Horror.1112
Description Horror.1112
These are very dangerous memory resident encrypted parasitic viruses. They hook INT 13h, 21h and write themselves to the end of COM and EXE files that are executed. Depending on the system date these viruses display the message: This is HORROR !
and erase the hard disk sectors. They also contain the string: COMSPEC
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Vivi.a
Description Macro.Word.Vivi.a
This is the encrypted Word macro virus. It contains seventeen macros: Documents NORMAL.DOT AutoExec Vaca AutoOpen AbreAiMeu FeCheiCya AutoClose DiaAgora DiaAgora Acao Acao ToolsMacro ToolsMacro Invisivel ToolsCustomize Invisivel FileTemplates FerramMacro FerramMacro Invisivel FerramPersonalizar UtilMacro UtilMacro Invisivel UtilPersonalizar Invisivel Invisivel KillChico KillChico EliaShim EliaShim AlevirusSCS AlevirusSCS Ale Ale
The virus infects the global macros area on opening an infected document (AutoOpen). It infects the documents on closing (AutoClose). The virus has stealth ability: it replaces the Tools/Macro menu. On May 19 the virus inserts into the C:AUTOEXEC.BAT file the hard drive formating instruction. It also erases the directories C:VDOC, C:CHICO. The virus creates and plays the "C:WINDOWSVOZALE.WAV" sound file. It displays the dialog window with the text: Visite a pagina das Putas!Aideticas!! Bem vindo novamente!!ola sou eu denovo Viviane Veloso!! Gostaram de minha foto peladona então não perca tempo pegue o telefone e ligue para mim, adoro dupla penetração anal e oral!! Namorado CORNO Telefone da EMPRESA = (011)4502331 Nome = NEY Corno conformado (011)2151966 Telefone da minha casa ligue para o CORNO tb
The virus contains the comments: Macro Virus Criado Por Alevirus S>C>S 02/26/98 Brasil Virii Maker's Voce Decryptou muito bem!!!! Parabens!! Shit voce não coisa melhor pra fazer do que ficar abrindo Virus dos Outros??? <Virus> Vivi
Macro.Word.WallPaper
Description Macro.Word.WallPaper
This is an encrypted macro virus. It contains two original macros, but while infecting global macros area the AutoOpen macro is copied to four macros: Documents NORMAL.DOT FilePrint -> FilePrint autoOpen -> autoOpen ToolsMacro FileTemplates ToolsCustomize
The virus infects the documents on all calls that are listed above (opening or printing a file, entering menus File/Templates, Tools/Macro, Tools/Customize) and copies itself to global macros on opening an infected document. The virus drops the SK2.BMP file that contains an image of a death's head.
On the 31th of any month the virus modifies the profile section [Desktop] (the WIN.INI file): [Desktop] Wallpaper=SK2.BMP TileWallPaper=1 SK2=
and increases SK2 value on each infection. It also creates the C:WINDOWSREGSK2.REG and writes the text to there: REGEDIT4 [HKEY_CURRENT_USERControl PanelDesktop] "TileWallpaper"="1" "Wallpaper"="C:\WINDOWS\SK2.BMP"
The virus then appends the following commands to the C:AUTOEXEC.BAT file : @echo off c: cd c:windows copy /y SK2.BMP c:windowssk2.bmp >nul regedit regsk2.reg >nul
On the same date (31th) the virus, depending on the system time, displays the dialog: [!!!PIRATE VIRUS!!!]-- Active! The [PIRATE VIRUS] has pillaged your computer! GO BACK TO MS-WORD??
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
TandlÄkare Anders Fridholm Aktiebolag Dfs - Agentur Nacka Dator & Kommunikation Aktiebolag Benny's MaskintjÄnst I Molkom Colosseumkliniken Sverige Ab
|