Macro.Word.Sunbeam
Description Macro.Word.Sunbeam
This Word macro virus contains three macros: DocClose, SUNBEAM, FileOpen. The virus infects the global macros area (NORMAL.DOT) on closing an active window (DocClose) and writes itself to documents that are opened (FileOpen). On October 5th the virus creates and executes the random named file (<3 letters of current document name>DIE.BAT) that contains the text: echo 123>clock$
Check other viruses! Be aware! Use Antiviral Software
Rubbit.734
Description Rubbit.734
This is a benign memory resident parasitic virus. It searches for original address of INT 21h handler in DOS area, hooks INT 21h and writes itself to the end of the files. While installing its TSR copy the virus copies itself to the address 9000:0106 and do not fix MCB list, that can halt the system. The virus infects COM files that are executed or loaded as overlay. While infecting they rename the file to "RUBBIT.$$$", infect it and then rename back to original name. These viruses also contain the texts: :RUBBIT.$$$
Rubix family
Description Rubix family
These are dangerous nonmemory resident encrypted viruses. They search for .COM files in the current directory, then overwrite them. The viruses have several blocks of code and data, these blocks are encrypted/decrypted on-the-fly when viruses are run. The viruses contain the text strings: *.COM Well, this is a new overwriting virus. K00l, huh? Not really. But it encrypts different sections of itself during executioner, and that's neat. Coder: Executioner
|