Tero.308
Description Tero.308
It is a harmless nonmemory resident encrypted parasitic virus. It searches for .COM files, then writes itself to the end of the file. The virus does not manifest itself in any way, it contains the text string: Tero by ETropf *.com
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Tenfaces
Description Macro.Word.Tenfaces
This is an encrypted macro virus. It contains three original macros, but while infecting it copies it with 8 different names to global macros area and with 4 names to documents. While copying the virus selects random name to hide its macros: Documents NORMAL.DOT Macro1: AutoOpen xxxxxLove xxxxxLove Macro2: xxxxxAnik xxxxxAnik FileClose Macro3: xxxxx1109 xxxxx1109 ToolsMacro Organizer ToolsCustomize FileTemplates
where "xxxxx" are random strings. The virus infects the system on AutoOpen call and writes itself to files on AutoClose. Macro3 is a payload macro and it disables Tools/Macro, Tools/Customize and File/Templates menus as well as Organizer. On these calls the virus displays the MessageBox: Microsoft Word You try to Kill meallhah!, I beat your Keyboard!
It then changes the keyboard layout. The virus also creates new variables in system profiles (WIN.INI file) in [Intl] section: Code_Name=WORDMACRO.TENFACES Creator=Creator of NoMercy! Dedicated=My Love, Anik AY
Macro.Word.Testarea
Description Macro.Word.Testarea
This macro virus contains only one macro AutoClose and replicates on closing a document. While infecting the virus saves the "backup" copy of document to the O:COMPSERVTESTAREA directory and saves the "report" information to the LOG.VRS file in the same directory: <UserName> <DocName> <DocPath> <DocName.VDC infection number> <date and time> The virus also contains the text: all.................Smile, I'm watching you................... :)
|