Macro.Word.Hark
Description Macro.Word.Hark
This is a Word macro virus. It contains two macros: AutoOpen, HARKONE. The virus replicates itself when documents are opened (AutoOpen). On June 1st it erases the whole text in the current document, maximizes it and inserts the text: H A R K O N E N J [ S L A M ]
Check other viruses! Be aware! Use Antiviral Software
BAT.CopyToC
Description BAT.CopyToC
These script viruses are written in BAT, and copy themselves to directories on the C: drive. BAT.CopyToC.a This virus is 552 bytes in size. When launched for the first time, the virus creates a file named 1.sys in the Windows directory. It then copies itself to the C: root directory as AllTheBat.bat. The virus registers this file in the system registry to ensure that the file is automatically launched each time the system is started. [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun] "AllTheBat"="c:\AllTheBat.bat" It creates an additional file named C:AllTheBat.reg to enable it to do this. On subsequent launches, the virus will rename all files in the current directory. It also adds the extension .bat to the name of every file. The virus attempts to copy itself to the A: drive as A:
eadme.txt.bat. BAT.CopyToC.b This virus is 1262 bytes in size. The virus attempts to copy itself to the C: drive under the following names: c:Gunslinger.bat c:progra~1msnmes~1Gunslinger.bat c:progra~1msnmes~11043data.bat c:progra~1window~1Gunslinger.bat c:progra~1window~1skinsdata.bat c:progra~1window~1Visual~1user.bat c:progra~1internGunslinger.bat c:progra~1internpluginsdata.bat c:progra~1internsignupuser.bat c:progra~1internw2kcpu.bat Payload The virus deletes EXE files in the C:progra~1 and C:Windows directories. BAT.CopyToC.c This virus is 825 bytes in size. The virus copies itself into other files on the C: drive. New files which contain a copy of the virus will have the following names: c:Autorun.exe.bat c:windows askman.exe.bat c:windowsNotepad.exe.bat c:windowssystem32xcopy.exe.bat c:windowsystem32systray.exe.bat Payload The virus disables the mouse and the keyboard by launching C:Windows
undll32 with the appropriate commands. It deletes .sys files from the Windows system directory and creates text files in the C: root directory. The C:Readme.txt file contains the following text string: Now you are f*ck The C:Virus Info.txt file contains the following text string: Poop Smells
BAT.DebugVir.782
Description BAT.DebugVir.782
It is a harmless nonmemory resident parasitic batch virus. It searches for .BAT files, then writes itself to the beginning of the file. To access DOS file searching/reading/writing functions this virus creates a temporary file, writes Assembler source code to there, then compiles and executes them by using the DEBUG utility. The virus contains the text strings: (hehe) Debug Batch Virus and here's your hostall
|