Virus Database


Invol Family

Description Invol Family

These are dangerous memory resident parasitic viruses. They infect EXE and SYS files. These viruses are polymorphic in the EXE files.
When an infected EXE file is executed, the virus opens the C:CONFIG.SYS file, looks for the first SYS file which is pointed by the "DEVICE=" string, and infects it. If there are not such SYS files, the virus in some cases creates the dummy VANSI.SYS file and places the command DEVICE=VANSI.SYS to the beginning of CONFIG.SYS file.
When the computer boots from the 'infected' CONFIG.SYS, the virus stays resident as a system driver, hooks INT 21h and writes itself to the end of EXE files that are executed.
These infectors contain the text strings:
c:config.sys EVICE C:vansi.sys device=vansi.sys vansi

On the 19th of any month they erase the FAT of C: drive, and display the message:
You have helped spread this virus.
This has been a message from your friendly
neighborhood infection service.
Thank you for your involuntary cooperation.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Foxz

Description Macro.Word.Foxz

This virus contains four macros in documents and eight in NORMAL.DOT:
Documents NORMAL.DOT
AutoClose AutoClose
AutoOpen AutoOpen
Action Action
Foxz ToolsMacro, FileTemplates, ToolsMacro, ViewToolbars,
HelpWordPerfectHelp

The virus infects the global macros area on opening an infected document (AutoOpen). It infects documents that are closed (AutoClose).
It modifies the Windows 95 register information. It contains the comments:
/---------------------------------------------------------------| You know Phardera?,he is X-SLAM member who kick out from SLAM |
| and USE my Name [foxz] for spaming SLAM VIRUS TEAM. |
| His real Name is Anton Reinhard Pardede!, he is a "Mikrodata |
| Crewz"(Computer Magazine in my country), as long as I know, he|
| work on Virus Division on that Magazine. |
| By this virus I want everybody know that "the fucking lamer |
| who Spaming SLAM" is not Me [foxz] |
| Regards, |
| Foxz/NoMercyVirusTeam Leader |
---------------------------------------------------------------/
------------------------------------------------------------
Code Name : WM.FoxZ Gn.III also know as "WinFake"
Author : Foxz [NoMercy]
Origin : Yogyakarta
Dedicated : for the fucking lamer "Phardera" who spaming SLAM
VirusTeam with my Name !
Greetz : Cicatrix, SLAM Crewz and NoMercyVirusTeam Crewz
Group : NoMercyVirusTeam
Effect : Change Windows 9x Register !
Thanks to : CJC, Lucifer, Gurita, CrazyMan, Aurodreph and You
who was see this Text !, see you in my Next virus :)
------------------------------------------------------------
October 30 '97
THANKS FOR SLAMVIRUS TEAM FOR THIS INFO !!! (SLAM mag)

Macro.Word.Friday

Description Macro.Word.Friday

This is an encrypted German-specific macro virus. It contains three macros:
Documents NORMAL.DOT
AutoOpen NOPO
NOPS DateiSpeichern
NOPSA DateiSpeichernUnter

It infects the global macros area on opening an infected document (AutoOpen) and copies itself to documents that are saved (DateiSpeichern, DateiSpeichernUnter - FileSave, FileSaveAs).
Depending on the system date and time the virus sets a password for current document or/and exits Windows. On Friday13th it sets the password "Friday13".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com