Virus Database


Macro.Excel.Spellcheck

Description Macro.Excel.Spellcheck

This virus infects Excel sheets. It contains only one module "MSExcel" with six functions: Auto_Close, Auto_Open, HasAddIn, RepeatInfect, Infect, Payload.
While opening an infected file the virus function Auto_Open takes control and infects the system: it creates the infected SPELLCK.XLA file in the Excel startup or alternate startup directory. The virus also creates the infected Add-in file. The virus pays attention to the environment and creates infected files in directories that are specific for MacOS and Windows.
The virus displays the MessageBoxes:
Thank you for using Microsoft Excel!
Just in case you didn't know, the current date is:
<date>

It also contains comments:
Date Virus.
Created: May 1, 1996.

NOTE:
The Date Virus was inspired by the Laroux virus. While this particular
macro virus is harmless, others are not! This macro virus was developed
to bring attention to the possible threat in the hopes that antivirus software
will be developed to protect this application.

Check other viruses! Be aware! Use Antiviral Software

Deadman.943

Description Deadman.943

It is a dangerous nonmemory resident encrypted parasitic virus. It searches for COM and EXE files, then writes itself to the end of the file. The virus scans the all subdirectories of disk. The virus may erase random sector on drive C and displays the message:
Program too big to fit in memory

The virus also contains the text strings:
[Napoleon]
Copyright (C) 1998-99 by Deadman [SOS]

DeadWin.1088

Description DeadWin.1088

These are memory resident encrypted parasitic stealth viruses. They hook INT 21h, and write themselves to the end of COM and EXE files that are executed or closed. When an infected file is opened, the viruses disinfect it. While infecting, the viruses can corrupt files.
The viruses check the names of files that are executed, and if the file name begins with "WI" (WIN.COM), they run their trigger routines (see below).
When WIN.COM is executed, depending on the system time (if the hours counter is equal to the seconds counter), displays the message "Dead to Windows!" and reboots the computer. It also contains the text:
Dracula lives Resucitated somewhere in time
by Dust Group, Tucumán, Argentina
On Fridays, when WIN.COM is executed, this virus checks the system timer, and if the hour counter is equal to the second counter, the virus displays the following message, and reboots the computer:
Dead to Windows!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Kjøkken
Digitale Binäre Optionen
Hernia Symptoms
Sinus Symptoms

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com