Virus Database


Macro.Word97.Jedi_Magic

Description Macro.Word97.Jedi_Magic

This virus contains two functions AutoOpen and AutoExit in single module Jedi_Magic. It replicates on documents opening. While infecting the global macros area the virus resets system variables:
UserName = "O.B.1. Canobi"
UserInitials = "OBC"
UserAddress = "BOOGZI BARBERS all Food Buster!!!"

The virus detects already infected documents by the Force variable in which it saves the text: "567374-Joseph.A.D.G.". On exiting Word the virus resets its module's attributes:
VB_Description = "Macro created 03/12/98 by Membership & Registry Division"
VB_ProcData.VB_Invoke_Func = "Normal.Jedi_Magic.AutoExit"

Check other viruses! Be aware! Use Antiviral Software

June8.1919

Description June8.1919

It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 9, 1Ch, 21h and writes itself to the end of COM and EXE files that are opened or renamed. Under debugger, or on June 8th it erases disk sectors. When Alt-Ctrl-Del keys are pressed at the same time and depending on its counters the virus plays a (Chinese?) tune. The virus contains the text string:
EXECOM

Junior.224

Description Junior.224

It is a harmless memory resident parasitic virus. Being executed it copies itself into Interrupt Vectors Table, hooks INT AEh and inserts instruction CD AE (call to INT AEh) into resident portion of COMMAND.COM instead of original INT 21h call. As a result, the virus receives the control when any program is executed. Then the virus writes itself to the end of COM files. The virus contains the text string:
Junior

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Hallandssanering Aktiebolag
Berndts El-installationer
Moens Damfrisering
Stiven Bilverkstad
Intereco Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com