Virus Database


Pyros

Description Pyros

It is a harmless nonmemory resident parasitic virus. It searches for .COM and .EXE files in the current directory, then checks files' internal format and infects DOS COM and EXE files, as well as Windows PE executable files. While infecting the virus writes itself to the end of the file. The PE infection routine is not correct enough, and infected PE files do not work under WinNT.
The virus code has two segments. The first segment is 16 bits DOS procedure that receives control when an infected DOS file is executed. The second segment is 32 bits routine that is activated when Windows infected executable starts. Both routines in similar way search for COM, EXE and PE files and infect them.
The virus does not manifest itself in any way. It contains the text strings:
[Pyros]
[Ruiner /CIH]

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Smac

Description Macro.Word97.Smac

This is a polymorphic macro-virus. It infects the global macros area on opening an infected document, and spreads itself to documents that are closed. The virus was named after one of its internal variables - "Smac".
The virus has stealth abilities, and on entering the ViewVBCode menu, it displays the message:
Illegal function in module 0xCB15C00

The virus contains six macros in one module "cb4111": AutoOpen, AutoExec, ViewVBCode, Do_The_Thing, AutoExit. The virus also has the Morph function that is used in virus polymorphic engine.
While infecting the NORMAL.DOT (global macros area), the virus also creates the infection AutoClose macro in there.
The virus contains the comments:
ThE wEiRd GeNiUs is back!
Greetings to the Codebreakers, VicodinEs & Lord Natas and to ALT-F11
Thanks for the cb4111 guide.
Until the next bug, greetings, WG

Macro.Word97.Sparkle

Description Macro.Word97.Sparkle

This is a stealth macro-virus. It contains three modules and 11 functions:
"Sparkle" - FileSave, Toolsmacro, Filetemplates, Sparkle,
Toolsmacro, Filetemplates, ViewVbCode,
"userform999" - ListBox2_Click, UserForm_Initialize, CommandButton2_Click,
CommandButton5_Click, UserForm_Click,
"userform900" - CommandButton1_Click, CommandButton2_Click,
CommandButton3_Click, CommandButton4_Click,
CommandButton5_Click, CommandButton6_Click, ListBox2_Click,
ScrollBar1_Change, UserForm_Click.

On saving files (FileSave), the virus disables the VirusProtection, infects the global macros area and documents.
The virus draws its own dialogue on entering the Tools/Macro menu (stealth). On pressing any button (except "Cancel"), the virus displays the MessageBox:
Microsoft Word
This program has performed an illegal operation and will shut down.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Cash Advance Loan
Preisvergleich
Chatroulette
Barclaycard.de
Kra Mark O Bygg

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com