Virus Database


Macro.Word.Hark

Description Macro.Word.Hark

This is a Word macro virus. It contains two macros: AutoOpen, HARKONE. The virus replicates itself when documents are opened (AutoOpen). On June 1st it erases the whole text in the current document, maximizes it and inserts the text:
H A R K O N E
N J [ S L A M ]

Check other viruses! Be aware! Use Antiviral Software

BAT.CopyToC

Description BAT.CopyToC

These script viruses are written in BAT, and copy themselves to directories on the C: drive.
BAT.CopyToC.a
This virus is 552 bytes in size. When launched for the first time, the virus creates a file named 1.sys in the Windows directory. It then copies itself to the C: root directory as AllTheBat.bat.
The virus registers this file in the system registry to ensure that the file is automatically launched each time the system is started.
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
"AllTheBat"="c:\AllTheBat.bat"
It creates an additional file named C:AllTheBat.reg to enable it to do this.
On subsequent launches, the virus will rename all files in the current directory. It also adds the extension .bat to the name of every file. The virus attempts to copy itself to the A: drive as A: eadme.txt.bat.
BAT.CopyToC.b
This virus is 1262 bytes in size. The virus attempts to copy itself to the C: drive under the following names:
c:Gunslinger.bat
c:progra~1msnmes~1Gunslinger.bat
c:progra~1msnmes~11043data.bat
c:progra~1window~1Gunslinger.bat
c:progra~1window~1skinsdata.bat
c:progra~1window~1Visual~1user.bat
c:progra~1internGunslinger.bat
c:progra~1internpluginsdata.bat
c:progra~1internsignupuser.bat
c:progra~1internw2kcpu.bat
Payload
The virus deletes EXE files in the C:progra~1 and C:Windows directories.
BAT.CopyToC.c
This virus is 825 bytes in size. The virus copies itself into other files on the C: drive.
New files which contain a copy of the virus will have the following names:
c:Autorun.exe.bat
c:windows askman.exe.bat
c:windowsNotepad.exe.bat
c:windowssystem32xcopy.exe.bat
c:windowsystem32systray.exe.bat
Payload
The virus disables the mouse and the keyboard by launching C:Windows undll32 with the appropriate commands.
It deletes .sys files from the Windows system directory and creates text files in the C: root directory.
The C:Readme.txt file contains the following text string:
Now you are f*ck
The C:Virus Info.txt file contains the following text string:
Poop Smells

BAT.DebugVir.782

Description BAT.DebugVir.782

It is a harmless nonmemory resident parasitic batch virus. It searches for .BAT files, then writes itself to the beginning of the file. To access DOS file searching/reading/writing functions this virus creates a temporary file, writes Assembler source code to there, then compiles and executes them by using the DEBUG utility. The virus contains the text strings:
(hehe) Debug Batch Virus
and here's your hostall

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Auto Part
Lighting
Jewelry
Kopiera Dvd
BostadsmÄklaren I Varberg Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com