Virus Database


Macro.Word97.Attention

Description Macro.Word97.Attention

These viruses contains only one macro AutoOpen and replicate themselves on opening documents. They contain the comments:
------------------------------
!!!!Attention!!!!Attention!!!!
------------------------------
This is *NOT* a Wazzu Varient!
This Virus is called AntiFWIN!
FWIN's Heuristics do not Work!
------------------------------

Check other viruses! Be aware! Use Antiviral Software

Cryptor.2169

Description Cryptor.2169

These are harmless nonmemory resident parasitic polymorphic viruses, their polymorphic engine is quite strong. They search for .COM files, then write themselves to the end of the file. The viruses do not manifest themselves in any way, they contain the text strings:
Cryptor.2169:
-= CrYpToR v1.0 =- (C)1995 by -Nigh+-$piri+-
[$UPD 1.0], $pirit's Universal Polymorphic Device v1.0.
(C)1995 by -Nigh+-$piri+-

Cryptor.2852:
-= CrYpToR v1.5 =- (C)1996 by -Nigh+-$piri+-
[$UPD 1.5], $pirit's Universal Polymorphic Device v1.5.
(C)1995-1996 by -Nigh+-$piri+-

Cryptor.3612:
-= CrYpToR v2.0 =- (C)1996 by -Nigh+-$piri+-
* BEST POLYMORPH-ENCRYPT VIRII IN WHOLE WORLD *
[$UPD 2.0], $pirit's Universal Polymorphic Device v2.0.
(C)1995-1996 by -Nigh+-$piri+-

CS.Gala

Description CS.Gala

This is the first known virus to infect CorelDraw scripts. When this script is activated, it searches in the current folder for other CorelDraw scripts (*.CSC files), reads their data and gets names of the first infected and first non-infected scripts. Then it reads the virus code from the infected script and writes it to the beginning of victim non-infected script. The virus infects one script at a time, and after infection, it returns control to the original script commands.
While infecting, the virus uses the temporary file MALLORN.TMP: the virus renames the victim file to this name, creates its copy with a victim file name, and appends to it the original victim file code from a MALLORN.TMP file.
The virus manifests itself on June 6th - it displays the following message window:
GaLaDRieL ViRUS bY zAxOn/DDT
Ai! lauri" lantar lassi sêrinen!.
YLni ênãtime ve rmar aldaron,
yLni ve linte yuldar vnier
mi oromardi lisse-miruvãreva
Andêne pella Vardo tellumar
nu luini yassen tintilar i eleni
ãmaryo airetri-lirinen.
all.

The virus code also contains comments at the very beginning of the virus and at the very end of its code:
REM ViRUS GaLaDRieL FOR COREL SCRIPT bY zAxOn/DDT
REM END OF ViRUS GaLaDRieL bY zAxOn/DDT

The possibility of CorelDraw script infection is based on the fact that this application supports programs that are written in a script language that is very close to VisualBasic used in MS Office. The CorelDraw scripts, as well as scripts in other applications and macros in MS Office, are used to customize the application. The CorelDraw script language supports a set of instructions that is enough to copy one script code to another one, access disk files and as a result to create a virus.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Site Proxys Unblock
Inkeris StÄd
BÄrgarbo Aktiebolag
Golvx VÄxjÖ
Hagalunds PlÅtslageri Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com