Macro.Word.Decept
Description Macro.Word.Decept
The virus code contains two macros: Document:NORMAL.DOT: --------- ----------- haha AutoOpen AutoClose original
The virus spreads on opening and closing documents. From 27/08/98 till 03/09/98, after 19:30 the virus replaces every tenth line with the "Se fodeu. HaHaHaHaHa!!!" text in the current document, then it displays the message: Microsoft Word Acabamos de destruir seu trabalho, espero que vocª tenha perdido muito tempo com esta bosta de documento.
After that the virus terminates the MS Word.
Check other viruses! Be aware! Use Antiviral Software
BackFormat.1855
Description BackFormat.1855
These are dangerous memory resident parasitic viruses. "BackFormat.2354," are encrypted ones. Upon execution, they hit the COMMAND.COM file, and the length of the COMMAND.COM file doesn't increase. This virus uses the "Lehigh" virus algorithm. Then they hook INT 21h, ("BackFormat.2000" hooks INT 13h also), and write themselves to the end of COM- and EXE-files. They infect newly created files on a floppy only and write themselves upon file closing. Upon infection of a COM-file, the virus checks the first instruction of it. If this instruction is not JMP (E9h), the virus infects the file in a standard manner: it writes itself to the end of the file and overwrites the beginning of the file with a "JMP Virus" instruction. If the first byte is JMP, the virus overwrites the instruction to where the first JMP points. These viruses contain the internal text string ":command.com". "BackFormat.2000" depending upon generation number and system date, this version changes the system tables upon floppy disk formatting. The sectors are formatted in reverse order: from the 9th to the first (for 360k floppies). If this floppy is not 360K, the disk will not be accessible. "BackFormat.2435" sometimes corrupts data upon it being saved on a disk.
BackTime.1234
Description BackTime.1234
This is a dangerous memory-resident virus. It hooks INT 8 (timer), and INT 21h and hits COM files by a standard way when they are executed. This virus drops "Stoned.March6" boot virus.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Timmy Elmqvist Bil Aw Entreprenad I Trestad Barenius VÅrd Handelsbolag Anslin, Merja Sabah Skomakeri
|