Virus Database


Macro.Word.Killuf family

Description Macro.Word.Killuf family

The viruses of this family contain three macros: AutoClose, VisioOpen, VisioClose. They spread on closing document (AutoClose). During infection they do not copy themselves to documents, but move. After copying they delete themselves in original document. They keep the name of current document in the WINWORD6.INI file in the [Microsoft Word] section with the name LUF01.
Starting from January 1st 1999 they erase the files on all drives in all directories: *.DOC, *.PPT, *.XL?, *.MPP, *.WPS, *.MDB. Then the MessageBox is displayed
HAPPY NEW YEAR FOLKS!

Check other viruses! Be aware! Use Antiviral Software

Abbas.5660

Description Abbas.5660

This is a dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM and EXE files that are executed.
By using INT 9 (keyboard) the virus checks INT 1 (trace), and while tracing it displays the message:
IRANIAN VIRUS W.by ABBAS KUHKAN ALIABADI
and halt the computer.
The viruses also contain the text string:
KUH
Depending on the system timer "Abbas.5660" loads some font, and displays (persian?) messages.

ABC.2378

Description ABC.2378

It is very dangerous memory resident virus. It infects COM- and EXE-files while DOS accesses them. The virus manifests itself from 13th of every month: it checks keyboard and after double pressing of any key duplicates this key (for example the keyboard input "1001" is transferred to "10001"). The infector writes a small program into files that tries to erase the FAT of all hard disks after starting. The virus hooks INT 16h, 1Ch, 21h.
The virus uses very powerful algorithm of en/decryption. The en/decryptor contains much of the assembler commands ADD, SUB, XOR in random order.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com