Macro.Word.Ciao.a
Description Macro.Word.Ciao.a
This German specific macro virus contains three macros in infected documents and two ones in NORMAL.DOT: Documents NORMAL.DOT ----------- ----------- DateiOffnen DateiOffnen - FileOpen DateiSpeichernUnter DateiSpeichernUnter - FileSaveAs AutoClose
The virus installs itself into the system when an infected document is closed. While installing the virus saves the current document the name C:DATEI.DOC and copies its two macros (DateiOffnen and DateiSpeichernUnter) to the global macros area (NORMAL.DOT). The virus infects other documents when they are saved with new names (FileSaveAs). To infect them the virus copies its three macros from the C:DATEI.DOC file. On file opening and saving with new name the virus displays the message: Winword Zu wenig Arbeitsspeicher! Schlie#en Sie alle laufenden Anwendungen! !! Es besteht die Gefahr von Datenverlusten !!
The virus also inserts into documents the text: *** A new star is born ***
Check other viruses! Be aware! Use Antiviral Software
Freddy.2271
Description Freddy.2271
It's a polymorphic virus, it searches for the COM- and EXE-files and hits them on every INT 21h call. Sometimes on saving the data to the file (INT 21h, ah=40h) this infector saves a random byte. It contains the internal text strings: COMMAND.COM *.COM *.EXE Freddy KRueGer 2.1 Fridrik!
FreddySoft.1663
Description FreddySoft.1663
It's harmless not memory resident encrypted parasitic virus. It searches for COM- and EXE-files (except IBMBIO.COM and IBMDOS.COM) and writes itself to their ends. It contains the internal text string: FREDDY_SOFT jln lobilobi blok Q27 Kalibata indah JAKARTA Selatan Greetings to STACK RIPPER, DOUBLE CLICK, SINGLE DRIVE COMEXESYSAUTOEXEC.BATIBMBIO.COMIBMDOS.COM
|