Macro.Word.Chaka
Description Macro.Word.Chaka
This is double-language virus, it supports both English and German Word versions. It contains only one macro AutoOpen in infected documents, but creates three macros ChAkA, FileOpen, DocClose in NORMAL.DOT while infecting the global macros area. The ChAkA macro is the copy of AutoOpen, it contains the infection routine. Other macros (FileOpen, DocClose) call this infection routine. As a result the virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to documents that are opened (FileOpen) or when document's window is closed (DocClose). The virus contains the text string: ChAkA! Nightmare Joker [SLAM]
Check other viruses! Be aware! Use Antiviral Software
Caesar
Description Caesar
This is a harmless, non-memory resident encrypted parasitic DOS virus. It infects DOS EXE files and creates its "dropper" in the C:WINDOWS directory. When an infected file is run, the virus creates the infected CAESAR.EXE file (virus dropper) in the C:WINDOWS directory and overwrites the WINSTART.BAT file with an instruction that will run the virus dropper. As a result, virus dropper is activated each time Windows is started up. The virus then returns control to the host program and does not infect any other files. When the virus dropper takes control, it searches for *.EXE files on all drives and infects them. While infecting, it writes itself to the end of the file. The virus checks file names and avoids infecting the following files: AN*, AD*, DR*, PR*, NC*, WI* Because of its method of infection, the virus is functional only when Windows is installed exactly in the C:WINDOWS directory.
Cagliari family
Description Cagliari family
These are very dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files that are executed. On May 1st they erase the FAT sectors on disks A, B, C, D and then display the message: caGLiArI
The similar string is used by virus in its "Are you here?" call - while installing the virus calls INT 21h with AX=FFABh, the memory resident copy returns 'CA', 'GL', 'IA', 'RI' in registers AX,BX,CX,DX.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Vask Lowongan Kerja Irs FÖretagsutveckling Staniszewski, Zbigniew Marcin Petter's
|