MutInt Family
Description MutInt Family
These are dangerous memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed. Sometimes these viruses infect the files incorrectly, these files halt the computer being executed. While infecting the viruses encrypt their bodies with new method: they search for INT 21h (CD21h) opcodes in their codes, and replace them with opcode CDxxh, where 'xx' is a random selected byte. While executing the viruses replace these CDxxh back to CD21h. These infectors contain the text string: The Mutating Interrupt Virus RABID`S Back and Kicking in `93 -Soltan Griss-
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Foxz
Description Macro.Word.Foxz
This virus contains four macros in documents and eight in NORMAL.DOT: Documents NORMAL.DOT AutoClose AutoClose AutoOpen AutoOpen Action Action Foxz ToolsMacro, FileTemplates, ToolsMacro, ViewToolbars, HelpWordPerfectHelp
The virus infects the global macros area on opening an infected document (AutoOpen). It infects documents that are closed (AutoClose). It modifies the Windows 95 register information. It contains the comments: /---------------------------------------------------------------| You know Phardera?,he is X-SLAM member who kick out from SLAM | | and USE my Name [foxz] for spaming SLAM VIRUS TEAM. | | His real Name is Anton Reinhard Pardede!, he is a "Mikrodata | | Crewz"(Computer Magazine in my country), as long as I know, he| | work on Virus Division on that Magazine. | | By this virus I want everybody know that "the fucking lamer | | who Spaming SLAM" is not Me [foxz] | | Regards, | | Foxz/NoMercyVirusTeam Leader | ---------------------------------------------------------------/ ------------------------------------------------------------ Code Name : WM.FoxZ Gn.III also know as "WinFake" Author : Foxz [NoMercy] Origin : Yogyakarta Dedicated : for the fucking lamer "Phardera" who spaming SLAM VirusTeam with my Name ! Greetz : Cicatrix, SLAM Crewz and NoMercyVirusTeam Crewz Group : NoMercyVirusTeam Effect : Change Windows 9x Register ! Thanks to : CJC, Lucifer, Gurita, CrazyMan, Aurodreph and You who was see this Text !, see you in my Next virus :) ------------------------------------------------------------ October 30 '97 THANKS FOR SLAMVIRUS TEAM FOR THIS INFO !!! (SLAM mag)
Macro.Word.Friday
Description Macro.Word.Friday
This is an encrypted German-specific macro virus. It contains three macros: Documents NORMAL.DOT AutoOpen NOPO NOPS DateiSpeichern NOPSA DateiSpeichernUnter
It infects the global macros area on opening an infected document (AutoOpen) and copies itself to documents that are saved (DateiSpeichern, DateiSpeichernUnter - FileSave, FileSaveAs). Depending on the system date and time the virus sets a password for current document or/and exits Windows. On Friday13th it sets the password "Friday13".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|