Virus Database


Macro.Word97.Saturn

Description Macro.Word97.Saturn

This macro virus contains eight macros in one module "Saturn": AutoOpen, AutoClose, Stealth, ToolsMacro, ToolsCustomize, ViewVBCode, Saturn, UMP.
The virus infects the global macros area on opening an infected document (AutoOpen). Other documents get infection on their opening and closing. While infecting the virus turn off the Word virus protection (the VirusProtection option). Depending on the system date and random counter the virus changes the computer's name to "SOS" and set on document the password "SOSxxx", where "xxx" is a number from 1 to 333. On entering the menu Tools/Macro, Tools/Customize or opening Visual Basic Editor it displays one of the following messages:
Not enough memory to perform this operation
Impossible open this function
Function does not answer system requests
This program has performed an illegal operation and will be locked
This option at present not available

The virus then swaps reaction on mouse buttons and closes all documents.

Check other viruses! Be aware! Use Antiviral Software

Nikki.3133

Description Nikki.3133

It is a harmless memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE (except COMMAND.COM) files that are executed, opened, renamed or when file attributes are accessed. The virus sets read-only attribute for infected files. The virus does not infect the programs: VIR*, CLEAN, DEBUG, SCAN, NAV. The virus deletes the anti-virus data files CHKLIST.*.
The virus contains the text strings:
TO Nikki Edval ng TorOntCan.FROM Putoksa Kawayan.
Kathang-isip sa Metro Manila, Philippines

Niko.3477

Description Niko.3477

It is a very dangerous memory resident parasitic virus. It traces and hooks INT 21h, hooks INT 3 (debugger), then it stays memory resident and writes itself to the end of COM and EXE files that are executed or opened. The virus if stuffed with anti-debugging tricks that cover more than 50% of the virus code.
Depending on the system timer the virus corrupts the data that is saved on disk (DOS call Write INT 21h, AH=40h). While creating a .AS* or .DB* file the virus depending on the system time corrupts it or creates a subdirectory with the same name. When any file is executed or opened, the virus calculates the CRC sum of its code, and the CRC is not correct, the virus "shakes" the screen, decrypts and displays the message and halts the computer. The message is:
FUCK YOU

Under debugger or depending on the system time the virus also calls the same effect but displays another message:
No viruses

The virus also contains the encrypted text strings in Russian and:
Oct(123,123,126) by one of student

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Crossworks
Bo-consult Energi I HammarÖ Aktiebolag
JÄRNMARKS ELINSTALLATIONS AKTIEBOLAG
Rw Bygg & Rep
Tbx Trading Handelsbolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com