Macro.Word.Nostradamus family
Description Macro.Word.Nostradamus family
This Italian Word macro virus contains three or four macros depending on the virus' version: "Nostradamus.a": MacroOnFile, StrumMacro, AutoOpen "Nostradamus.b": MacroOnFile, StrumMacro, AutoOpen, FileModelli
While infecting the NORMAL.DOT the virus copies the MacroOnFile macro with the the FileSalva name. The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen), and writes itself to documents that are saved (FileSalva). This is the stealth virus: on entering Tools/Macro and File/Temlates menus it draws its own Dialogs (in Italian). On 31st of any month the virus displays the MessageBox: NOSTRADAMUS Virus Barbaro impero dal terzo sarai soggiogato, Gran parte d'individui della sua origine farà perire: Per decesso senile avverrà la sua fine, il quarto colpirà Per timore che il sangue con il sangue morte ne derivi. Centuria 3%, LIX
Check other viruses! Be aware! Use Antiviral Software
Fist Family
Description Fist Family
These are harmless encrypted parasitic viruses. They write themselves to the end of the file. Fist.403,625 These are nonmemory resident viruses. They search for .COM files of current directory, and infect them. They contain the texts: "Fist.403": *.COM Screaming Fist (c)1 "Fist.625": *.COM Screaming Fist (c)10/91
Fist.683 It is a memory resident not encrypted virus. It hooks INT 21h and infects .COM files that are accessed. It contains the text string: Screaming Fist (c)10/91 C:COMMAND.COM COMSPEC=
Fist.692,696,711,732,838,855,862, Fist.Stranger These are memory resident viruses. "Stranger.709.b" is not encrypted. They hook INT 21h and infect COM and EXE files including COMMAND.COM. They contain the texts: "Fist.696,732": C:COMMAND.COM Screaming Fist II "Fist.692,711": Screaming FistC:COMMAND.COM "Fist.855,862": Screaming Fist IIC:COMMAND.COM "Stranger.709.a": I am a stranger in a strange landall "Stranger.709.b": I am a Stranger in KOREA ...
Fist.927
Description Fist.927
It's a harmless memory resident encrypted virus. It infects COM- and EXE-files and MBR of the hard disk in a standard way. The MBR is hit when an infected file is started. The virus saves its part and the MBR sector at the location 0/0/2 (track/head/sector). The virus infects memory while booting from an infected disk. After that it infects files only. The virus hooks INT 13h, 1Ch, 21h. This virus is a MBR-generation of the "Fist" file viruses.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|