Macro.Word.Beeper.a
Description Macro.Word.Beeper.a
These are encrypted Word macro viruses. They contain six original macros in NORMAL.DOT and infected documents: "Beeper.a": AutoExec, AutoClose, AutoOpen, AutoNew , TheTime , Kill "Beeper.b": AutoOpen, TFGAMV, AutoExec, AutoNew, AutoClose, Joke
While infecting global macros area (NORMAL.DOT) "Beeper.b" also creates two addition macros with random selected names. These macros contain copies of the TFGAMV and Joke macros. The viruses infect the global macros area while infecting an opening document. They write themselves to documents while opening existing or creating a new document (AutoOpen, AutoNew). Beeper.a It maximizes Word windows and inserts into the current document the text: You are infected with The Time A virus from Cool Zero
The virus does not executes the Kill and TheTime macros, i.e. they may be activated only by user's request (by File/Templates or Tools/Macro menus). When activated, the TheTime macro checks the system time and at 15:59 beeps and displays the MessageBoxes: Hi I'm the Time virus I don't like Your COMMAND.COM and AUTOEXEC.BAT Play with me !! :-) You have 1 Minute time to find me Find me, I do nothing Find me not SAY BYE TO YOUR COMMAND.COM AND AUTOEXEC.BAT
The Kill macro at 16:00 deletes the files C:COMMAND.COM and C:AUTOEXEC.BAT. Beeper.b This virus prints documents on opening them (AutoOpen). At 17:00 it tries (but fails) to create and execute the SMILEY.COM file. This file contains an "intended" DOS virus.
Check other viruses! Be aware! Use Antiviral Software
Ramones.a
Description Ramones.a
It is a very dangerous memory resident multipartite virus. It hooks INT 13h and writes itself to the boot sectors of the floppy disks and to the MBR of the hard drive. The virus encrypts the original boot and MBR sectors before saving them on disk. The virus also overwrites EXE files that are accessed. When such file is executed, the virus infects the MBR of the hard drive, displays the message and returns to DOS: Incorrect DOS Version.
The virus also contains the text: [RamonesMania] by Evil One.
Randall.3072
Description Randall.3072
It is not a dangerous nonmemory resident polymorphic parasitic virus. It searches for COM and EXE files and writes itself to the end of the file. It deletes CHKLIST.MS files, it contains the text strings: DOS *.exe *.com CHKLIST.MS RANDALL FLAGG
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Lagerqvist RÖr Inc Industrial Noise Control Aktiebolag FolktandvÅrden GÄvleborg Ab Ab ByggnadsstÄllningar BrÄmhult Castillo, Pablo Javier
|