Invol Family
Description Invol Family
These are dangerous memory resident parasitic viruses. They infect EXE and SYS files. These viruses are polymorphic in the EXE files. When an infected EXE file is executed, the virus opens the C:CONFIG.SYS file, looks for the first SYS file which is pointed by the "DEVICE=" string, and infects it. If there are not such SYS files, the virus in some cases creates the dummy VANSI.SYS file and places the command DEVICE=VANSI.SYS to the beginning of CONFIG.SYS file. When the computer boots from the 'infected' CONFIG.SYS, the virus stays resident as a system driver, hooks INT 21h and writes itself to the end of EXE files that are executed. These infectors contain the text strings: c:config.sys EVICE C:vansi.sys device=vansi.sys vansi
On the 19th of any month they erase the FAT of C: drive, and display the message: You have helped spread this virus. This has been a message from your friendly neighborhood infection service. Thank you for your involuntary cooperation.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Foxz
Description Macro.Word.Foxz
This virus contains four macros in documents and eight in NORMAL.DOT: Documents NORMAL.DOT AutoClose AutoClose AutoOpen AutoOpen Action Action Foxz ToolsMacro, FileTemplates, ToolsMacro, ViewToolbars, HelpWordPerfectHelp
The virus infects the global macros area on opening an infected document (AutoOpen). It infects documents that are closed (AutoClose). It modifies the Windows 95 register information. It contains the comments: /---------------------------------------------------------------| You know Phardera?,he is X-SLAM member who kick out from SLAM | | and USE my Name [foxz] for spaming SLAM VIRUS TEAM. | | His real Name is Anton Reinhard Pardede!, he is a "Mikrodata | | Crewz"(Computer Magazine in my country), as long as I know, he| | work on Virus Division on that Magazine. | | By this virus I want everybody know that "the fucking lamer | | who Spaming SLAM" is not Me [foxz] | | Regards, | | Foxz/NoMercyVirusTeam Leader | ---------------------------------------------------------------/ ------------------------------------------------------------ Code Name : WM.FoxZ Gn.III also know as "WinFake" Author : Foxz [NoMercy] Origin : Yogyakarta Dedicated : for the fucking lamer "Phardera" who spaming SLAM VirusTeam with my Name ! Greetz : Cicatrix, SLAM Crewz and NoMercyVirusTeam Crewz Group : NoMercyVirusTeam Effect : Change Windows 9x Register ! Thanks to : CJC, Lucifer, Gurita, CrazyMan, Aurodreph and You who was see this Text !, see you in my Next virus :) ------------------------------------------------------------ October 30 '97 THANKS FOR SLAMVIRUS TEAM FOR THIS INFO !!! (SLAM mag)
Macro.Word.Friday
Description Macro.Word.Friday
This is an encrypted German-specific macro virus. It contains three macros: Documents NORMAL.DOT AutoOpen NOPO NOPS DateiSpeichern NOPSA DateiSpeichernUnter
It infects the global macros area on opening an infected document (AutoOpen) and copies itself to documents that are saved (DateiSpeichern, DateiSpeichernUnter - FileSave, FileSaveAs). Depending on the system date and time the virus sets a password for current document or/and exits Windows. On Friday13th it sets the password "Friday13".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|