Macro.Word.UnderGround
Description Macro.Word.UnderGround
This is an encrypted macro virus. It contains two macros. Their names are Macro7 and AutoClose in NORMAL.DOT. In documents their names are randomly selected: <letter><number>, <letter><number> (for example: T45, E53). The virus infects the documents that are closed (AutoClose). To infect the global macros area (NORMAL.DOT) on opening an infected document, the virus sets one of random named macros in document as the auto-macro. As a result, the macros in infected document do not have any auto-name, but they are executed while opening this document as the AutoOpen auto-macro. While infecting the virus creates a temporary macro. While infecting the NORMAL.DOT the virus displays the MessageBox and asks a user for permission: SoftWare UnderGround Can I install myself into your NORMAL.DOT [YES] [NO]
In case of "YES" the virus infects the NORMAL.DOT, displays the statistic information about current document and document author's name.
Check other viruses! Be aware! Use Antiviral Software
Alex.368
Description Alex.368
This is a nonresident harmless virus. It infects COM files in a standard way (except COMMAND.COM). The virus contains the text string: The One Night Virus (C) Alex Hacker *.COM The virus is not memory resident but copies small resident programs into the interrupt vector table. The first program erases text from screen by nice method some times after installation. The second program writes byte FEh to port 60h (?).
ALEX.599
Description ALEX.599
It is a harmless nonmemory resident parasitic virus. It searches for .COM files and writes itself to the end of the file. It contains the text string: ALEX PATH=*.com
|