Virus Database


Nova.a

Description Nova.a

It is a harmless memory resident boot virus. It hooks INT 13h, 1Ch and writes itself into MBR of the hard drive and boot sectors of the 1.2Mb floppy disks. The virus does not change the size of the system memory (the word at the address 0000:0413). On installation the virus decreases that number, waits for DOS loading (by hooking INT 1Ch), and then increases the size of the system memory.

Check other viruses! Be aware! Use Antiviral Software

Macro.Excel.Don

Description Macro.Excel.Don

This is an Excel macro virus. It contains one module DON that contains one function AutoOpen. The infection routine present in the virus code consists of 49 encrypted text strings. In case of need (on infection) the virus decrypts them, saves to the DON.TXT file, then copies this file to the macros area with name "Replicate" and executes it. After executing (i.e. after infecting a file or system) the virus deletes the "Replicate" module.
If an infected file is opened from Excel startup directory (i.e. the system is already infected) it sets its AutoOpen function on sheets deactivating (OnSheetDeactivate function) and infects the Workbooks on changing active sheet. Otherwise the virus creates an infected file with name <number>.DON in Excel startup directory, i.e. infects the system.
The virus can be easily detected by the presence of a <number.DON> file in the XLSTART directory. The virus also creates the DON2.TXT file and writes to there the name of active Workbook.

Macro.Excel.Emperor.a

Description Macro.Excel.Emperor.a

This virus infects Excel sheets. It contains one macro (module) with the name "Emperor[number]" that contains five functions:
Auto_Open, keyplus, check_file, write_virus, run_virus
Upon opening (closing), the infected Excel file executes the Auto_Open (Auto_Close) virus function. This function summons the check_file (CheckFile) function that sets a four-digit password to the virus sheet. The virus then makes visible all hidden windows, looks for the "Emperor" module in all Workbooks and infects uninfected ones. While infecting, the virus copies its macro with the name "Emperor[number of infection]". The virus then closes all windows that were opened during infection.
The virus deletes the menus: Worksheet View - Toolbars, Format - Sheets, Tools - Scenario; Module - Edit/Delete, Tools/Menu Editor, Tools/Protection.
On the 1st and 15th of any month, depending on the random system counter, the virus displays the MessageBox:
The First Emperor Ver 1.00 [02/29/1997]
[the rest of the text is in unknown coding]

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Dell Inspiron 640m Battery
Kuching Houses
Billiga Fönster
Elektro Ohm I Stockholm Ab
SmÅdjurskliniken I Askersund Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com