Macro.Word97.Crud
Description Macro.Word97.Crud
This is a stealth macro virus. It contains six macros: AutoOpen, AutoClose, ToolsMacro, FileSaveAs, ToolsProofing. The virus replicates itself on opening, closing and saving documents. It also disables VirusProtection. On entering Tools/Macro menu it displays the Balloon: Help !! That option is not installed, please install the HELP files to continue
Check other viruses! Be aware! Use Antiviral Software
Serbu family
Description Serbu family
These are not dangerous memory resident encrypted parasitic viruses. They use several levels of anti-debugging tricks in installation routine as well as in interrupt handlers. They write themselves to the end of COM and EXE files that are executed or opened, as well as to the end of .GIF and .JPG files (!!). When an infected file is executed, the virus decrypts itself by using INT 1 and INT 3 hooks, then allocates block of DOS memory, copies itself to there, traces INT 21h, 2F and hooks them. To hook INT 2Fh the virus patches the DOS kernel. Depending on the system date the viruses display the rectangle: XXXXXXXX XXXXXXXX
"Serbu.3493" displays the text: .. A_C_O: Dirgantara Jaya ..
The viruses also contain the text strings: "Serbu.3493": R-SERBU-1 (c)09-16H Emhaka "Serbu.3493": -SERBU-
Sesc.448
Description Sesc.448
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. The end of each infected file contains the ID-word "SESC".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Short Mens Haircuts Marine Underwater Lights Caliplus Review Computer Knowledge
|