Kid.256
Description Kid.256
These are not dangerous nonmemory resident parasitic viruses. They search for .COM files and write themselves to the end of the file. They contain the text strings: (c)1992littleKid! SNA*.* *.com
"Kid.393" displays "face" letter (ASCII 01). "Kid.434" on November, 11th deletes the host files.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Mentes
Description Macro.Word.Mentes
This is an encrypted Word macro virus. It contains ten macros: Killer, AutoExec, AutoOpen, DocClose, FileOpen, FileSave, AutoClose, FileSaveAs, ListMacros, ToolsMacro. The virus replicated on opening an infected document, saving and saves with new name. The replication routine presents only in one macro Killer, other macros call it to spread the virus. The infection subroutine in the virus is named "MENTES". The virus author leaves a possibility of self-destruction: if the MY.INI file exists in Windows directory, and it contains the section [Word Info] with the "Kod=aaa" string inside, the virus disables its infection routine and removes all its macros. The virus is able to "steal" documents when they are saved. To do that the virus writes the C:LOGIN.SYS file name of closed document, current date, time and contents of the document. It then connects the \HS_WORKHCOMMONSTUDENTTEMP disk and moves to it the C:LOGIN.SYS file to the first logical drive that is write-enabled. The name of new file is ARCHIVE.A??, where '??' is number from "10" till "50". This file name is also saved to the PROG.INI file on the same disk. On entering the List/Macros and Tools/Macro Word menus the virus displays the MessageBox and cancels execution of original macros viewing routines (stealth): Macro function is not installed.
Macro.Word.Mercado
Description Macro.Word.Mercado
This is an encrypted Word macro virus. It contains eight macros: AutoOpen, UtilMacro, FerramMacro, ArquivoAbrir, ArquivoSalvar, UtilPersonalizar, ArquivoSalvarComo, FerramPersonalizar. The virus infects the global macros area (NORMAL.DOT) on opening an infected document and writes itself to documents that are opened, saved or saved with new name. On May 19th the virus writes to the C:AUTOEXEC.BAT file the commands that format the hard drive, the virus then displays the MessageBoxes: Alevirus Labs 1997 11/21/97 Virus Extra Hipermercado Extra = Mais Caro = Caixas sem educa o = Vacas HEHE Hipermercado Extra 100% Caixas HIV Positivo!!! S>C>S
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Provillus Hair Regrowth Treatment Trægulv KALLAX BETONG OCH GRUS AB WEIDERMAN WORLD TRAVELS AB Blog Barricade
|