Macro.Word97.Ozwer
Description Macro.Word97.Ozwer
This is a stealth macro virus. It infects global macros area (NORMAL.DOT template) on opening an infected document and hooks many events: documents open, close, save, print, paste and copy commands, etc. Other documents get infection on any of hooked actions. While infecting a document the virus changes MS Word window caption to "ø Microsoft Word". To hide itself the virus disables menus: Tools/Macro Tools/Templates and Add-ins.. Tools/Customizeall Tools/Options... View/Toolbars
It also displays own ToolMacro dialog box where are no any macro listed. On try to open Visual Basic Editor the virus displays one of two messages (depending on MS Word localisation): Error interno en Word Basic Err=1100e. Imposible cargar bibliotecas din¡micas. Compruebe que todos los archivos estŠn en sus carpetas. Si el problema persiste, consulte la guia del usuario. Word Basic internal error Err=1100e Unable to load module 1x6004. Check that all files are in their folders and that they are not damaged. If the problem persists, consult user's guide.
Every twenty minutes the virus checks words count in current document and if it is in ranges 350-400, 700-750, 900-950, 1000-1050, 1150-1200, 1300-1350 or 1500-1600 then in one case of four the virus mixes words in the document.
Check other viruses! Be aware! Use Antiviral Software
Ku.334.a
Description Ku.334.a
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of .EXE files that are executed. This virus contains the word "Ku".
Kuarahy.4608
Description Kuarahy.4608
It is a dangerous memory resident encrypted multipartite virus. The virus infects the MBR of the hard drive, boot sector of 1.4M floppy disks, writes itself to the end of COM, EXE, SYS files, creates companion COM files for BAT files, adds droppers to ARJ archives. The virus also affects object modules (OBJ files), but fails and corrupts them. The virus has bugs and often halts the system while installing memory resident or while infecting files and disks. The virus does not infect the COMMAND.COM and anti-virus programs: COMMAND, SCAN, NAV, F-PROT, GUARD, FINDVIRU, TOOLKIT, AVP. It also deletes the anti-virus data files: ANTI-VIR.DAT, CHKLIST.MS, CHKLIST.CPS, AVP.CRC. On 31th of month the virus displays the message: [KUARAHY by Int13h] - Written in the Republic of Paraguay - Please register!
The virus also contains the text strings: [KUARAHY] Koa ha'e Int13h/iKx rembiapokué hina! :) HOMO ¿SAPIENS? HAHAHA! DOS Infection Device Learn some guaraní words!:Kuarahy=Sun Añá=Devil Kuñá=Woman execomsysobjbatovlarj E-mail me: Int13h@antisocial.com PARAGUAY WORLD CUP '98 Rohaihú Paraguay!
|
Home
Viruses from A to Z 0-9
A
B
Ń
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Enitor FÖretagsvÅrd Ab Umiren StÄd Aktiebolag E. Fors Billackering Ab A-m Fasad & Kakelteknik Ab Loander Bygg
|