Virus Database


Macro.Word.Smmd

Description Macro.Word.Smmd

The virus contains one macro that is names AutoOpen in documents and FileSaveAs in NORMAL.DOT. It infect the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are saved with new name (FileSaveAs). While infecting the virus slightly modifies its code: it inserts into its source WordBasic code empty lines.
The virus contains the comments:
**********************************************************
WARNING: This is trivial example of Self Modifying Macro !
Only for evaluation purposes !
It is strongly prohibited to spread this macro !
The name for this shit must be "SMM_demo"
Do not use other name please !
----------------------------------------------------------
Name for this shit: "SMM_demo" research macro
Author: Unknown
date: Unknown
origin: Unknown
**********************************************************

Check other viruses! Be aware! Use Antiviral Software

Apo.2108

Description Apo.2108

It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the beginning of .COM and end of .EXE files that are executed. While infection of the files the virus renames them to the name X$X$$X$X.$X$, infects and then renames back to original name.
While infecting .EXE files the virus corrects several fields in EXE header: the virus increases the length of EXE header to cover original contents of the file. As a result the original file body is defined as EXE header, and while loading such file info the memory DOS loads only the virus body. Then the virus opens the host file, restores the fields in EXE header, executes host file, and then writes "infected" fields back to EXE header.
The virus also hooks INT 1Ch and some time after installation erases the disk sectors. The virus has the bugs, and in some cases halts the computer. The virus contains the encrypted text string:
ApoVir

Apocalipse.1685

Description Apocalipse.1685

It is a dangerous memory resident encrypted parasitic virus. It traces INT 13h, 21h, hooks INT 21h and writes itself to the end of COM and EXE files that are executed. While installing into the system memory it also infects the C:DOSMODE.COM file.
The virus writes the counter into hard drive sector and increases that counter each time the virus installs itself into the memory. After 100 installation the virus corrupts CMOS and MBR of the hard drive, and displays:
Apocalipse 2.0 por M.A.C.
Isto é um vírus - afaste-se do computador, sen¦o constipa-se !
Boa sorte nas reparaç_es - nada está perdidoall
Também, andavas a trabalhar demais - aproveita para descansar !
Lembra-te: coisas destas só ajudam a formar caracter - n¦o,
n¦o precisas de agradecer, é um prazer ajudar...
Voltarei...
Preme uma tecla

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Image Converter Review
Pochłaniacz Wilgoci
Bio
Nicaragua Volcanos
Cs Bilteknik I VÄxjÖ Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com