FaxFree.594
Description FaxFree.594
These are dangerous memory resident parasitic encrypted viruses. They hook INT 21h, and write themselves to the end of EXE-files (except SCAN.EXE and VSHIELD.EXE) that are executed. FaxFree.1536 On the 25th and 26th of every month, "FaxFree.1536" erases part of the DOS data. In some cases, it erases disk sectors. It also contains the following internal text strings: FaX Free!! P. 0.9 Welcome
FaxFree.Abstract.1024 This is a harmless encrypted virus. It contains the internal string: MOSQUITO DOS 7.00 NODOSACT SPECIAL THANKS TO MAXCC (c)91-92 rel.2soon ABSTRACTSPACE P. 0.98 Rev 4 24IX89 bye bye Copy at your own risk
FaxFree.Darkover.1536 This is a dangerous encrypted virus. It overwrites disk boot sectors with a Trojan program, and displays the following message: P. 1 Rev 5 DarkOver bye bye
It also contains the internal strings: Work Area stopHello this is the core Rev 5 5/17/91 P 1c DarkOver CopyRight Fry/05/17/91 S.U.D., Inc.
FaxFree.Fago_t2 In some cases, it displays the text message: Umb ho utilizzato solo il virwork di DarkOver bye bye Fago_T2 new name 2/4/92
Sometimes it overwrites the boot sector of the current drive with a Trojan program. This virus also contains the internal texts: Work Area stopHello this is the core Rev 5 5/17/91 P 1cFago_T2 data add 0022 year 0025Fago_T2 count add 0027 cs 002b FAM Associates. Kill with us F.A. from PE, Italy. Help us!
FaxFree.Mecojoni Depending on the system date, these viruses erase disk sectors and display: Ti sentivi sicuro. Avevi lo SCAN !!! Invece lo hai preso nel culo. Infatti il virus MECOJONI ti ha formattato l Hard disk. MECOJONI è un virus self-modifying!
These viruses also contain the internal strings: Microsoft BASIC 7.1 (C) 1990-91 VDSOFT91
FaxFree.Mosquito Sometimes it hangs the computer. It contains the internal text strings: WorZ ,-a stop Hello this is the core Rev 3 26/4/91 P 0.98c P. 0.98 Rev 4 24IX89 bye bye Mosquito
FaxFree.Pinniz These are encrypted viruses. Depending on the system date, they erase DOS data at address 0000:05xx. They contain the internal strings: "FaxFree.Pinniz.a,b": Noi Otto **Pinniz** Campagna contro la Pirateria Partecipate tutti!!! Vettore PISello ver 2.01 12-2-91
"FaxFree.Pinniz.c,d": Noi Otto **Pinniz** Campagna contro la Pirateria Partecipate tutti!!! P. 0.9 Welcome
FaxFree.Pisello "FaxFree.Picello.1024" is harmless virus, "FaxFree.Picello.1536" erases DOS data. These viruses contain the texts: "FaxFree.Picello.1024": My name is PISello BYE 31-1-91 "FaxFree.Picello.1536": PISello ver 2.0 12-2-91
FaxFree.Sultan.2766 This is a benign virus that displays: Your pc is ready to leave this world! See u later :) Friendly, your Sultan.
It contains the internal string also: Hello Sultan (c)1992 AZV inc. copy at your own risk!
FaxFree.Topo This is a harmless virus containing the encrypted strings: FaX Free!! 0.9 Welcome COMSPEC=C:DOSCOMMAND.COM PATH=C:DOS;C:WIN3;C:;C:TOPO;C:UTILITY PROMPT=$p$g TEMP=C:WIN3TEMP
FaxFree.Tower This is a benign virus. If the infected file is altered, the virus decrypts and displays the message: THE LEANING TOWER antibiotic Virus actived Warning!! I have detected a dangerous VIRUS in the file you have now loaded Re-Boot your system and delete the file
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Alliance
Description Macro.Word.Alliance
This virus contains only one macro in infected documents - AutoOpen, but while infecting the system it copies it to two macros - AutoOpen and AutoNew. As a result, the virus infects the system on opening an infected document, and infects the documents that are opened or created. The virus sets Subject in the FileSummaryInfo to: You Have Been Infected by the Alliance
Macro.Word.Anak
Description Macro.Word.Anak
This is an encrypted macro virus. It contains four original macros that are copied to five ones while infecting documents and NORMAL.DOT: Documents NORMAL.DOT Macro1 anakAE AutoExec Macro2 AutoOpen anakAO anakAO Macro3 anakSA FileSave anakSA Macro4 anakSMU anakSMU
The virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to document on saving them (FileSave). The virus defines new short cut key "Shift-Ctrl-F" and associates it with Tools/Customize menu. To hide its macros (stealth feature) the virus removes the File/Templates, Tools/Macros and Tools/Customize menus. Starting from 25th of any month, starting from 14:00 the virus creates new template, inserts the text into there: alli n t r o d u c i n g... anakSMU Semarang, March 1997
The virus then registers itself in the system. To do that it creates the ANAKSMU.BAT file, writes the commands to there and executes it: @ECHO OFF REM --------------------------------------------------------- REM anakSMU wont destroy your REGEDIT, Just wanna be there :) REM email: anakSMU@TheOffice.net" REM --------------------------------------------------------- ECHO REGEDIT4 > anakSMU.REG ECHO [HKEY_CURRENT_USERSoftwareanakSMU] >> anakSMU.REG ECHO [HKEY_CURRENT_USERSoftwareanakSMUanakSMU@TheOffice.net] >> anakSMU.REG ECHO [HKEY_CURRENT_USERSoftwareanakSMU18.090 - Semarang] >> anakSMU.REG START /MIN REGEDIT anakSMU.REG EXIT
The virus then displays the MessageBox: anakSMU Yeah!, I wish I were anakSMU
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Property Investment Company Cd Top10 Spiegelreflexkameras PERSSON & WIDNER BIL AB
|