Virus Database


Macro.Word97.PBB

Description Macro.Word97.PBB

This virus spreads itself on documents opening and closing. On opening a document the virus checks the system date. If day number is less than 3, the virus hides mouse cursor and displays the message:
Created By Yusril Ihza Mahendra
PARTAI BULAN BINTANG

Another virus routine deletes all libraries (.DLL) files from Windows system folder if day number is greater than 25. This routine is executed on document opening, calling Visual Basic Editor and clicking "Tools/Macro" menu.
The virus body contains the text strings:
Macros Pbb mungkin tidak bisa Anda hapus, Anda hanya bisa menghapus makro
buatan Anda (Descr: 'Makro non-Pbb')
Terimakasih Anda Telah
Memproteksi Word dengan Aman

Check other viruses! Be aware! Use Antiviral Software

Helloween.257

Description Helloween.257

These are relatively harmless memory resident parasitic viruses. They hook INT 21h, and write themselves to the end of COM and EXE files that are executed. They contain a encrypted string that contains file-name parts (4 letters per name), and the viruses do not infect these files (SCAN*.*, SHIE*.*, TRAP*.* and so on):
SCANSHIETRAPVIRUVCOPASTAALIKAZORREX.MANDUEXEUCOMVIRTCLEATSAFNAV.INI.BOOT3P.E

On November 1st, "Helloween.1376, 1384, and 1447" decrypt and display the following message:
Nesedte porad u pocitace a zkuste jednou delat neco rozumneho!
*******************
!! Poslouchejte HELLOWEEN - nejlepsi metalovou skupinu !!

"Halloween.1182" hooks INT 8, 13h, and 21h, and emulates the disk read/write error: it returns a carry processor flag upon disk access.
On February 27th, "Helloween.1376b" displays the following message:
Zdravim uzivatele pocitacu hlavne vsechny LENKY a nejvic tu nasi!
Preji ti vsechno nejlepsi k tvemu svatku ahoj P.

On 10th and 20th "Helloween.1888" displays:
Virus napsany specialne pro inzenyra ZAKA ze SPS
*******************
Nepodlehejte panice, mate nakazeno jen par souboruall
(c) 1993 II.A 1988
Tak a ted si vyzkousime treba: RESET
Kdyby kazdy nespokojeny student napsal virus, tak v nasich skolach by
ani jiny software nekoloval a McAfee by se divil...

On the 5th and 24th of the month, "Helloween.2470" displays:
_ _ _
_ _ -m
__________ ____ __ __ ------- zdrojovy
__ __ __ __ __ ƒ ƒ ƒ text:
__ __ __ ____ ------- 867 radku
__ ________ __ __
__________ __ __ __ __ & spol.
(c) 1993 II.A 1988
Specialne pro ucitele SPS Prostejov:
Ing. M. Zaka, Ing. J. Melku, Ing. P. Cizka, Ing. K. Kabrhela
Ing. M. Blahu, Ing. M. Pavlovskeho a dalsi vyucujici.
Specialni podekovani patri:
Macrosoftu (sorry Microsoftu) za MeSsy DOS
Borlandu za TASM, TLINK, TD
Zdenku Breitenbacherovi za EDDIE 1.17

"Helloween.1377" "shifts" the screen.
"Helloween.1839" checks the current date and tries to decrypt and display a message, but the virus has the bug and never displays it:
Virus napsany specialne pro inzenyra ZAKA ze SPS
*******************
Nepodlehejte panice, mate nakazeno jen par souboru...
(c) 1993 II.A 1988
Tak a ted si vyzkousime treba: RESET
Kdyby kazdy nespokojeny student napsal virus, tak v nasich skolach by
ani jiny software nekoloval a McAfee by se divil...

Helloy.293

Description Helloy.293

It is not a dangerous nonmemory resident parasitic virus. It searches for .COM files, then writes itself to the end of the file. The virus displays the message:
Helloy , baby !!!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Private Krankenzusatzversicherung
Algarve Car Hire
Zydot
Download Shareware And Freeware
Susannes StÄd Service

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com