Macro.Word97.Blaster
Description Macro.Word97.Blaster
This is a dangerous macro-virus. Also known as Cont. It infects global a macro area upon opening an infected document. Other documents are infected upon closing. The infecting routine locates the virus' procedures "Document_Close" and "Document_Open" separately, and stores them on the disk file C:CONT.DBL. When a victim's document is being infected, the infection routine adds the virus code from this file (C:CONT.DBL) to a document, without destroying the document's macros. The exception are macros with the same names as the virus procedures contain, making the virus even stealthier. In one case out of two, the virus changes a document's summary information to: Title="Macro Carrier" Author="Dream Blaster" Keywords="Minny"
The virus' payload routine activates on the 17th of each month. It looks for the disk file "C:MINNY.LOG" that also has a "hidden" and "read only" attributes set. If such a file does not exist, the virus appends to the AUTOEXEC.BAT file several commands that destroy all files and folders on drives C:, D:, E: and F: upon next computer rebooting.
Check other viruses! Be aware! Use Antiviral Software
Ghost_2.5000
Description Ghost_2.5000
This is a very dangerous memory resident encrypted parasitic stealth-virus. It hooks INT 21h and 25h, and writes itself to the beginning of COM- and EXE-files that are executed, opened or closed. If the resulting COM-file length is out of segment (64K), the virus converts the file to EXE format. While installing its TSR copy, if there is no free system memory, the virus displays the following message, and exits to DOS: Swap file creation error at 0FAD:2DEC. Program aborted.
The virus contains code that overwrites .PAS- and .CPP-files with the following text: There is nothing in the world that I ever wanted more than to never feel breaking apart all my programs again. The spiderman is always hungry
but this code is never executed. In January, the virus corrupts the data on the hard drive, and then displays the following message (there may be any random digit instead of "000000000"), and "drops snow" on the screen: Happy New Year ! Ghost 1.0 is terminating its work now. Please waitall Write down this number : 0000000000 and pray for your data rescue.
The virus also contains the internal text strings: COMMAND.COM .COM.EXE.PAS.CPP I feel so tired. The way the rain comes down how it`s how I feel inside. I`ve been living so long with my pictures of you Remembering you standing quiet in the rain
Ghostball.2351.a
Description Ghostball.2351.a
It is a not dangerous not memory resident virus which by standard way hits .COM-files of current directory and directories listed in PATH. It writes a small program into Boot-sectors of disks. This program hooks INT 8 and starts to run a ball (see "Ping-Pong" virus) but doesn't infect any files or sectors. This virus contains the text "GhostBalls, Product of Iceland Copyright (c) 1989, 4418 and 5F19".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Hmmm Certifierad Massageterapi Joax Handelsbolag Hvitt Vsh GÄvle Montage & Portcenter Ab Klingeroth I Gammalkil Aktiebolag
|