Virus Database


Macro.Word.Reflex

Description Macro.Word.Reflex

It is an encrypted virus. It contains three macros, but in any infected document or global macros area two of them are identical.
NORMAL.DOT Infected files
Macro1 FA FA
AutoOpen
Macro2 FClose FClose
FileClose

The virus uses these duplicated macros as source macros while infecting - to infect global macros area (on AutoOpen) the virus copies its macros:
FA -> FA
FClose -> FClose and FileClose

While infecting a document (on FileClose) the virus copies:
FA -> FA and AutoOpen
FClose -> FClose

The virus displays the message box with the text:
RED DWARF
Where's the Gerbil of bubbly?

Check other viruses! Be aware! Use Antiviral Software

Sobakin.9592

Description Sobakin.9592

This is a dangerous memory resident {polymorphic:Poly}, {stealth:Stealth} parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are accessed. The virus doesn't infect files with names beginning with the following letters:
DR, AV, TB, WE, F-
The virus also restores the original INT 21h address. After infecting 255 files, the virus displays messages in Russian and waits until a key is pressed. After infecting 65,535 files, the virus erases CMOS memory, and erases hard-drive sectors and displays the following message:
Triple L - long live lamer,LMD - lamer must die,
R U ready 4 Hell? No,than say thanx 2:
H(Cr)acker Shtirliz & Cyberpunk Dead One
è â êîíöå ÿ õîòåë áû ñêàçàòü,÷òî êàæäûé íîâûé âèðü õîðîíèò ñ
òàðóøêó DOS,è ýòî ãðóñòíîall.
Is that illusion or reality? Cyber Culture 1998
The virus also contains the text strings:
ã------------------------¬
¦ Pirates Shadow Service ¦
L-------------------------
ViRUS [Feudal] v1.oî
AUTHORS
Dead One & Shtirliz
Feudal ][ coming soon...
Keep CyberSpace Free !
Runtime error 204 at 0000:

Socha.753

Description Socha.753

It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of .COM files that are opened. The virus activates only if the system date is set to 1981. When any file is executed (except ME$.OVL and NCMAIN.EXE), the virus appends a command line to the file C:M_EDITME$.OVL. The virus contains the strings:
Socha
C:m_editme$.ovl
comCOM

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Ryggkliniken Anders Nordwall Ab
Ke-bo Scanservice
Hillbom, JÖrgen
Rea StÄd Handelsbolag
Anders Hansson Trafikutbildning

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com