Virus Database


Macro.Word.Crow

Description Macro.Word.Crow

This brazilian virus contains three macros: autoOpen, CROWFuck, ArquivoSalvar. It replicates on opening and closing documents (autoOpen, ArquivoSalvar auto-macros).
The virus code contains many effects:
the virus deletes macros accessing menu items,
on the 5th of any month starting from April it inserts the strings into the document's summary info:
Title = The CROW_Fuck!!!
Subject = nothing
Author = The Best Virus Creator
Comments = Surprise!!! You Die!!!!!
VOCÊ FOI INFECTADO PELO VIRUS The CROW_Fuck - Macro - Fuck Microsoft,,
Mcafee, ThunderByte and more!!!
!í!í! Bye Bye LAMMER !í!í!

on 8th of any month starting from May it adds a file erasing commands to the C:AUTOEXEC.BAT file and then displays the MessageBox:
The CROW_Fuck - Macro virus
Surprise!!! You Die!!!!!!
> > Brazil < <

if system minutes > 57 , the virus prints to the status bar the running string:
The CROW_Fuck - Brazil - 97 !!!!!

if there are more than 50 words in document, the virus insert a space at random selected place. Depending on random counter it also insert into document the "CROW" word.
on Fridays the virus insert the text into document:
CROW_Fuck - The Complete Macro Vírus
Este vírus é dedicado a todos que pensam que o povo do terceiro mundo não
é capaz de criar coisas que tenham utilidade; aos Lammers, porque sem
eles não daria para se disseminar o vírus; à Microsoft, por tornar tão
fácil a pirataria; à Mcafee, por seu Vir
usScan ser totalmente burro e fácil de se enganar.
See Ya
The CROW

Check other viruses! Be aware! Use Antiviral Software

Fifo.333

Description Fifo.333

This is a harmless memory-resident parasitic virus. It copies itself into Interrupt Vectors Table, hooks INT 21h and intercepts GetDiskSpace DOS function (AH=36h). When that function is executed, the virus searches for COM files, and writes itself to the beginning of the file. The virus contains the text string:
*.COM FIFO

FileHider.1057

Description FileHider.1057

This is memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM files that are executed or opened. While installing into the system memory, this virus searches for the original INT 21h address in such complex way that it can halt a computer.
This virus isn't dangerous. Sometimes it displays one of the following messages:
Fucky machine! How about buying an AT?
Good machine you have!
Monochrome is out! Try VGA graphics!
Making day out of night again?
Give me a rest!
Your disk is quite full, isn't it?

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Ruza's StÄdfirma
Lars Nieckels Oa-konsult
Bilskadeservice I Nacka Aktiebolag
Rae HemslÖjd
VoxtorpsgÅrden Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com