Virus Database


Macro.Word97.Layla

Description Macro.Word97.Layla

It is a dangerous stealth macro virus. It contains ten macros in one module "TJ": AutoOpen, LAYLA, AutoExec, AutoExit, AutoClose, FileClose, ToolsMacro, ToolsCustomize, FileTemplates, ViewVBCode.
It infects the global macros area on opening an infected document (AutoOpen) and infects other documents on opening and closing (AutoOpen, AutoClose).
The virus turns off the Word virus protection (the VirusProtection option) and deletes "NewMacros" module that contains user defined macros. It also disables the Tools/Macro, Tools/Customize menus (stealth). On opening the Visual Basic editor the virus closes Word without saving changes in documents.
On 27th or 29th of any month on closing documents the virus runs its payload procedure. On opening Word at these days the virus displays in the status bar the text:
Excellent dayall for me... :)

The payload procedure is also run on opening document at 27th or 29th second of minute. This procedure replaces all digits by text "Tj" or "Layla" depends on day of month. Also it replaces every 9th character in document by Aries sign.
On exiting Word the virus searches in subdirectories of "c:", "c:program files", "d:" and "e:" for files by wildcard "*d*r*w*.*" (looking for DrWeb anti-virus) and deletes all files in directories where suitable files were found. Then it searches for "*a*v*p*.*" and deletes "*.avc" and "*.key" files (AVP anti-virus databases and key file). As a result of quite scrappy wildcards the virus can delete many other files.
The virus also changes following information:
UserName = ""
UserInitials = "TJ_LAYLA"
UserAddress = ""

Check other viruses! Be aware! Use Antiviral Software

Squatter.9742

Description Squatter.9742

This is a dangerous memory resident parasitic highly polymorphic and stealth virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. Depending on their counters the virus also infects the "C:DOSKEYB.COM" file, if it exists. The virus does not infect the anti-virus programs SCAN, TBAV, F-PROT. It also deletes the anti-virus data files: ANTI-VIR.DAT, CHKLIST.MS.
Because of bugs in the polymorphic engine the virus often cannot decrypt itself and halts the computer. On May 24th the virus displays the messages:
Squattering your system has become by hobbie :)
-SQUATTER v1.2- Coded by The Mental Driller/29A
This virus also contains the text:
[MeDriPolEn v0.1]

Squawk.852

Description Squawk.852

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. It beeps by the PC speaker and contains the text:
Nguyen Van Cuong - Saigon IBM comppany.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Obd
Dell Tc023 Battery
Cookie Recipes
Short Mens Haircuts
Unblock Proxy

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com