Virus Database


Mutator Family

Description Mutator Family

These are dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed. They contain errors and sometimes infect the files incorrectly.
"Mutator.307" does not check neither the file format nor file name extension and infect EXE files as COM files, as a result these files halts being executed. This virus contains the text string:
Mutator v2.0b

"Mutator.459" contains the text:
MUTAtOR (C) Mutation Inc.

"Mutator.780" is the encrypted virus. Under tracing it displays the message:
Fuck you, asshole!!! You're using a Debugger!!!

On October, 30th it displays:
Hey! Holloween almost here!
Better be good, or the demon's will get you!

It also contains the text:
[Mutator] C/B: MainFrame [Mutation INc.]

Check other viruses! Be aware! Use Antiviral Software

Macro.Excel.Laroux

Description Macro.Excel.Laroux

This virus infects Excel sheets (XLS files). It contains two macros: auto_open and check_files. While loading an infected document, Excel executes the auto macros auto_open, and the virus gains control. The virus auto_open macro contains just one command that defines the check_files macro as a handler of the OnSheetActivate routine. As a result, the virus hooks the sheet-activate routine, and while opening a sheet, the virus (the check_files macro) gains control.
When the check_files macro gains the control, it searches for PERSONAL.XLS files in the Excel Startup directory, and checks the module count in the current Workbook.
If the infected macro is an active Workbook, and the PERSONAL.XLS file does not exist in the Excel Startup directory (the virus is executed for the first time), the virus creates that file there, and saves its code to that file using the SaveAs command. When Excel is loading its modules the next time, it automatically loads all XLS files from the Startup directory. As a result, the infected PERSONAL.XLS is loaded as well as other files, the virus gains control, and hooks the sheet activation routine.
If the active macro is not infected (there are no modules in the active Workbook), and the PERSONAL.XLS file exists in the Excel directory, the virus copies its code to the active Workbook. As a result the active Workbook is infected.
To check your system for the virus, you should to check PERSONAL.XLS and other XLS files for the string "laroux" that is present in infected sheets.

Macro.Excel.Laroux.YZ

Description Macro.Excel.Laroux.YZ

This virus is related to "Laroux". After seven infection it manifests itself by the video effect: it changes colors of cells so that the result is colored mosaic text:
larou
XYZ

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com