Gisela.702
Description Gisela.702
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. While installing memory resident the virus also infects the C:COMMAND.COM file. On January 21th the virus decrypts and displays the message: Virus GISELA 2.0 By EJECUTOR (Hecho en Argentina) Feliz cumpleaños Gisela.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Showoff
Description Macro.Word.Showoff
text (c) Michal A. Egler This virus contains the following encrypted macros: Hayo, AutoOpen, Nomercy2, Organizer, ToolsMacro, FileTemplates. On the 13th day of any month the virus creates the file C:WINDOWSSYSTEMNOMERCY.DLL. This file contains a debug script with the NoMercy.575 DOS parasitic virus dump code. By using this script the virus creates the virus dropper NOMERCY2.COM. Next the virus deletes files: C:*.BAT C:*.SYS C:WINDOWS*.GRP C:WINDOWS*.DRV C:WINDOWS*.DLL C:WINDOWSSYSTEM*.DRV C:WINDOWSSYSTEM*.DLL
It also inserts the following commands into the AUTOEXEC.BAT file to execute the virus dropper: @echo off nomercy2.com
After restarting the computer the virus code stays resident and infects each executed COM and EXE file. The virus displays a UserDialog containing the text: No Mercy II [Hell on WinWord], The Madness Continuesall.. wall NoMercy II ©1997 by CrazybitS From the land of Smoking Vulcanoes and Gamelan Orchestras This Macro Virus Was Released for follow his brother No Mercy
Sometimes the virus changes names of macros: Nomercy = AutoOpen AutoClose = Nomercy2 AutoExec = Hayo ToolsMacro = ToolsMacro Organizer = Organizer FileTemplates = FileTemplates
Sometimes the virus displays a UserDialog with the text: No Mercy II Was Distrub ! Mmmmm.... you just lost your files ! Don't do it again !
Macro.Word.Shuffle
Description Macro.Word.Shuffle
This is a stealth Word macro virus. It contains one macro in documents (AutoOpen) and four macros in NORMAL.DOT (XXXXX, FileSaveAs, ToolsMacro, FileTemplates). The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are saved with new name (FileSaveAs). The virus infects the documents in usual way, while infecting the NORMAL.DOT the virus deletes all macros in there, minimizes the Word window, and copies its macros string-by-string to the global macros area.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
David Soard Proxy Server Free Myspace Proxy Server Free Unblocked Proxy Browse Unblocked Proxy Websites
|