SeeYou family
Description SeeYou family
These are very dangerous memory resident partly encrypted boot viruses, stealth. They infect the boot sector of C: drive as well as boot sector of floppy disks. While loading from infected disk they reserve a block of memory by decreasing the size of DOS memory (the word at the address 0000:0413), copy themselves to that block, hook INT 13h, wait for DOS loading process, hook INT 21h and on first execution of DOS program (usually - COMMAND.COM) they allocate a block of DOS memory, copy themselves to there and restore the original size of DOS memory. As a result they hide themselves between DOS kernel and resident copy of COMMAND.COM. Depending on the system date they erase disk sectors and displays one of the messages: See you later all Happy birthday, Populizer !
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Schoo
Description Macro.Word.Schoo
This is an encrypted virus. It contains 7 macros: Documents NORMAL.DOT GRBack GetRid AutoOpen AutoOpen2 FileSave FileSave VerIdent2 VerIdent FileSaveAs FileSaveAs BJTradeMark BJTradeMark ToolsSpelling ToolsSpelling
It infects the global macros area on opening an infected document. It infects files that are saved with new name. The virus adds new commands to Word auto-correction: school -> schoo' recognize -> reckonize recognized -> reckonized assembly -> assemily CHS -> Crowley High Schoo'
Since 28 of May 1998 the virus displays many MessageBoxes, for example: Microsoft Word Virus Alert Warning: The 'Big Johnson' Virus has been detected.
On 28 may 1998 it display the MessageBox: Microsoft Word Virus Alert Transferring control to virus subroutine: Virus initializingall It's the last day of school!
On all following days it displays the MessageBox: Microsoft Word Virus Alert Transferring control to virus subroutine: Virus initializing... School's out!
Macro.Word.Screw
Description Macro.Word.Screw
This macro virus contains 11 macros: Documents NORMAL.DOT ABC ABC AO AO AutoOpen FileOpen FileTemplates FP FP, FilePrint FSA FSA, FileSave, FileSaveAs HLP HELP, HLP SCR SCR TMC ToolsMacro, ToolsCustomize, FileTemplates, TMC ToolsMacro
It infects the global macros area on opening an infected document, but has an error - it copies nonexistent macros AE instead of AO. As a result this virus is able to replicate only once - there will be no AutoOpen macro in second generation. On printing depending on the current time the virus pastes at the end of the document the text "SCREW VIRUS IS HERE" and replaces all sequences: ' a ' -> ' e ' ' I ' -> ' Me ' '. ' -> ' !!! '
and restores them after printing. The virus installs new ScreenSaver (Marquee), this saver will display the message: You Are Infected With The Screw Virus!!!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|