Virus Database


BAT.CopyToC

Description BAT.CopyToC

These script viruses are written in BAT, and copy themselves to directories on the C: drive.
BAT.CopyToC.a
This virus is 552 bytes in size. When launched for the first time, the virus creates a file named 1.sys in the Windows directory. It then copies itself to the C: root directory as AllTheBat.bat.
The virus registers this file in the system registry to ensure that the file is automatically launched each time the system is started.
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
"AllTheBat"="c:\AllTheBat.bat"
It creates an additional file named C:AllTheBat.reg to enable it to do this.
On subsequent launches, the virus will rename all files in the current directory. It also adds the extension .bat to the name of every file. The virus attempts to copy itself to the A: drive as A: eadme.txt.bat.
BAT.CopyToC.b
This virus is 1262 bytes in size. The virus attempts to copy itself to the C: drive under the following names:
c:Gunslinger.bat
c:progra~1msnmes~1Gunslinger.bat
c:progra~1msnmes~11043data.bat
c:progra~1window~1Gunslinger.bat
c:progra~1window~1skinsdata.bat
c:progra~1window~1Visual~1user.bat
c:progra~1internGunslinger.bat
c:progra~1internpluginsdata.bat
c:progra~1internsignupuser.bat
c:progra~1internw2kcpu.bat
Payload
The virus deletes EXE files in the C:progra~1 and C:Windows directories.
BAT.CopyToC.c
This virus is 825 bytes in size. The virus copies itself into other files on the C: drive.
New files which contain a copy of the virus will have the following names:
c:Autorun.exe.bat
c:windows askman.exe.bat
c:windowsNotepad.exe.bat
c:windowssystem32xcopy.exe.bat
c:windowsystem32systray.exe.bat
Payload
The virus disables the mouse and the keyboard by launching C:Windows undll32 with the appropriate commands.
It deletes .sys files from the Windows system directory and creates text files in the C: root directory.
The C:Readme.txt file contains the following text string:
Now you are f*ck
The C:Virus Info.txt file contains the following text string:
Poop Smells

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Random

Description Macro.Word.Random

This is a harmless macro virus. It contains only one macro, but while infecting a document of the global macros area it copies this macro with a name that it random selected from ten variants:
AutoOpen, AutoClose, AutoNew, AutoExec, AutoExit, FileSaveAs, FileOpen, FileClose, autoOpen, FileExit
While infecting the virus displays a MessageBox with the selected name. The virus infects the files two and more times, as a result infected documents and templates may contain from one up to ten macros.

Macro.Word.Randomic

Description Macro.Word.Randomic

This Word macro virus contains only one macro with random selected name: <random letter><random number>. It infects the documents and NORMAL.DOT on keystroke that is assigned to this macros, this key is also pointed by document's variable "TKey".
The virus removes the Tools menu. On April 4th it displays the dialog and reboots the computer:
>> RANDOMIC << STRANGE LUCK >> RANDOMIC <<
______________________________________________
Your system is infected
with the RANDOMIC macro virus.
Immediately stop your work, or you will regret it.
______________________________________________
That's maybe your last chance!!!
______________________________________________
Nightmare Joker [SLAM]
1997

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Åkerholm, Anna Karin
Salatullens Bilservice
Din MÄklare I SkÅne Handelsbolag
Lenson Ab
Andra HjÄlpen Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com