Virus Database


SeeYou family

Description SeeYou family

These are very dangerous memory resident partly encrypted boot viruses, stealth. They infect the boot sector of C: drive as well as boot sector of floppy disks. While loading from infected disk they reserve a block of memory by decreasing the size of DOS memory (the word at the address 0000:0413), copy themselves to that block, hook INT 13h, wait for DOS loading process, hook INT 21h and on first execution of DOS program (usually - COMMAND.COM) they allocate a block of DOS memory, copy themselves to there and restore the original size of DOS memory. As a result they hide themselves between DOS kernel and resident copy of COMMAND.COM.
Depending on the system date they erase disk sectors and displays one of the messages:
See you later all
Happy birthday, Populizer !

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Schoo

Description Macro.Word.Schoo

This is an encrypted virus. It contains 7 macros:
Documents NORMAL.DOT
GRBack GetRid
AutoOpen AutoOpen2
FileSave FileSave
VerIdent2 VerIdent
FileSaveAs FileSaveAs
BJTradeMark BJTradeMark
ToolsSpelling ToolsSpelling

It infects the global macros area on opening an infected document. It infects files that are saved with new name.
The virus adds new commands to Word auto-correction:
school -> schoo'
recognize -> reckonize
recognized -> reckonized
assembly -> assemily
CHS -> Crowley High Schoo'

Since 28 of May 1998 the virus displays many MessageBoxes, for example:
Microsoft Word Virus Alert
Warning: The 'Big Johnson' Virus has been detected.

On 28 may 1998 it display the MessageBox:
Microsoft Word Virus Alert
Transferring control to virus subroutine:
Virus initializingall
It's the last day of school!

On all following days it displays the MessageBox:
Microsoft Word Virus Alert
Transferring control to virus subroutine:
Virus initializing...
School's out!

Macro.Word.Screw

Description Macro.Word.Screw

This macro virus contains 11 macros:
Documents NORMAL.DOT
ABC ABC
AO AO
AutoOpen
FileOpen
FileTemplates
FP FP, FilePrint
FSA FSA, FileSave, FileSaveAs
HLP HELP, HLP
SCR SCR
TMC ToolsMacro, ToolsCustomize, FileTemplates, TMC
ToolsMacro

It infects the global macros area on opening an infected document, but has an error - it copies nonexistent macros AE instead of AO. As a result this virus is able to replicate only once - there will be no AutoOpen macro in second generation.
On printing depending on the current time the virus pastes at the end of the document the text "SCREW VIRUS IS HERE" and replaces all sequences:
' a ' -> ' e '
' I ' -> ' Me '
'. ' -> ' !!! '

and restores them after printing.
The virus installs new ScreenSaver (Marquee), this saver will display the message:
You Are Infected With The Screw Virus!!!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com