Macro.Excel.Emperor.b
Description Macro.Excel.Emperor.b
This virus infects Excel sheets. It contains one macro (module) with the name "Emperor[number]" that contains five functions: Auto_Close, CheckFile, WriteVirus, ScreenTool, MenuDelete. Upon opening (closing), the infected Excel file executes the Auto_Open (Auto_Close) virus function. This function summons the check_file (CheckFile) function that sets a four-digit password to the virus sheet. The virus then makes visible all hidden windows, looks for the "Emperor" module in all Workbooks and infects uninfected ones. While infecting, the virus copies its macro with the name "Emperor[number of infection]". The virus then closes all windows that were opened during infection. The virus deletes the menus: Worksheet View - Toolbars, Format - Sheets, Tools - Scenario; Module - Edit/Delete, Tools/Menu Editor, Tools/Protection. On Mondays and Saturdays, it displays the MessageBox: The First Emperor Ver 1.10 [the rest of text is in unknown coding]
Check other viruses! Be aware! Use Antiviral Software
Devices.2000
Description Devices.2000
It is a harmless memory resident parasitic polymorphic virus. It writes itself to beginning of SYS and to the end of EXE files. While executing an infected EXE file the virus opens the C:CONFIG.SYS file, scans it for the names of device drivers, infects them and returns to the host program. While infecting a SYS file the virus creates the temporary file DEVICES.$$$, writes its code to that file, appends the code of the SYS file, then deletes the SYS file and renames DEVICES.$$$ to the original name of infected SYS file. While loading an infected SYS file the virus installs itself into the system memory as device driver, hooks INT 1Ch, waits for some time, then hooks INT 21h and while accessing to floppy disks searches and infects EXE files. The virus contains the text strings: XMSXXXX0 :devices.$$$ config.sys *.exe
Devil.941
Description Devil.941
This is very dangerous memory-resident virus which by standard way affects .COM-files in the current directory (as infected files are activated) or as soon as they are started (from TSR-copy of the virus). From time to time the virus changes the color of some characters on the screen. Depending on its internal counters this infector deciphers and displays the following text: "Have you ever danced with the devil under the weak light of the moon? Pray for your disk!". It contains the strings: "Drk", "*.com", hooks INT 9, 21h.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Buy Ukraine Nude Photos Handy Neuheiten Usps Zip Codes Online Shopping Mall Alpha Urls
|