Virus Database


Nculi.1688

Description Nculi.1688

It is a dangerous memory resident parasitic virus. It traces INT 13h, 21h, hooks INT 21h and then writes itself to the end of EXE files. The infected files contain the texts at the end of the file:
NCU LI

Sometimes the virus decrypts and displays the message, and then halts the system:
PARITY ERROR ADDR (HEX) = ( 02C14H ) SYSTEM HALTED

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.PBB

Description Macro.Word97.PBB

This virus spreads itself on documents opening and closing. On opening a document the virus checks the system date. If day number is less than 3, the virus hides mouse cursor and displays the message:
Created By Yusril Ihza Mahendra
PARTAI BULAN BINTANG

Another virus routine deletes all libraries (.DLL) files from Windows system folder if day number is greater than 25. This routine is executed on document opening, calling Visual Basic Editor and clicking "Tools/Macro" menu.
The virus body contains the text strings:
Macros Pbb mungkin tidak bisa Anda hapus, Anda hanya bisa menghapus makro
buatan Anda (Descr: 'Makro non-Pbb')
Terimakasih Anda Telah
Memproteksi Word dengan Aman

Macro.Word97.Peace

Description Macro.Word97.Peace

This virus contains two macros in module "peace": AutoOpen, helpabout. It replicates on documents opening. It disables the menu items "Tools/Macro" and "Tools/Templates and add-insall". On 1st of each month on entering the Help/About it displays the MessageBox:
Peace
Copy me I want to travel

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



VERISEC AB
MATS ERIKSSON I STOCKHOLM AB
UNISEC VARULARM AB
TKBM BIL AB
LANGENFELD BAD AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com