Virus Database


BAT.Batalia4

Description BAT.Batalia4

This is the harmless non-memory resident parasitic BAT virus. It searches for BAT files in the current directory, then infectes them. While infecting a file the virus run the ARJ archiver to pack necessary files. If there is no ARJ.EXE file in PATH, the virus fails to replicate itself.
The virus contains two parts of code and data. The first part (the header) contains DOS commands:
@echo off
rem BAT4
arj x %0 >nul
call i
del sg
del i.bat
The second part (the rest) is an ARJ archive. This archive contains the I.BAT file that is the main virus code and the additional file named SG. The SG file contains several additional batch commands.
Thus any infected file contains the text strings (DOS commands) and the binary data (ARJ archive).
When executed, the virus runs the ARJ archiver, extracts the I.BAT and runs it. This batch file then searches for not infected BAT files in the current directory and infects them.
While infecting, the BAT.Batalia4 virus appends its code to the end of files and does not modify the original file contents.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Switcher

Description Macro.Word.Switcher

This is an encrypted stealth Word macro virus. It contains ten macros: AutoExec, AutoOpen, AutoClose, FileClose, FileOpen, FileSave, FileSaveAs, FilePrint, FileTemplates, ToolsMacro.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document, saving it, saving with new name, closing, printing and entering Tools/Macro menu. Documents get infection when they are saved, saved with new name or closed. The infection routine is placed in FileClose macro, other macros call that macro to run infection.
On closing a document if the seconds are less than 10, the virus replaces one random digit in current document. On entering Tools/Macro and File/Templates menus the virus displays the MessageBox:
Configuration conflict - menu item is not available.

Macro.Word.SwLabs

Description Macro.Word.SwLabs

This Word macro virus contains seven identical macros: AutoOpen, Skammy, AutoNew, AutoExit, FileOpen, AutoClose, FileClose.
It replicates on all calls listed above. Because of an error(?) it disables files opening - FileOpen does not display the Open File dialog.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Tekniskt Arbete
Tewako Logistik
Kol Senior Consulting
TandlÄkare Pia Waninger Aktiebolag
Lannefors - Konsult Handelsbolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com