Virus Database


Macro.Word.Chaka

Description Macro.Word.Chaka

This is double-language virus, it supports both English and German Word versions. It contains only one macro AutoOpen in infected documents, but creates three macros ChAkA, FileOpen, DocClose in NORMAL.DOT while infecting the global macros area.
The ChAkA macro is the copy of AutoOpen, it contains the infection routine. Other macros (FileOpen, DocClose) call this infection routine. As a result the virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to documents that are opened (FileOpen) or when document's window is closed (DocClose).
The virus contains the text string:
ChAkA! Nightmare Joker [SLAM]

Check other viruses! Be aware! Use Antiviral Software

Caesar

Description Caesar

This is a harmless, non-memory resident encrypted parasitic DOS virus. It infects DOS EXE files and creates its "dropper" in the C:WINDOWS directory.
When an infected file is run, the virus creates the infected CAESAR.EXE file (virus dropper) in the C:WINDOWS directory and overwrites the WINSTART.BAT file with an instruction that will run the virus dropper. As a result, virus dropper is activated each time Windows is started up. The virus then returns control to the host program and does not infect any other files.
When the virus dropper takes control, it searches for *.EXE files on all drives and infects them. While infecting, it writes itself to the end of the file. The virus checks file names and avoids infecting the following files:
AN*, AD*, DR*, PR*, NC*, WI*
Because of its method of infection, the virus is functional only when Windows is installed exactly in the C:WINDOWS directory.

Cagliari family

Description Cagliari family

These are very dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files that are executed. On May 1st they erase the FAT sectors on disks A, B, C, D and then display the message:
caGLiArI

The similar string is used by virus in its "Are you here?" call - while installing the virus calls INT 21h with AX=FFABh, the memory resident copy returns 'CA', 'GL', 'IA', 'RI' in registers AX,BX,CX,DX.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Vask
Lowongan Kerja
Irs FÖretagsutveckling
Staniszewski, Zbigniew Marcin
Petter's

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com