Macro.Word.Niknat.i
Description Macro.Word.Niknat.i
This encrypted macro virus contains four macros, it replicates on closing documents (AutoClose): Documents NORMAL.DOT EvaHzg EvaHzg AutoClose DCloseAN FileTemplates FileTemplates, ToolsMacro TCloseAN AutoClose
On October 23 the virus creates the EVAH.BMP file with a porno-picture image inside in the Windows directory and sets it as the Windows background picture (wallpaper). The virus then also changes Windows color palette. On entering the File/Templates and Tools/Macro Word menus the virus displays the MessageBox (stealth): Microsoft Windows Windows Protection Errorr
The virus also contains the comments, these comments depend on the virus version: "Niknat.a,b,all": by NAENBGOURSG SO.HT.AI.KS 231076-GREECE Thanks to NEURO VRD 19-4-1997 VRP A.U.A (+.+.+)
"Niknat.i": -------------------------------- Latin word -virus- means poison and is a derivative of two Sanskritic roots --> -vishas->(poison) and -ishus->(arrow). NAENBGOURSG - SO.HT.AI.KS M.SC. in MacroViral Science ---------------------------------
Check other viruses! Be aware! Use Antiviral Software
Ambulance.793.a
Description Ambulance.793.a It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus manifest itself in the same way as original "Ambulance" viruses do.
AMD.3081
Description AMD.3081
This is a benign memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus also stores filenames on opening and creating, and then infects them on closing. Depending on their internal counters the virus manifests itself by using Novell NetWare protocols (in case the Novell NetWare is installed on the net): it sends messages to all users of the network. This virus is encypted in EXE files. It sends a message in Russian to the network users. It also contains the text string: Name: Babylon5 Cast Of Warriors (c) TechnoMag
|