Sylvia Family
Description Sylvia Family
These are harmless nonmemory resident parasitic viruses. They search for .COM files (except COMMAND.COM, IBMIO.COM, IBMDOS.COM) in the current directory of the current and C:drives, then infect not more than 5 files. They write themselves to the beginning of the file. If one corrects the text in the virus (see bellow), they halt the system, then decrypt and display the message: FUCK YOU LAMER !! system haltedall
There is the following text at the virus beginning: This program is infected by a HARMLESS Text-Virus V2.1 Send a FUNNY postcard to : Sylvia Verkade, Duinzoom 36b, 3235 CD Rockanje The Netherlands. You might get an ANTIVIRUS program.....
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Andry
Description Macro.Word.Andry
This encrypted virus contains only one macro AutoOpen and infects the global macro area on opening an infected document and writes itself to other documents when they are being opened. On March 1st it sets to documents the password "Andry Christian", prints the text to status bar: * I'M ANDRY CHRISTIAN, IF YOU THOUGHT, YOUR DOCUMENTS OR TEMPLATES WERE SAFE, YOU WERE WRONG ! *
It then displays the dialog: HACKERS Labs '96 - Hackware Technology Research ANDRY [CHRISTIAN] WORD MACRO VIRUS IS HERE !!! DO YOU SUPPORT MY VIRUS ? YES NO
In case of "NO" key the virus overwrites the C:AUTOEXEC.BAT file with commands: @ECHO OFF CLS ECHO Please wait . . . FORMAT C: /U /C /S /AUTOTEST > NUL
and the C:CONFIG.SYS file with commands: DOS=HIGH,UMB FILES=40 BUFFERS=40 DEVICE=C:DOSHIMEM.SYS DEVICE=C:DOSEMM386.EXE RAM
On the same date (March 1st) depending on the system time the virus runs the disk formatting command: COMMAND /C FORMAT C: /U /C /S /AUTOTEST > NUL
Depending on the system time the virus inserts into current document the text: Helloall. Andry Christian WordMacro Virus Is Here....!!!
The virus also contains the comments: '======================================================================' ' Source Code of Andry Christian WordMacro Virus 0.99 - ßeta Release ' '======================================================================' ' Virographer by Andry [Christian] in [Batavia] City, of INDONESIA ' ' Viroright (C) 1996-1999 Hackware Technology Research - HACKERS Labs. ' ' Multi Platform, Multi Infector, Stealth, OneMacro, Encryption, etc ' ' Last Update by 01-Maret-1996 & 01:03 PM - Found Bugs...? Call Me ' '======================================================================' ' HACKERS Labs. -> WE ARE A BIG FAMILY OF THE VIRUS CREATOR's TEAM ' '======================================================================'
Macro.Word.Angus
Description Macro.Word.Angus
It is an encrypted Word macro virus, it contains nine macros: Document NORMAL.DOT FileClose FC AutoOpen NOpen FileSave 7 other FileSaveAs with random FilePrint names FilePrintDefault FileTemplates ToolsMacro FileExit PCGURU4
It infects global macros area on opening or closing an infected document (AutoOpen, FileClose). It infects documents on saving and saving with new name (FileSave, FileSaveAs). While infecting documents the virus stores renames its macros (see above) with random names and saves references to them to document's variables. On October 23rd on printing documents the virus appends to the end of documents the message: NAENBGOURSG Hello from GREECE
On October 24th the virus creates and spawns the PCGURU4.BAT file that contains the instructions: @echo off Rem PcGuru4 virus by NAENBGOURSG Rem Golden Version 4.3 type PcGuru4.bat >> PcGuru4.bat
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|