Virus Database


Macro.Word.MadDog

Description Macro.Word.MadDog

These are not encrypted macro viruses. They contain six macros: AutoExec, AutoOpen, AutoClose, FileClose, FCFinish, AOpnFinish. They infect the system on AutoOpen and files on FileClose.
The viruses contain the text:
--------------------------------------------------------
Microsoft Word for Windows 95 "MadDog" Macro Set
v 1.0, March l996
--------------------------------------------------------
(c) Copyright Microsoft Corporation, 1995

On AutoClose they replace 'e' symbol with 'a' within current document.

Check other viruses! Be aware! Use Antiviral Software

Cartier.1056

Description Cartier.1056

Cartier.1056 is a dangerous not memory resident parasitic virus. It searches for .COM-files and writes itself to their ends. It erases the FAT of the C: drive and displays:
+----------------------------------------------------------------------------+
¦ Don't panic it, I am just a virus named [Cartier]. Nice to meet you ! ¦
¦ You are so dirty to get software without any payments ! I don't like it ! ¦
¦ So, I destory all of your datas in the hard disk now ! Feel so good ! ¦
+----------------------------------------------------------------------------¦
¦I wish you like that ! ¦ What about a drink ? ¦ See you next time ! ¦
+----------------------------------------------------------------------------+

Cascade.1491

Description Cascade.1491

This is a memory resident virus. Its body except for the beginning (first 32 bytes) is encoded. As a key the length of the infected file is used. That is why two strains of the same virus in most cases will coincide only in the first 32 bytes.
As an infected program is executed, the control of the JMP command is transferred to the beginning of the virus. By first commands the virus determines the length of the source file and deciphers its body.
On creating its memory-resident copy the virus:
copies its body into the highest addresses of the memory;
moves the body of the main program into the highest addresses of the memory;
moves the virus body into cleared area above the main program body;
sets INT 1Ch, 21h, 28h to its own copy.
ƒ all ƒ ƒ ... ƒ ƒ ... ƒ ƒ ... ƒ
+---------ƒ +---------ƒ +---------ƒ +---------ƒ
ƒProgram ƒ ƒProgram ƒ--+ ƒFree ƒ +-->ƒVirus ƒ
ƒ ƒ ƒ ƒ ƒ ƒmemory ƒ ƒ ƒ ƒ
ƒ ƒ ƒ ƒ ƒ +---------ƒ ƒ +---------ƒ
+---------ƒ +---------ƒ +-->ƒProgram ƒ ƒ ƒProgram ƒ
ƒVirus ƒ--+ ƒVirus ƒ ƒ ƒ ƒ ƒ ƒ
ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ
+---------ƒ ƒ +---------ƒ +---------ƒ ƒ +---------ƒ
ƒ ... ƒ +-->ƒVirus ƒ ƒVirus ƒ--+ ƒ ... ƒ
ƒ(copy) ƒ ƒ ƒ
+---------ƒ +---------ƒ
ƒ ... ƒ ƒ ... ƒ

The virus affects only COM files as it's loaded into the memory for execution. Infection is carried out by standard method. Most widely spread versions of this virus does not reinfect files.
The virus changes interrupt vectors 1Ch, 21h and 28h. It also produces a specific video-effect: crumbling down of letters on the screen; does not have destructive functions.
Sometimes it displays the message:
IL SISTEMA è FOTTUTO!!
S.E.K. VIRUS Made in ITALY RM
5iD G.Ferraris 90/91 (c)
Then it erases the disk sectors. It also deletes CHKLIST.CPS file.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



StÄdmannen I Halmstad
Bilbolaget Personbilar HÄlsingland Ab
Stens Allservice
Queen & Commitment Kommanditbolag
Alfta Golvservice L-o SÖroms

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com