Macro.Word.Andry
Description Macro.Word.Andry
This encrypted virus contains only one macro AutoOpen and infects the global macro area on opening an infected document and writes itself to other documents when they are being opened. On March 1st it sets to documents the password "Andry Christian", prints the text to status bar: * I'M ANDRY CHRISTIAN, IF YOU THOUGHT, YOUR DOCUMENTS OR TEMPLATES WERE SAFE, YOU WERE WRONG ! *
It then displays the dialog: HACKERS Labs '96 - Hackware Technology Research ANDRY [CHRISTIAN] WORD MACRO VIRUS IS HERE !!! DO YOU SUPPORT MY VIRUS ? YES NO
In case of "NO" key the virus overwrites the C:AUTOEXEC.BAT file with commands: @ECHO OFF CLS ECHO Please wait . . . FORMAT C: /U /C /S /AUTOTEST > NUL
and the C:CONFIG.SYS file with commands: DOS=HIGH,UMB FILES=40 BUFFERS=40 DEVICE=C:DOSHIMEM.SYS DEVICE=C:DOSEMM386.EXE RAM
On the same date (March 1st) depending on the system time the virus runs the disk formatting command: COMMAND /C FORMAT C: /U /C /S /AUTOTEST > NUL
Depending on the system time the virus inserts into current document the text: Helloall. Andry Christian WordMacro Virus Is Here....!!!
The virus also contains the comments: '======================================================================' ' Source Code of Andry Christian WordMacro Virus 0.99 - ßeta Release ' '======================================================================' ' Virographer by Andry [Christian] in [Batavia] City, of INDONESIA ' ' Viroright (C) 1996-1999 Hackware Technology Research - HACKERS Labs. ' ' Multi Platform, Multi Infector, Stealth, OneMacro, Encryption, etc ' ' Last Update by 01-Maret-1996 & 01:03 PM - Found Bugs...? Call Me ' '======================================================================' ' HACKERS Labs. -> WE ARE A BIG FAMILY OF THE VIRUS CREATOR's TEAM ' '======================================================================'
Check other viruses! Be aware! Use Antiviral Software
Gandalf.240
Description Gandalf.240
These are harmless nonmemory resident encrypted parasitic viruses. They search for COM files in the current directory, then write themselves to the end of the file. The viruses contain the text strings: "Gandalf.240": [Gandalf.Gray]*.COM "Gandalf.444": [MARTYR:2] - Greets to MarY PoPPinS + SMAUG - [VC.UK] *000018*
Ganja.437
Description Ganja.437
It is a harmless nonmemory resident parasitic virus. It searches for EXE files, then writes itself to the end of the file. The virus does not manifest itself in any way. It contains the text strings: =GANJA #1= / (C) 1995 [TAC] INC.*.EXE .. This Program is too Stoned to operate correctly!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Firewire Pinout Time Management Video Software Downloads Saturn Calling Card Armband
|