Squad.1299
Description Squad.1299
It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 10h, 17h, 21h and writes itself to the end of COM and EXE files that are executed. On opening .C, .CPP, .PAS, .TXT and .PRG files the virus overwrites them with the text: This virus is a publicity stunt of the DOG SQUAD (CSE 93 Batch of RECJ) and has been issued in public interest by the Registar of the Squad. Long Live N.P.
The virus disables printing (INT 17h) and several graphic video modes (INT 10h).
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Waverley
Description Macro.Word.Waverley
This virus contains only one macro, AutoClose, and infects files upon closing. It then checks the system date and time and starting from October, if the seconds are 45 or more, the virus appends the following to the end of a document: We are citizens of Australia. We are youth of Victoria. We are victims of Mount Waverley Secondary College. We tolerated your discipline. We stomached your abuse. We bore your unprofessionalism. We toed the line to protect the bullshit image of YOUR school. We watched our friends be pressured out of your school, just so you could keep your fucking pass rate figures up. And now the world will see, through the spread of this virus just how TOTALLY FUCKED UP we are! Parents: yeah- go ahead send your kids to a school where about half of us use drugs. You won't see those figures in the glossy brochure. This community announcement was proudly sponsored by: M.W.S.C. Year 12 Class Of '96. - in YOUR face.
Macro.Word.Wazzu
Description Macro.Word.Wazzu
This virus contains only one macro autoOpen and infects files when MS Word opens them, and copies its macros to Global area (NORMAL.DOT) when MS Word opens an infected document. The virus is not encrypted and may be easily detected by scanning for text strings: RndWorddo wazzu do RndWorddRgV
After infecting a document or installing into the system the virus takes a random selected word from document and moves it to random selected position. The virus repeats that up to three times depending on the random counter. Then it also depending on the random counter inserts the string "wazzu " at random selected position within document. In detail: the virus has three subroutines in its macro: MAIN - it is main routine and it takes control when autoOpen macro is executed Payload - is called by MAIN, replaces words and inserts "wazzu". RndWord - is called by Payload, sets random selected position within document
The virus modifies the document with the probabilities (p): replacing words - three times with p=1/5, inserting "wazzu" - p=1/4. Wazzu-related viruses The original "Wazzu" ("Wazzu.a") virus is one of the most widespread viruses on the world. The possible reason is that this virus was placed on the Microsoft WWW site, infected documents also were (are) distributed on several CD disks. As a result there are several dozens of related viruses, and the number of such related viruses is increasing every month. Below short descriptions are given, to name viruses CARO standard names are used (AVP does detect and disinfect majority of these viruses as "Wazzu.a"). "Wazzu.b,i" differ from original one only by included comment: < - - - - - - here 's the payload
"Wazzu.c,t,ac" do not manifest themselves in any way - they have no Payload subroutine (RndWord subroutine presents in virus, but is never called). "Wazzu.d,f,q,w,ad" do not have both Payload and RndWord subroutines. "Wazzu.f" is a shortest virus in the family - its code (binary data in infected file) has only 318 bytes of length. "Wazzu.e,h" are encrypted variants of original "Wazzu". "Wazzu.h" is slightly corrupted and may halt MS Word or cause an error message. "Wazzu.g,r" are encrypted viruses. "Wazzu.g" contains EatThis subroutine instead of original Payload. With probability 1/10 these viruses display a MessageBox with the text: Microsoft Word This one's for you, Bosco.
"Wazzu.k" is corrupted "Wazzu.a". "Wazzu.l" do not have any subroutines in macro except MAIN. With probability 1/10 it appends the string " wazzu!" to the end of document. "Wazzu.m,s" have no Payload subroutine, but call it. That will cause Word's error message. "Wazzu.u,aa,ad" are the same as "Wazzu.a", but do not insert the "wazzu" string. "Wazzu.x" does not contains any subroutines except MAIN. It contains the text: The Meat Grinder virus - Thanks to Kermit the Frog, and Kermit the Protocol
"Wazzu.y,z" are the same as "Wazzu.a", but code of these virus is slightly modified, for example all TAB (09h) symbols are replaced with 8 spaces in "Wazzu.y".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
People With Fair Credit Property Montenegro Algarve Car Hire Portugal Web Design Austin
|