Virus Database


Rajaat.144

Description Rajaat.144

These are harmless memory resident viruses. They hook INT 21h and contain the string "Rajaat".
"Rajaat.287,443" are companion viruses. When any .EXE file is executed, they create companion .COM files.
"Rajaat.443" also hooks INT 28h. On INT 28h calls it searches and infects .EXE files.
Other "Rajaat" viruses are parasitic ones, they write themselves to the end of EXE files that are executed.
Rajaat.144,146
These are a dangerous nonmemory resident parasitic viruses. They search for .COM files and write themselves to the beginning of the file. The infection way is quite smart, but they may corrupt files or/and halt the system. They contain the text string:
*Rajaat.COM

Rajaat.RTFM
It is a harmless nonmemory resident polymorphic parasitic virus. It searches for .COM files and writes itself to the end of the file. It contains the text strings:
Rajaat
[RTFM]

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Trojan.Format

Description Macro.Word.Trojan.Format

This is a Word macro-Trojan. It contains one macro: AutoOpen. This Trojan inserts into the file AUTOEXEC.BAT commands that delete files and format the hard drive. The Trojan also inserts the following text into the current document:
RESET seu micro agora seu LAMMER BURRO !!!
Auto-Destrui o em 15 seg.

and shutdowns Windows.

Macro.Word.Tunguska

Description Macro.Word.Tunguska

This is an encrypted Italian macro virus. It contains eight macros: AutoExec, AutoOpen, FileApri, AutoClose, FileSalva, GuidaSupporto, FileSalvaConNome, GuidaInformazioni.
The virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to documents on saving and saving with new name (FileSalva, FileSalvaConNome).
The virus creates two strings in the WINWORD6.INI file in [Microsoft Word] section:
DictionaryHelp=1
DOC-PATH=<NORMAL.DOT directory>

The virus also tries to read from this section two variables: "CheckCRC" and "Debug". If CheckCRC=1, the virus disables its infection routine. If Debug=1, the virus displays many debug MessageBoxes.
The virus contains the comments:
------------------------------------------------------------------------
Virus: TUNGUSKA
------------------------------------------------------------------------
Variabile in Winword6.ini:
CheckCRC$ : se = 1, il virus NON infetta il MIO computer
Debug$ : se = 1, visualizzo i messaggi di Debug
DictionaryHelp$ : se = 1, scattata una certa data
------------------------------------------------------------------------
MACRO Italiane MACRO Inglesi COMMENTO
------------------------------------------------------------------------
AutoClose AutoClose intercetta doppio-click
AutoExec AutoExec intercetta avvio Word
AutoOpen AutoOpen intercetta apertura file
FileApri FileOpen intercetta Dialogo Apri
* FileChiudiOChiudiT. FileClose intercetta chiusura file
FileSalva FileSave intercetta salva file
FileSalvaConNome FileSaveAs intercetta Dialogo SalvaConNome
* FileModelli Templates intercetta Dialogo Modelli
GuidaInformazioni GuidaInformazioni virus
GuidaSupporto GuidaSupporto per controllo presenza virus
------------------------------------------------------------------------

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Pr-dienst
Online Bookmarks
Fantasy Art
Men's Haircuts

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com