Rabbit.504
Description Rabbit.504
This is a dangerous, non-memory resident parasitic virus. It searches for COM files, then scans the file for the zero-bytes area 504 bytes in length and, writes itself to there. If there is no such cave, the virus does not infect the file. After infecting each file, the virus displays the file name. The virus has a bug and corrupts some files while infecting them.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Alliance
Description Macro.Word.Alliance
This virus contains only one macro in infected documents - AutoOpen, but while infecting the system it copies it to two macros - AutoOpen and AutoNew. As a result, the virus infects the system on opening an infected document, and infects the documents that are opened or created. The virus sets Subject in the FileSummaryInfo to: You Have Been Infected by the Alliance
Macro.Word.Anak
Description Macro.Word.Anak
This is an encrypted macro virus. It contains four original macros that are copied to five ones while infecting documents and NORMAL.DOT: Documents NORMAL.DOT Macro1 anakAE AutoExec Macro2 AutoOpen anakAO anakAO Macro3 anakSA FileSave anakSA Macro4 anakSMU anakSMU
The virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to document on saving them (FileSave). The virus defines new short cut key "Shift-Ctrl-F" and associates it with Tools/Customize menu. To hide its macros (stealth feature) the virus removes the File/Templates, Tools/Macros and Tools/Customize menus. Starting from 25th of any month, starting from 14:00 the virus creates new template, inserts the text into there: alli n t r o d u c i n g... anakSMU Semarang, March 1997
The virus then registers itself in the system. To do that it creates the ANAKSMU.BAT file, writes the commands to there and executes it: @ECHO OFF REM --------------------------------------------------------- REM anakSMU wont destroy your REGEDIT, Just wanna be there :) REM email: anakSMU@TheOffice.net" REM --------------------------------------------------------- ECHO REGEDIT4 > anakSMU.REG ECHO [HKEY_CURRENT_USERSoftwareanakSMU] >> anakSMU.REG ECHO [HKEY_CURRENT_USERSoftwareanakSMUanakSMU@TheOffice.net] >> anakSMU.REG ECHO [HKEY_CURRENT_USERSoftwareanakSMU18.090 - Semarang] >> anakSMU.REG START /MIN REGEDIT anakSMU.REG EXIT
The virus then displays the MessageBox: anakSMU Yeah!, I wish I were anakSMU
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Colon Cleaner Gnc Breast Enlargement Supplements No Credit Check Payday Loan Sensa Pens
|