Macro.Word.Ice
Description Macro.Word.Ice
This encrypted macro virus contains 5 macros: Plong, AutoOpen, FileSaveAs, ToolsMacro, FileTemplates. It writes itself to the global macros area on opening an infected document (AutoOpen). It infects other documents on their saving with new name (FileSaveAs). In the WIN.INI file the virus runs a counter of infected documents: [Yesman] LastActive={count}
When this counter reaches 24, the virus displays to the StatusBar the message: Lontong Micro Device (c) 1993 By ICE-Man
On entering menu Tools/Macro the virus displays the message: ICE - Man '93 This virus dedicated to all my best friend : ~ Edong, Rosamya, Boeyoenk, Ludho, Bstyle ~ Be Cool Guys and keep your life on the line all 2 some one I love very much, why U disapoint me I hope this not happend again 2 some one that U love
Check other viruses! Be aware! Use Antiviral Software
RiftVilly family
Description RiftVilly family
These are harmless memory resident parasitic viruses. They hook INT 21h, and write themselves to the end of COM files. "RiftVilly.469" intercepts file access to DOS functions and infects COM files that are executed, opened or renamed; "RiftVilly.490" does the same with EXE files. "RiftVilly.480" intercepts a ChangeDir DOS function, and upon such calls, searches for .COM files in the current directory and infects them. The viruses contain the following text strings: "RiftVilly.469": Rift Villy v.3.4 "RiftVilly.480": Rift Villy v.3.1 "RiftVilly.490": Rift Villy v.4.0
Rikki family
Description Rikki family
These are not dangerous nonmemory resident parasitic viruses. They search for .COM files, then writes itself to the end of the file. While infecting a file they temporary rename it with COx (x=FFh) extension. To rename file the viruses do not call any DOS function, but make it by absolute disk read/write calls (INT 25h/26h) - the viruses read directory entry, search for file name, patch it and then write directory sector back to disk. The viruses display the messages: "Rikki.839": Demo virus #1 by Rikki Cate 21/9/90 File infected: Press key to continue
"Rikki.1787": Demo virus #3 by Rikki Cate 21/9/90 File infected: Press key to continue
"Rikki.1970" Demo virus #2 by Rikki Cate 21/9/90 File infected: Press key to continue PC-cillin has been replaced by a demonstration virus. To activate the virus, reboot the computer. PC-cillin has been replaced by a demonstration virus. This message could easily duplicate the PC-cillin start-up screen. The virus is now resident in memory in place of PC-cillin. It will emulate the PC-cillin display and command keys. It will also infect any .COM programs which are accessed by interrupt 21 hex. Press any key to continue.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
University Accommodation Center Ab Hofe Mj Rostskydd Kommanditbolag Kristall StÄd
|