Virus Database


Horror.1112

Description Horror.1112

These are very dangerous memory resident encrypted parasitic viruses. They hook INT 13h, 21h and write themselves to the end of COM and EXE files that are executed. Depending on the system date these viruses display the message:
This is HORROR !

and erase the hard disk sectors. They also contain the string:
COMSPEC

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Vivi.a

Description Macro.Word.Vivi.a

This is the encrypted Word macro virus. It contains seventeen macros:
Documents NORMAL.DOT
AutoExec Vaca
AutoOpen AbreAiMeu
FeCheiCya AutoClose
DiaAgora DiaAgora
Acao Acao
ToolsMacro ToolsMacro
Invisivel ToolsCustomize
Invisivel FileTemplates
FerramMacro FerramMacro
Invisivel FerramPersonalizar
UtilMacro UtilMacro
Invisivel UtilPersonalizar
Invisivel Invisivel
KillChico KillChico
EliaShim EliaShim
AlevirusSCS AlevirusSCS
Ale Ale

The virus infects the global macros area on opening an infected document (AutoOpen). It infects the documents on closing (AutoClose). The virus has stealth ability: it replaces the Tools/Macro menu.
On May 19 the virus inserts into the C:AUTOEXEC.BAT file the hard drive formating instruction. It also erases the directories C:VDOC, C:CHICO.
The virus creates and plays the "C:WINDOWSVOZALE.WAV" sound file. It displays the dialog window with the text:
Visite a pagina das Putas!Aideticas!!
Bem vindo novamente!!ola sou eu denovo Viviane Veloso!!
Gostaram de minha foto peladona então não perca tempo pegue o telefone e
ligue para mim, adoro dupla penetração anal e oral!!
Namorado CORNO Telefone da EMPRESA = (011)4502331 Nome = NEY Corno conformado
(011)2151966 Telefone da minha casa ligue para o CORNO tb

The virus contains the comments:
Macro Virus Criado Por Alevirus S>C>S 02/26/98 Brasil Virii Maker's
Voce Decryptou muito bem!!!! Parabens!! Shit voce não coisa melhor
pra fazer do que ficar abrindo Virus dos Outros???
<Virus> Vivi

Macro.Word.WallPaper

Description Macro.Word.WallPaper

This is an encrypted macro virus. It contains two original macros, but while infecting global macros area the AutoOpen macro is copied to four macros:
Documents NORMAL.DOT
FilePrint -> FilePrint
autoOpen -> autoOpen
ToolsMacro
FileTemplates
ToolsCustomize

The virus infects the documents on all calls that are listed above (opening or printing a file, entering menus File/Templates, Tools/Macro, Tools/Customize) and copies itself to global macros on opening an infected document.
The virus drops the SK2.BMP file that contains an image of a death's head.


On the 31th of any month the virus modifies the profile section [Desktop] (the WIN.INI file):
[Desktop]
Wallpaper=SK2.BMP
TileWallPaper=1
SK2=

and increases SK2 value on each infection. It also creates the C:WINDOWSREGSK2.REG and writes the text to there:
REGEDIT4
[HKEY_CURRENT_USERControl PanelDesktop]
"TileWallpaper"="1"
"Wallpaper"="C:\WINDOWS\SK2.BMP"

The virus then appends the following commands to the C:AUTOEXEC.BAT file :
@echo off
c:
cd c:windows
copy /y SK2.BMP c:windowssk2.bmp >nul
regedit regsk2.reg >nul

On the same date (31th) the virus, depending on the system time, displays the dialog:
[!!!PIRATE VIRUS!!!]-- Active!
The [PIRATE VIRUS] has pillaged your computer!
GO BACK TO MS-WORD??

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



TandlÄkare Anders Fridholm Aktiebolag
Dfs - Agentur
Nacka Dator & Kommunikation Aktiebolag
Benny's MaskintjÄnst I Molkom
Colosseumkliniken Sverige Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com