Virus Database


Macro.Word.Decept

Description Macro.Word.Decept

The virus code contains two macros:
Document:NORMAL.DOT:
--------- -----------
haha AutoOpen
AutoClose original

The virus spreads on opening and closing documents.
From 27/08/98 till 03/09/98, after 19:30 the virus replaces every tenth line with the "Se fodeu. HaHaHaHaHa!!!" text in the current document, then it displays the message:
Microsoft Word
Acabamos de destruir seu trabalho, espero que vocª tenha perdido
muito tempo com esta bosta de documento.

After that the virus terminates the MS Word.

Check other viruses! Be aware! Use Antiviral Software

BackFormat.1855

Description BackFormat.1855

These are dangerous memory resident parasitic viruses. "BackFormat.2354," are encrypted ones. Upon execution, they hit the COMMAND.COM file, and the length of the COMMAND.COM file doesn't increase. This virus uses the "Lehigh" virus algorithm. Then they hook INT 21h, ("BackFormat.2000" hooks INT 13h also), and write themselves to the end of COM- and EXE-files. They infect newly created files on a floppy only and write themselves upon file closing. Upon infection of a COM-file, the virus checks the first instruction of it. If this instruction is not JMP (E9h), the virus infects the file in a standard manner: it writes itself to the end of the file and overwrites the beginning of the file with a "JMP Virus" instruction. If the first byte is JMP, the virus overwrites the instruction to where the first JMP points.
These viruses contain the internal text string ":command.com".
"BackFormat.2000" depending upon generation number and system date, this version changes the system tables upon floppy disk formatting. The sectors are formatted in reverse order: from the 9th to the first (for 360k floppies). If this floppy is not 360K, the disk will not be accessible.
"BackFormat.2435" sometimes corrupts data upon it being saved on a disk.

BackTime.1234

Description BackTime.1234

This is a dangerous memory-resident virus. It hooks INT 8 (timer), and INT 21h and hits COM files by a standard way when they are executed.
This virus drops "Stoned.March6" boot virus.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Timmy Elmqvist Bil
Aw Entreprenad I Trestad
Barenius VÅrd Handelsbolag
Anslin, Merja
Sabah Skomakeri

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com