Virus Database


Macro.Word.Nomvir

Description Macro.Word.Nomvir

This is a very dangerous virus. It contains ten macros: AutoExec, AutoNew, AutoOpen, DateiSpeichern, DateiSpeichernUnter, DateiBeenden, ExtrasOptionen, DateiDokvorlagen, FuckIt, and DateiDrucken.
Upon AutoNew and AutoExec, it infects the global macros area. Upon DateiSpeichern and DateiSpeichernUnter (FileSave, FileSaveAs), it infects a document.
The virus looks for the "Nomvir=" parameter in the "Compatibility" section (WIN.INI file), and does not perform any action if there is "Nomvir=0x0690690". The virus also creates a counter "iCount" in the "intl" section, and increases it when any document is printed. Depending on the counter, the virus deletes the C:AUTOEXEC.BAT and C:CONFIG.SYS files. Depending on the system date, the virus replaces some words in documents with "hell" or appends to the end of the document the following text:
Fuck Microsoft & Bill Gates

On January 1st, December 25th, on the 23rd of any month, and on Saturday 13th, it deletes the following files:
C:WINDOWSUSER.DA0
C:WINDOWSSYSTEM.DA0
C:WINDOWSUSER.DAT
C:WINDOWSSYSTEM.DAT

Depending on the system time, the virus sets randomly selected passwords for documents. Upon accessing Tools/Macro and the DateiDokvorlagen menu, the virus displays the MessageBoxes:
Nicht genügend Arbeitsspeicher !
Interner Fehler !

Check other viruses! Be aware! Use Antiviral Software

Ava Family

Description Ava Family

These are the memory resident parasitic EXE-infectors. They hook INT 21h and write themselves at the end of EXE-files upon their execution or opening.
Ava.550
It's a harmless virus. Tt doesn't manifest itself.
Ava.600
It's a dangerous virus. It contains the text string " Ava " and sometimes changes the offset of the information saved.

Avalanche Family

Description Avalanche Family

These are dangerous memory resident encrypted stealth parasitic viruses. They trace and hook INT 21h, and write themselves at the end of COM- and EXE-files are executed, they delete some anti-virus programs. The viruses contain the internal text strings (the second string contains the beginnings of the file names, the viruses delete these files on their execution):
AVALANCHE/Germany '94allMetal Junkie greets Neurobasher
F-PR TBAV SCAN MSAV CPAV TBME TBFI TBSC VIRS TBDR

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Team Clean I Halmstad Handelsbolag
Ruthjennys Örtsalvor I BollnÄs Ab
Get Motorsport Handelsbolag
Nbj Bygg Och Kakel
Ll Eu-mopedutbildning Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com