Virus Database


Macro.Word.Beeper.a

Description Macro.Word.Beeper.a

These are encrypted Word macro viruses. They contain six original macros in NORMAL.DOT and infected documents:
"Beeper.a": AutoExec, AutoClose, AutoOpen, AutoNew , TheTime , Kill
"Beeper.b": AutoOpen, TFGAMV, AutoExec, AutoNew, AutoClose, Joke

While infecting global macros area (NORMAL.DOT) "Beeper.b" also creates two addition macros with random selected names. These macros contain copies of the TFGAMV and Joke macros.
The viruses infect the global macros area while infecting an opening document. They write themselves to documents while opening existing or creating a new document (AutoOpen, AutoNew).
Beeper.a
It maximizes Word windows and inserts into the current document the text:
You are infected with
The Time
A virus from Cool Zero

The virus does not executes the Kill and TheTime macros, i.e. they may be activated only by user's request (by File/Templates or Tools/Macro menus). When activated, the TheTime macro checks the system time and at 15:59 beeps and displays the MessageBoxes:
Hi I'm the Time virus
I don't like Your COMMAND.COM and AUTOEXEC.BAT
Play with me !! :-)
You have 1 Minute time to find me
Find me, I do nothing
Find me not
SAY BYE TO YOUR COMMAND.COM AND AUTOEXEC.BAT

The Kill macro at 16:00 deletes the files C:COMMAND.COM and C:AUTOEXEC.BAT.
Beeper.b
This virus prints documents on opening them (AutoOpen). At 17:00 it tries (but fails) to create and execute the SMILEY.COM file. This file contains an "intended" DOS virus.

Check other viruses! Be aware! Use Antiviral Software

Ramones.a

Description Ramones.a

It is a very dangerous memory resident multipartite virus. It hooks INT 13h and writes itself to the boot sectors of the floppy disks and to the MBR of the hard drive. The virus encrypts the original boot and MBR sectors before saving them on disk.
The virus also overwrites EXE files that are accessed. When such file is executed, the virus infects the MBR of the hard drive, displays the message and returns to DOS:
Incorrect DOS Version.

The virus also contains the text:
[RamonesMania] by Evil One.

Randall.3072

Description Randall.3072

It is not a dangerous nonmemory resident polymorphic parasitic virus. It searches for COM and EXE files and writes itself to the end of the file. It deletes CHKLIST.MS files, it contains the text strings:
DOS *.exe *.com
CHKLIST.MS
RANDALL FLAGG

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Lagerqvist RÖr
Inc Industrial Noise Control Aktiebolag
FolktandvÅrden GÄvleborg Ab
Ab ByggnadsstÄllningar BrÄmhult
Castillo, Pablo Javier

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com