Macro.Word97.Opey
Description Macro.Word97.Opey
This macro virus contains fifteen macros in one module "A_OPEY_0x": greetings, OnlyYou, A_OPEY_05, filesave, fileclose, FileExit, FileNew, AutoOpen, AutoExec, FileSaveAs, FilePageSetup, fileprint, Fileopen, AutoClose, AutoExit. The virus infects the global macros area on opening an infected document (AutoOpen), and infects other documents on run of any of its auto-macros. While infecting the virus disable menus: "Tools/Macro", "Tools/Customizeall", "Tools/Templates And Add-Ins". It also disable and hides the "Visual Basic" toolbar and turn off the Word virus protection (the VirusProtection option). The virus changes the user's information: UserName = "OPEY A." UserAddress = "CNNHS B'92 PHILIPPINES (CNSC)" UserInitials = "LOVE"
Depending on the current date the virus appends to the AUTOEXEC.BAT file one of the congratulations: echo MERRY CHRISTMASS AND A HAPPY NEW YEAR !!! echo HAPPY HALLOWEEN !!! echo HAPPY VALENTINES DAY !!! echo HAPPY LABOR DAY !!! echo BONIFACIO DAY !!! echo RIZAL DAY !!! echo HAPPY INDEPENDENCE DAY !!! echo HOLY WEEK !!!
and commands: echo from: OPEY A. pause
Check other viruses! Be aware! Use Antiviral Software
ShyDemon family
Description ShyDemon family
These are not dangerous nonmemory resident encrypted parasitic viruses. They searches for .COM files, then for EDIT.COM file, then write themselves to the end of the file. On May 30th they display the message: (C) Shy Demon Is A Dark Wizard 1996 Production Helloall Hope I'm Not Disturbing.... Don't Wanna Cause Any Trouble... But I Just Infected 2 Files... And If You're Not Nive To Me I Will Infect More... Please Don't Kill Me! We Virii's Also Have A Life You Know... See Ya Next [03.30], Gotta Run...
The viruses also contain the text strings: [Shy Demon - Dark Wizard - Sweden - 96.03.10] *.com edit.com
SI.509
Description SI.509
It is a dangerous memory resident parasitic virus. It hooks INT 1Ch, 21h, intercepts DOS calls Create/Remove/Change Directory, Create/Open File and on these calls search for .COM files in the current directory, then writes itself to the end of the file. To detect its TSR copy the virus writes ID-word "SI" to the BIOS data area at the address 0:0472 (Warm boot flag). At 10:00 the virus reboots the computer. The virus contains the text: *.COM
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Aktiebolaget Hofors PlattsÄttning Olofssons I BjÖrkeberg Hudcirkeln Hagalunds Montage Ab Jj Rep & Ren
|