Virus Database


Geri.476

Description Geri.476

This is a harmless, non-memory resident encrypted parasitic virus. It searches for .COM files in the current directory, then writes itself to the end of the file.
The virus contains the following text strings:
*.COM
v 1.1 by Geri$oft, 95.01.28.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.GamesVirus

Description Macro.Word97.GamesVirus

This virus contains seven macros in one module "GamesVirus": AutoExec, AutoOpen, FileSaveAs, FileTemplates, PayLoad, ToolsMacro, ViewVBCode.
It infects the global macros area on opening an infected document and infects documents on opening or saving with new name.
On entering the Tools/Macro and File/Templates menus the virus displays the MessageBoxes:
Microsoft Word
accès refusé!!!!
Microsoft Word
Fonction Sub inconnu

Depending on the system date and time the virus manifests itself in several ways. If current number of seconds is 1, the virus writes to the Subject field in FileSummaryInfo the text:
GamesVirus est avec vous, HAHA !!

If current number of minutes is 1, the virus writes the string to the StatusBar:
Remerciement à GamesVirus et à son auteur: ZeMacroKiller98

On tje 1st of any month it calls the Payload macro which displays several MessageBoxes and user forms. Depending on user's input the virus display MessageBoxes, erases system files, appends to the end of C:AUTOEXEC.BAT file instructions that format the hard disk, or in cycle draws the text in the status line:
Tu es le meilleur, bravo de la part de GamesVirus et de son auteurall.

Macro.Word97.Gelap

Description Macro.Word97.Gelap

It is stealth macro virus. It contains seven macros in one module "AuAhGelap": AutoOpen, AutoClose, Au, Ah, ToolsMacro, Gelap, ViewVBCode.
It infects the global macros area on opening an infected document (AutoOpen) and infects other documents on opening and closing (AutoOpen, AutoClose).
The virus turns off the Word virus protection (the VirusProtection option). It also disables the Tools/Macro menus and Visual Basic Editor (stealth).
Before infection the virus checks user name and if it is not "Sembako" displays the baloon:
Hello <UserName>
Sorry, but your Microsoft Word doesn't belong to you any more.
Now it is mine!!

After that the virus changes user name to "Sembako" and user initials to "SBK".
Between 8:00am and 9:00am the virus displays the message:
Selamat pagi
Selamat pagi cewek-cewek yang cakep-cakep.

Between 12:00pm and 2:00pm the it displays:
Selamat siang .
Hallo cewek-cewek, udah pada makan siang belum ?
Sekarang udah jam <current time> loh. Salam sayang buat kamu
semua dari my creator.

After 5:00pm it displays:
Selamat sore.
Hallo cewek-cewek, kok belum pulang sih?
Sekarang udah jam <current time> loh. Eh, ada salam dari my creator.

On April 18th the virus sets the password "!@#$%BoMoH!@#$%" for active document and inserts into document the text:
Happy birthday to my Creator!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Wolfis Technik Blog
Genital Warts Removal
Bele Byggnads Ab
S1 I HÄrnÖsand Ab
HammarÖ DÄck & Bil Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com