in documents: Autoexec, AutoOpen and four macros with random names. The infected NORMAL.DOT contains eight macros: AutoClose, ToolsMacro, FileTemplates, Organizer and four macros with random selected names.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are closed (AutoClose). The names of random named macros the virus saves in document's variables (in case of infected document) or in the WIN.INI file in the [Intl] section in strings Here_1, Here_2, e.t.c (in case of NORMAL.DOT). The virus detects itself in the system by the string "I_am_Here" in the [Intl] section.
On 11th of any month the virus displays the MessageBox:
Episode 2: TenFaces [the series continueall]
The 10Faces is back! hey AVers the name is 10Faces!!
not Mercy.A -(c)reator of NoMercy-

The virus contains the commented text:
Hiya Pyro are you decrypt again !
I don't borrow the code from "Outlaw" anymore
(it's now original)
this random code is smaller than before and better randomize result
Using Simple-Little-Fast -random generator
Thankz to ya Pyro without your critics this never happen

Macro.Word.Messa

Description Macro.Word.Messa

This is an encrypted macro virus. It contains 21 macros: CUS, EOP, ESA, NIZ, PLT, WEV, CROM, CUST, ESAA, INFO, MESSA, WATCH, BEEPER, README, AutoExec, AutoOpen, FileOpen, FileSave, FileSaveAs, TheVWarning, POO.
The virus infects the system on opening an infected document - it copies this document with new name THEVWARN.ING to Word Startup-Path and User-Dot-Path. As a result the virus will activate each time Word will start (Word reads and loads templates from Startup-Path and User-Dot-Path). The virus also infects the global macro area. The documents get infection on opening and closing.
Depending on the current time the virus hooks timer and sets on timer the BEEPER macro. It also runs the OOP macro (it is renamed POO) that on pressing Alt-Ctrl-Shift-K is runs the TheVWarning macro. TheVWarning macro in one minute runs the WATCH macro. The WATCH macro renames the macros:
OEX - AutoExec
OOP1 - AutoOpen
EOP - FileOpen
ESA - FileSave
ESAA - FileSaveAs
NIZ - Organizer
CROM - ToolsMacro
PLT - FileTemplates
CUS - ToolsCustomize
CUST - ToolsCustomizeToolbar
WEV - ViewToolbars

The BEEPER macro beeps and displays the MessageBox:
I am so sorry. I do not mine it to disturb You.
But maybe all there is something that You have to do! <Time>
THE 'V' WARNING <Date>

The MESSA macry displays the message:
THE 'V' WARNING MESSAGE
Sorry to interrupt You. I think You are tired,
because You have worked until midnight.
so I suggest You to go to bed now and
tomorrow You could work harder than this day.
Kota Pelajar, Yogyakarta.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Haftpflichtversicherung
Kredite Beantragen
Online Cash Advance
Bra Bil I EnkÖping Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com