Trash.512
Description Trash.512
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are closed. Sometimes it creates COM files with random name and leaves random data in these files.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Nuker
Description Macro.Word.Nuker
This is an encrypted Word macro virus. It contains 8 macros: Documents NORMAL.DOT AutoOpen AutoOpenNuke AutoExecNuke AutoExec FileOpenNuke FileOpen FileSaveAsNuke FileSaveAs FileTemplatesNuke FileTemplates NukePower NuclearPower ShellOpenNuke ShellOpen ToolsMacroNuke ToolsMacro
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are also opened (FileOpen). On infecting the virus checks files for other macros and deletes them, if they are found. The virus checks the filenames for special symbols (spaces, semicolons,all). If there is such one, the virus truncates the file name and displays the MessageBox: NuclearPower You cannot open multiple files at the same time with NuclearPower installed. The first file you selected will be opened.
On saving document with new name the virus displays the InputBox: Save As Please, enter the name of the file:
The AutoExec macros (on Word startup) assigns the NuclearPower with "Ctrl+Shift+O" keys. This macro being executed displays the MessageBox: NuclearPower greets you You are infected by NuclearPower. But, I swear that I am harmless and I will protect you from any other macro virus!
The virus also modifies the System Registry, as a result the virus macros are executed on DDE calls.
Macro.Word.Ochoy
Description Macro.Word.Ochoy
This is an encrypted macro virus containing five macros in infected documents and ten macros in global macros area (NORMAL.DOT): Documents NORMAL.DOT Ard01, AutoOpen Ard01 Ard02 Ard02, FileSave, AutoClose Ard03 Ard03, FileTemplates, ToolsMacro, ToolsCustomize Ard04 Ard04, FileOpen
It infects the global macros area on opening an infected document (AutoOpen) and copies itself to documents that are saved or closed (FileSave, AutoClose). Before infecting the virus deletes all macros in target. The virus stores the counter of infections in document's variable "ard01". Depending on this counter the virus either prints to the status line the text "O C H O Y * P K T B N I", or displays the MessageBox: BNI - PKT (c) Ardi Sunardi - 1 9 9 7
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Mobile Affiliate Program Reines Golv Aktiebolag Tomcon Bil Aktiebolag Maruuf Bilservice Ixat Service Aktiebolag
|