Virus Database


Macro.Word.Magnum

Description Macro.Word.Magnum

This encrypted macro virus contains three macros: Magnum, ToolsMacro, ExtrasMakro. The virus does not have any auto-macro, but gets control in another way. While infecting a document or global macros area the virus copies its macros to there and assigns the SPACE key with "Magnum" macro. MS Word saves such information and restores it on loading global macros or opening an infected document.
As a result, when MS Word is opening an infected document or loading global macros, it sets "Magnum" macro as routine that will be executed on SPACE keystroke.
After infecting global macros the virus displays a message box with the text:
MaGnUm

The ToolsMacro and ExtrasMakro macros are there to hide the virus in system - on selecting Tool/Macro the virus displays dummy menu that on any item (except CANCEL) displays the error messages:
WordBasic Err = 7
Not enough memory!
WordBasic Err = 7
Nicht genügend Arbeitsspeicher!

The virus drops the DOS virus "HLLO.Havoc" by using the trick with DEBUG utility - writes hexadecimal virus dump to disk and runs DEBUG to convert it to DOS executable file HTC.COM. Then the virus appends to the end of the C:AUTOEXEC.BAT file the commands:
@echo off
htc.com
cls

and then creates and writes to system profile (WIN.INI) the text:
[DosVirus]
Installed=Yes

On April 13 it creates the NORMAL.DOT file and writes the strings to there:
Schon mal im blasen Mondlicht mit dem Teufel getanzt?
;-))
The Magnum Virus! NJ 1996

Check other viruses! Be aware! Use Antiviral Software

Atomant

Description Atomant
These are not dangerous memory resident viruses. They hook INT 21h and write themselves to the end of executed files.
Atomant.564
This version of the virus infects only COM files. It hooks INT 80h and removes itself from RAM at the respective request. After an hour since infection of the system memory the virus blocks deletion procedures when a user tries to delete a file and displays the following text:
HÁt igazÁn nem kedveltek bennânket ?
The virus contains the following text string:
AtomAnt v1.00
Atomant.2143
This is not dangerous memory resident encrypted parasitic virus. It hooks INT 1, 9, 1Ch, 21h and writes itself at the end of COM- and EXE-files are executed. It displays the messages:
A billentyûzet 5000 leütésig garanciális.Ez most lejárt.Kérem cserélje ki !
Csak aztán idejében hagyja abba !
Ez nem SKÅLA áru!!!!
Hát igazán nem kedveltek bennünket ?
MC Hammer rap-sztár és PEPSI ôrült, de most kicseréltük a PEPSI-ét
valami másra all FILLING, NOTHING MORE THEM FILLING ...
Kérem fogadjon el egy vírust a vallási eszmélés egyházától.
Nem akar adakozni ?
Túl régi ROM-BIOS verzió ! Cserélje ki újabbra !
Atomant v3.0 Erôsebb, mint valaha !
Csôtörés az I-O csatornábkan.Kérem azonnal hívjon szerelôket!!!
Tömeg van az adatbuszon.Gyorsítsa meg az a

Atomic Family

Description Atomic Family

These are dangerous not memory resident viruses. They search for .COM-files only and infect them. "Atomic.2332,371,480" are overwriting viruses, they write their bodies instead of the file. Other "Atomic" viruses are parasitic ones and write themselves at the file end.
These viruses contain the text string "*.COM", they contain several other strings, some of them are displayed by the viruses, then the viruses reboot or hang the computer up.
"Atomic.232,350" displays the last strings on error during file infection:
"Atomic.232":
The Tricky Dicky Virus
*.COM [TrickyDicky] Created in the city of Toronto
Bad command or file name
Fail on INT 24 .. NOT!!

"Atomic.350":
[TAD2A] Created by Memory Lapse of Ontario, Canada
[TAD2A] The Atomic Dustbin 2A - Just Shake Your Rump!
Fail on INT 24 .. NOT!!

"Atomic.371" on 25th of every month displays the second string, the last string is displayed on any execution:
[TAD1A] Memory Lapse -- Toronto, CANADA
The Atomic Dustbin 1A -- This is just the first step
Bad command or file name

"Atomic.480" displays the second string on 1st of every month, on 26th it types the last string:
[TAD1B] Memory Lapse -- Toronto, CANADA
The Atomic Dustbin 1B --
This is almost the second step
Program execution terminated
The Atomic Dustbin - YOUR PHUCKED!

"Atomic.831":
*.COM COMMAND.COM DOSCOMMAND.COM
Copyright (c) 1993 Memory Lapse - Ontario, Canada
[TAD2B]-The-Atomic-Dustbin-2B
Unable to infect program
Fail on INT 21
+------------------------------------------+
¦ The Atomic Dustbin 2B - I'm Here To Stay ¦
+------------------------------------------+

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Best Pc Rpg
Pferdeversicherung
SÖren Runesson Bygg Och Reparation
MuskÖ HÄstcenter Handelsbolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com