Virus Database


AAV.8224

Description AAV.8224

It is a very dangerous memory resident parasitic virus. It hooks INT 10h, 13h, 16h, 21h and stays memory resident. When any file is executed, or on DOS GetDiskSpace call, or in its INT 10h handler, if the system is not busy, the virus searches for .COM and .EXE files and writes itself to the end of the file.
The virus pays special attention for C:COMMAND.COM file and infects it in the way similar to the "Peasant" virus - it overwrites the beginning of the COMMAND.COM with 512 bytes of virus loader and saves the original COMMAND.COM's header and the rest of the virus code to the not used sectors of the first track on the hard drive.
When infected COMMAND.COM is executed, virus loader reads the rest of the virus code from the hard drive, stays memory resident, then restores the original beginning of COMMAND.COM and returns control.
This way of infection may corrupt the data and the files. The virus may also halt the system while loading memory resident - it uses quite complex way of interrupts hooking/releasing and may corrupt DOS kernel.
Depending on the system time, date and several other conditions the virus displays the messages in Chinese and in English:
THIS FILE MAY BE INFECTED WITH VIRUS
TO KILL VIRUS,YOU CAN REINSTALL THIS FILE
IDEARS AUTO_ANTI_VIRUS SOFTWARE GROUP AAV MARK:4540055520
AUTO_ANTI_VIRUS
THIS FILE IS SAFE THANKS FOR USE AAV
IDEARS AUTO_ANTI_VIRUS SOFTWARE GROUP AAV MARK:4540055520

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Ping

Description Macro.Word97.Ping

This virus contains one procedure "Document_Open" in one module. The virus infects the global macros area on opening an infected document. Other documents get infection on their opening. While infecting the virus turns off the Word virus protection (the VirusProtection option).
On every document open the virus attacks (floods) four internet web servers. For that it executes system program that continuesly sends ICMP packets. This kind of attack slow down or even crashed attacked server and also overflows user internet channel. This program virus runs four times, one copy for each server from the list:
innocentangels.com
whitesonly.net
kkk.com
daddysgirl.com

Macro.Word97.Plain

Description Macro.Word97.Plain

This macro virus contains only one macro named AutoClose. It infects the system and documents on closing files. Being run on Macintosh computers since 5th day of any month it erases files on disk.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Hair Loss Treatment
Datenschutz
Hot Jessica Biel
Private Domain Registration
Health And Safety Consultants

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com