Virus Database


Macro.Word97.Aljadezz

Description Macro.Word97.Aljadezz

This is the polymorphic macro virus. It contains twelve macros in the module "aljadezz": FileSaveAs, Mutate, EditFind, AutoOpen, FileSave, FilePrint, Inserta, ToolsMacro, ViewVBCode, ToolsCustomize, FileTemplates, Retro.
The virus replicates on executing one of the macros: FileSaveAs, EditFind, AutoOpen, FileSave, FilePrint. It uses polymorphic routine inserting random comments into the virus code.
The macro EditFind erases the system files:
C:WINDOWSWIN.COM
C:CONFIG.SYS
C:AUTOEXEC.BAT
C:COMMAND.COM

On printing (FilePrint) the virus adds a page with the text:
-=INFECTADO CON EL ALJADEZZ VIRUS=-

The virus then deletes the files:
C:WINDOWS*.*
C:*.*

The virus also erases the anti-virus programs:
C:Archivos de ProgramaAntiViral Toolkit ProAvp32.exe
C:progra~1Antivi~1Avp32.exe
C:Archivos de ProgramaAntiViral Toolkit Pro*.avc
C:progra~1antivi~1*.avc
C:f-macrof-macro.exe
C:f-prot~1f-macro.exe
C:Archivos de ProgramaCommand SoftwareF-PROT95Sign.def
C:progra~1comman~1f-prot95sign.def
C:Archivos de ProgramaCommand SoftwareF-PROT95Dvp.vxd
C:progra~1comman~1f-prot95dvp.vxd
C:Archivos de ProgramaMcAfeeVirusScan95Scan.dat
C:progra~1mcafeeviruss~1scan.dat
C:Archivos de ProgramaMcAfeeVirusScan95Mcscan32.dll
C:progra~1mcafeeviruss~1mcscan32.dll
C:Archivos de ProgramaMcAfeeVirusScanScan.dat
C:Archivos de ProgramaMcAfeeVirusScanMcscan32.dll
C:Archivos de ProgramaNorton AntiVirusViruscan.dat
C:progra~1 orton~1viruscan.dat
C:Archivos de ProgramaSymantecSymevnt.386
C:progra~1symantecsymevnt.386
C:PC-Cillin 95Scan32.dll
c:pc-cil~1*.dll
C:PC-Cillin 95Lpt$vpn.*
C:PC-Cillin 97Scan32.dll
C:PC-Cillin 97Lpt$vpn.*
C:TscPC-Cillin 97Scan32.dll
c: scpc-cil~1*.dll
C:TscPC-Cillin 97Lpt$vpn.*
C:TBAVW95Tbscan.sig
c:Tbavw95Tb*.*
C:Tbavw95Tbavw95.vxd
C:Archivos de ProgramaNorton Antivirus*.*

Check other viruses! Be aware! Use Antiviral Software

Pempe family

Description Pempe family

These are not dangerous memory resident parasitic viruses, "Pempe.1943" encrypted. They trace INT 13h, 21h, hook INT 8, 21h and on disk access DOS calls search for .EXE files and write themselves to the end of the file. Depending on their counters the viruses decrypt and display the message:
+-----------------------------+
| P E M P E |
| AMACC (Makati,Phils) [PM] |
+-----------------------------+

The "Pempe.1811" virus also contains the text:
PEMPE 1.2

Penetrator.984

Description Penetrator.984

It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed or opened. On 77th infection the virus erases the disk sectors and displays the message:
Cat scratch fever.(CSF)
by Penetrator (IRI).Special thanks to Dr.Armageddon.
Writing such funny things is not a crime!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



StÄdpatrullen I UmeÅ Kommanditbolag
Wakepower Ab
LantmÄnnen Maskin Ab
MassÖr Jonas
Hautanen Svets & Smide

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com