Virus Database


Macro.Excel.Hidemod

Description Macro.Excel.Hidemod

This virus infects Excel sheets. It contains six macros: Auto_open, Auto_close, ChangeCell, CreatePers, CheckV101, HideModV101 and several functions in one module "ModulV101".
To infect the system the virus creates the infected PERSONAL.XLS file in the ALTSTART directory and declares it as the Alternate Startup directory. To create this file the virus looks for Windows directory and creates it there:
C:WINDOWSALTSTART
C:WIN95ALTSTART
D:WINDOWSALTSTART
D:WIN95ALTSTART

If there is no such directories, the virus creates alternate directory on the C: drive: C:ALTSTART.
To infect other sheets the virus hooks sheets activation procedure. The virus handler also has stealth ability: it does not allow to examine a module with the virus, switching current page to first non-virus found.
The virus also hooks formulas calculation procedure and with probability 30% erases the source formula and replaces it with calculated result (i.e. this cell will be not recalculated).

Check other viruses! Be aware! Use Antiviral Software

15years.a

Description 15years.a

It's a dangerous memory encrypted resident boot virus. It hooks INT 16h, 13h and writes itself into MBR of hard drive and boot sectors of floppy disks. On April, 7th it overwrites disk sectors with the string:
Esto te pasa por programas que a nosotros nos cuesta tanto
trabajo hacer. Que te quede de Experiencia, México,1994

Depending on its internal counters the virus changes the keys that are entered from keyboard. It contains the internal text string also:
This Virus is from MEXICO, I have 15 years old

1stVir.3032

Description 1stVir.3032

This is harmless, memory resident parasitic virus. It hooks INT 9, 13h, 1Ch, 21h, and 28h. The virus writes itself to the end of COM and EXE files. When the file is executed, the virus stores its name, and infects that file on INT 1Ch or INT 28h calls. So the virus infects the file not at the same moment when the file is executed, but with some delay.
Other interrupt vectors the virus uses in its video effect: the virus changes the video mode, pages, cursor and mouse position, and displays the string "1st".
The virus contains the encrypted text strings:
EXECOM
1stVIR

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



STENUNGSUNDS TRANSPORT AB
VARGÖNS LIVS AB
AB PAPPERSTEKNIK
IE Orkut Proxy

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com