Roohi.2048
Description Roohi.2048
This is a relatively harmless memory resident parasitic virus. The virus stays memory resident only under DOS 5.0 or higher, in another case it displays: Incorrect DOS version
and terminates the execution of the host program. While installing, the virus hooks INT 21h, and intercepts ChDir DOS functions. While selecting a new subdirectory, the virus searches for all EXE files except SCAN.EXE, CLEAN.EXE, FINDVIRU.EXE, and writes itself into the file middle between the EXE header and the module body. The virus has a bug, and fails to infect files on the hard drive. On the 13th of any month, the virus displays the following message and halts a PC: Roohi v2.0 This is Power of Iran - 1995 Roohi Virus Found, By Seyed Roohollah Marashi
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Bench.c
Description Macro.Word97.Bench.c
This virus runs its infection routine when any of its auto-macros. As well as Macro.Word97.Bench.a virus it disables macro viewing menus. It also sets the security level to minimal one. If global macros area is already infected, the virus displays the text "-=([B]MV.F)=-" to the application caption, and the text "-=([Bench] Macro Virus - Strain F)=-" to the status bar. On exiting MS Word the virus searches and infects all documents in current folder. On document saving it looks for anti-viruses NAV and F-PROT on the C: drive and remove their files, displays to the application's caption "-=([B]MV.F])=-" and "-=([B]MV.F)=- / SAiNTS ViRii Dept. - Test Version" to the status bar. On entering the Visual Basic Editor the virus denies the operation and displays balloon with message: [Bench] Macro Virus - F You're not permitted to go there! Now you're gonna pay! Then it saves the active document with the "[Bench]" password, drops on the disk and executes a file infected by the Win95.CIH virus, and then displays another balloon with the message: [B]MV.f I have just attempted to install the CIH virus on your system. I just felt like warning youall
Macro.Word97.Biok.a
Description Macro.Word97.Biok.a
This macro virus contains eight macros in module "BiosKiller": AutoExec, Document_Open, FileSaveAs, FileTemplates, HelpAbout, PayBiosKiller, ToolsMacro, ViewVBCode. The global macros area (NORMAL.DOT) gets infection when an infected document is opened (Document_Open). The virus spreads itself to other documents on their saving with new name (FileSaveAs). The virus copies its code from file to file by using Import/Exports VisualBasic calls via the C:BK.SYS and C:APVBK.SYS disk files. The virus disables the Word VirusProtection. On entering the FileTemplates menu the virus displays the MessageBox: Virus BiosKiller Vous feriez mieux de vous acheter un AVall
On entering the ToolsMacro menu the virus displays the MessageBox: Virus BiosKiller Je suis un virus comme CIH...
On starting MS Word at 16 minutes of any hours or at 26 seconds of any minute the virus displays the MessageBox: Virus BiosKiller Vous connaissez le virus CIH ? Je fais la même chose que lui...
On starting MS Word on 26th of any month the virus displays the MessageBox: Virus BiosKiller Votre Bios va subir des changements... HAHAHAHAHA
It then creates the C:CMOS.BAS, writes a CMOS-erasing instructions to there and executes it with a help of DOS QBASIC utility. The virus then calls the ExitWindows function.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Twisthead Sisthair Roumeliotis, Georgia Roy International Ab Bimo StÄd & Hobby HEXIRON AB
|