Virus Database


NightKing.1568

Description NightKing.1568

It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files (except AVG.EXE) that are executed or opened. While infecting a computer the virus stores the current time in the MBR of the hard drive, and one month after infecting the virus reads to the memory the FAT of the C: drive, then corrupts the FAT, displays the message:
+-----------------------------------------------+
¦ Hello dear friend, your computer is attacking ¦
¦ by NIGHT KING I. virus. If do you like your ¦
¦ data very much, don't reset your computer ¦
¦ before midnight ! ¦
+-----------------------------------------------+

then the virus waits till midnight and restores the corrupted data. If the computer is rebooted before midnight the FAT is lost.

Check other viruses! Be aware! Use Antiviral Software

Macro.Excel97.Sugar.a

Description Macro.Excel97.Sugar.a

These are stealth Excel97 macro-viruses. They hook windows/sheets activation and deactivations events and infect corresponding files. While infecting, the viruses save their code as "class" macros (see also "Macro.Word97.Class").
Sugar.a
It creates the infected BOOK1 file in the Excel start-up directory. It disables the Macro Virus Protection by direct access to the system registry.
Depending on the current minute, day and month, the virus inserts into the current sheet up to 200 cells with a text inside "-(Dr. Diet Mountain Dew)-", changes their size and color, and then inserts the message "The -[Sugar.Poppy]- by VicodinES" to the very first cell of the sheet.
The virus also contains the following comments:
'=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'
'The Sugar.Poppy Excel Class Object Virus'
' written by VicodinES '
'=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'
' Can I have a bottle of '
' WARM DIET MOUNTAIN DEW '
'=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'

Sugar.b
This virus is very similar to the previous version. It also disables the Macro Virus Protection in the system registry, but does it with the help of MS Word: the virus transfers, to Word's global macros area, the AutoExec macro that by VisualBasic instructions disables VirusWarning when Word is executed.
This virus contains the following comments:
'-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'
'Sugar.Poppy.II Excel Class Object Virus'
' written by VicodinES '
'-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'
' Can I have a bottle of '
' WARM DIET MOUNTAIN DEW '
'-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'
' Now it infects '
' ANY AND ALL CLASS OBJECTS '
'-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'
' Module Parasitic Code Added '
'-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-'

Macro.Excel97.SW.a

Description Macro.Excel97.SW.a

This Excel macro virus is related to "Macro.Excel.Laroux". It intercepts a sheet's activation routine, and infects Excel worksheets. It contains three macros in the module "sw": Auto_Open, no, Auto_Close.
The virus deletes all menu items, shortcut menus and hot key used to view macros or related to this. Depending on the current time, the virus changes all values in the cells from B4 till G40 - it multiplies all these values by ten. On Saturdays and Sundays, the virus cleans the current sheet, and displays the following in the MessageBox:
Ha! Ha! Ha! Idiot ! ! !
Today is rest day!
Why do you work so hard?
All work and no play make you a dull boy!
Come on! Let's go out and have some fun!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com