Virus Database


Gorgan.2718

Description Gorgan.2718

It is not a dangerous memory resident polymorphic, stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or created. The virus also infects the C:COMMAND.COM file. The virus scans the C:CONFIG.SYS file as well and infects files which are refferred in there. The virus deletes the antivirus data file: CHKLIST.MS. It doesn't infect files with names:
TOOLKIT, FINDVIRU, GUARD, SCAN, CLEAN, TKUTIL, VIVERIFY, INSTALL, CERT,
AUTHOR, FV, IMEN, AUTOHARD
The virus contains the text string:
This is 'GORGAN' by M.S.S(designer of 'sarcoma').

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Appder.a

Description Macro.Word.Appder.a

This Word macro virus contains two original macros, but while infecting documents copies them to three macros:
NORMAL.DOT Infected files
Appder -> Appder, AutoOpen
AutoClose AutoClose

The virus infects the global macros area on AutoOpen and writes itself to documents on AutoClose. It also creates the "NTTHNTA=value" line in the "[Microsoft Word]" section in WINWORD6.INI file and increases this value while infecting any document. When this value reaches 20, the virus deletes the files:
C:DOC*.EXE
C:DOC*.COM
C:WINDOWS*.EXE
C:WINDOWSSYSTEM*.TTF
C:WINDOWSSYSTEM*.FOT

Macro.Word.Archfiend

Description Macro.Word.Archfiend

This Word macro virus contains six macros: AutoExec, AutoOpen, FileOpen, ArchFiend, FileSaveAs, ToolsMacro (stealth). The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are saved with new name (FileSaveAs).
On 5th of any month the virus: on Macintosh erases all files and displays the MessageBox:
ArchFiend

On PC it erases BMP files in Windows directory (C:WINDOWS*.BMP) and creates the FIEND.TXT there containing the text:
##################
## WM.ArchFiend ##
##################
Nrsi:lshoi:m{{i:mhsnn t:st:St~ut is{{;
XOR by 1ah
Your Unlucky Number is: < ½ á ¡«Ñ ¿ ½«>

While saving a document with new name, if current time is 13 seconds, the virus sets for the document a random selected password. On entering the Tools/Macro menu the virus writes to the C:AUTOEXEC.BAT file the command:
echo BLOW ME!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Portugal Car Hire Algarve
Tongue Piercings
Vergleich Heizung
Free Proxy Ip Unblock Web
German Translation

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com