Virus Database


Macro.Word.NoPrint

Description Macro.Word.NoPrint

This is German specific Word macro virus. It contains three macros: AutoOpen, DateiDrucken, DateiDruckenStandard. It replicates itself on documents opening. It manifests itself in only one way - it disables printing.

Check other viruses! Be aware! Use Antiviral Software

Andryushka.3536

Description Andryushka.3536

These are very dangerous memory-resident polymorphic viruses. They affect COM- and EXE-files (excluding COMMAND.COM) whenever an infected file is started (search in directories). "Andryushka" also infect files from its TSR-copy (when the files are opened, run, renamed and so on). After getting infection from virus "Andryushka.3536" EXE-files are changed to COM-format (see the "VACSINA" viruses). The virus penetrates into the middle of a file. The part of the infected file where the virus has been written to is encrypted and placed at the end of the infected file.
The virus creates counters in the Boot-sectors of disks and depending on the counters values may corrupt some sectors on the disk C:. On doing this the virus plays a tune and displays the following text:
+-----------------------+
ƒ Hello!!! ƒ
ƒ My name is Andryushka ƒ
ƒ I come from Perm,USSR ƒ
+-----------------------+

The virus also contains the text: "insufficient memory". "Andryushka" works with interrupt handlers fairly well: it saves a part of the INT 25h handler in its own body and writes its code (call to INT 21h) into the emptied place. When INT 25h is called its handler is restored.

Andy.998

Description Andy.998

These are dangerous memory resident parasitic viruses. They hook INT 21h, 28h and infect COM files that are executed. The viruses have bugs and halt the system if there is no UMB memory. While infecting they write themselves to the end of the file. The viruses do not infect files immediately when they are executed, but delay it up to INT 28h call (DOS internal idle). So they infect files in the "background".
"Andy.998" also hooks INT 13h and on 15th of any month writes data to disk instead of reading. This definitely corrupts data on the disk. "Andy.1016.b" hooks INT 13h as well, but it disables writing to disks on any day, that corrupts data that is copied or modified. "Andy.1016.a" hooks INT 1Ch and depending on their internal counters changes color of the screen and disables keyboard.
The viruses contain the texts:
"Andy.998": ANDY-3
"Andy.1016.a": ANDY-1
"Andy.1016.b": ANDY-2

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Tetőtéri Ablakok
Bokföring
Pregnancy And Ovulation Calculator
Stoły Bilardowe
Calling Cards

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com