Virus Database


Macro.Word.Archfiend

Description Macro.Word.Archfiend

This Word macro virus contains six macros: AutoExec, AutoOpen, FileOpen, ArchFiend, FileSaveAs, ToolsMacro (stealth). The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are saved with new name (FileSaveAs).
On 5th of any month the virus: on Macintosh erases all files and displays the MessageBox:
ArchFiend

On PC it erases BMP files in Windows directory (C:WINDOWS*.BMP) and creates the FIEND.TXT there containing the text:
##################
## WM.ArchFiend ##
##################
Nrsi:lshoi:m{{i:mhsnn t:st:St~ut is{{;
XOR by 1ah
Your Unlucky Number is: < ½ á ¡«Ñ ¿ ½«>

While saving a document with new name, if current time is 13 seconds, the virus sets for the document a random selected password. On entering the Tools/Macro menu the virus writes to the C:AUTOEXEC.BAT file the command:
echo BLOW ME!

Check other viruses! Be aware! Use Antiviral Software

Inferno.781

Description Inferno.781

It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 12h, 21h and writes itself to the end of COM files that are executed. Under debugger the virus overwrites the MBR of the hard drive. The virus contains the text string:
NAME OF THIS VIRUS IS "INFERNO" NEXT VERSION WILL BE BETTERall

Infiltrator.304

Description Infiltrator.304

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the zero area (if it is found) of .COM files that are modified (INT 21h, AH=40h). The virus contain the text string:
INFILTRATOR

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com