Pyros
Description Pyros
It is a harmless nonmemory resident parasitic virus. It searches for .COM and .EXE files in the current directory, then checks files' internal format and infects DOS COM and EXE files, as well as Windows PE executable files. While infecting the virus writes itself to the end of the file. The PE infection routine is not correct enough, and infected PE files do not work under WinNT. The virus code has two segments. The first segment is 16 bits DOS procedure that receives control when an infected DOS file is executed. The second segment is 32 bits routine that is activated when Windows infected executable starts. Both routines in similar way search for COM, EXE and PE files and infect them. The virus does not manifest itself in any way. It contains the text strings: [Pyros] [Ruiner /CIH]
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Smac
Description Macro.Word97.Smac
This is a polymorphic macro-virus. It infects the global macros area on opening an infected document, and spreads itself to documents that are closed. The virus was named after one of its internal variables - "Smac". The virus has stealth abilities, and on entering the ViewVBCode menu, it displays the message: Illegal function in module 0xCB15C00
The virus contains six macros in one module "cb4111": AutoOpen, AutoExec, ViewVBCode, Do_The_Thing, AutoExit. The virus also has the Morph function that is used in virus polymorphic engine. While infecting the NORMAL.DOT (global macros area), the virus also creates the infection AutoClose macro in there. The virus contains the comments: ThE wEiRd GeNiUs is back! Greetings to the Codebreakers, VicodinEs & Lord Natas and to ALT-F11 Thanks for the cb4111 guide. Until the next bug, greetings, WG
Macro.Word97.Sparkle
Description Macro.Word97.Sparkle
This is a stealth macro-virus. It contains three modules and 11 functions: "Sparkle" - FileSave, Toolsmacro, Filetemplates, Sparkle, Toolsmacro, Filetemplates, ViewVbCode, "userform999" - ListBox2_Click, UserForm_Initialize, CommandButton2_Click, CommandButton5_Click, UserForm_Click, "userform900" - CommandButton1_Click, CommandButton2_Click, CommandButton3_Click, CommandButton4_Click, CommandButton5_Click, CommandButton6_Click, ListBox2_Click, ScrollBar1_Change, UserForm_Click.
On saving files (FileSave), the virus disables the VirusProtection, infects the global macros area and documents. The virus draws its own dialogue on entering the Tools/Macro menu (stealth). On pressing any button (except "Cancel"), the virus displays the MessageBox: Microsoft Word This program has performed an illegal operation and will shut down.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Cash Advance Loan Preisvergleich Chatroulette Barclaycard.de Kra Mark O Bygg
|