FishN6.a
Description FishN6.a
This is an encoded memory-resident very dangerous virus that hits COM and EXE files by standard way upon their execution and closing. In infected files it increases the year of last modification by 100. The virus supports practically all functions of a stealth-virus. FishN6 encodes its own body not only in files, but also in its TSR copy (on entering the system the virus decodes itself through the INT 21h chain, on exiting - it encodes itself). Since 1991 FishN6 hangs up the system reporting the following: FISH VIRUS #6 - EACH DIFF - BONN 2/90 Apart from this string, it contains the following lines: COD SHARK CARP BASS TROUT MUSKYZ SOLE PIKE MACKEREL FISH TUNA FISH FI The virus hooks INT 13 and INT 21h. If the number of current day is equal to the number of current month then this virus erases the disk C: sectors. This infector contains the internal text strings: Don't trouble trouble until trouble troubles you. (c)Fly
Check other viruses! Be aware! Use Antiviral Software
Macro.Excel97.Xlscan
Description Macro.Excel97.Xlscan
It is a stealth Excel97 macro virus. It infects workbooks on their closing. While infecting the virus saves its code in sheets as "class" macros (see also "Macro.Word97.Class"). It also creates the infected MsOffice8.xls file in the Excel startup directory and disables the Macro Virus Protection by direct access to system registry. Each time an infected document is being closed, the virus creates in the "C:WindowsSystem" folder several files with names generated using current date and time and extension ".INF"
Macro.Excel97.Yawn
Description Macro.Excel97.Yawn
This virus creates an infected workbook "PERSONAL.XLS" in the Excel start-up folder. Upon Excel startup, this workbook is automatically loaded and the virus gains control. The virus activates upon the opening of every workbook and infects it. To disable the Excel macro-virus protection, the virus uses calls to the system functions that directly modify the system registry. The virus hides itself by deleting the menu item "Tools/Macro". The virus has no any payload.
|