Virus Database


Macro.Word.Wordde

Description Macro.Word.Wordde

This is a dangerous Word macro virus. It contains six macros: WordDE, AutoExec, FileOpen, FilePrint, FileSaveAs, AutoOpen (WordSU in NORMAL.DOT). It infects the system on opening an infected document (AutoOpen), it infects documents that are opened (FileOpen) and saved with new name (FileSaveAs).
The virus sets on the system timer a macro that shutdowns Word in a random selected time. On printing documents the virus replaces a string in Russian with new one. The virus creates the section in Windows profile (WIN.INI file):
[gay]
lox= <opened infected documents counter>

When counter reaches 5, the virus erases the COMMAND.COM file.

Check other viruses! Be aware! Use Antiviral Software

Pysk Family

Description Pysk Family

These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files.
Pysk.1536
It infects the files that are executed. Depending on the current date it hooks INT 9, or INT 15h, or INT 1Ch and changes keyboard flags or scancodes (by hooking INT 15h, 1Ch), displays the message when Alt-Ctrl-Del keys are pressed (INT 9). In some cases this virus decrypts and displays one of the messages:
I can't find this file, but I love you?
Co to za bzdura?
Cmoknij mnie w dysk!!!
KEEP SMILING
VIRUS PYSKKILLER v 5.47 (c) MSDRAGON SOFTWARE
ALL DATA WILL BE DESTROY!!! TURN OFF COMPIUTER!!!
One, two, threeall TEST SOUND
Have a good time! - M.S.
STRAJK!
Incorrect DOS version or virus(perhaps PYSKKILLER)
You are dupek!
LEGIA IS THE BEST

Pysk.2464
This is an encrypted stealth virus. It infects the files that are executed or closed. When an infected file is opened, the virus disinfects it.
This virus also hooks INT 8 (timer), and on each timer tick the virus calculates CRC sum of its code. If CRC sum is wrong (the code of the virus is not the same as original code) the virus reboots the computer.
Depending on the system date and its internal counter that virus hooks INT 1Ch. On each INT 1Ch call the virus searches for "disk" or "dysk" string on the screen, and replaces it with "pysk" string.
Depending on its internal counter the virus creates C:Q.COM file, and writes there silly memory resident COM virus.
This virus contains the text strings:
CHKDSK
c:q.com
VIRUS PYSKKILLER written by SMOK 9-IX-1994 W-wa
ACID ZONE !!! W.Hury was here.
COMMAND SMOK NO NAME HOST_FOR_C NEPTUN413 BAZIC DISK!

Python.1142

Description Python.1142

It is a very dangerous memory resident parasitic encrypted virus. It hooks INT 21h and writes itself to the end of .COM and .EXE files that are executed or loaded as overlays. Depending on the system timer it erases MBR of the hard drive. It contains the string:
PYTHON

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



TVÄTTPARTNER I SVERIGE AB
FotvÅrdskliniken IgelbodaplatÅn
Pronetco Byggkonsulter Aktiebolag
MalmÖ Elektriska ByrÅ Ab
Kristines Damfrisering

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com