Virus Database


Trash.512

Description Trash.512

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are closed. Sometimes it creates COM files with random name and leaves random data in these files.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Nuker

Description Macro.Word.Nuker

This is an encrypted Word macro virus. It contains 8 macros:
Documents NORMAL.DOT
AutoOpen AutoOpenNuke
AutoExecNuke AutoExec
FileOpenNuke FileOpen
FileSaveAsNuke FileSaveAs
FileTemplatesNuke FileTemplates
NukePower NuclearPower
ShellOpenNuke ShellOpen
ToolsMacroNuke ToolsMacro

The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are also opened (FileOpen). On infecting the virus checks files for other macros and deletes them, if they are found. The virus checks the filenames for special symbols (spaces, semicolons,all). If there is such one, the virus truncates the file name and displays the MessageBox:
NuclearPower
You cannot open multiple files at the same time with NuclearPower
installed. The first file you selected will be opened.

On saving document with new name the virus displays the InputBox:
Save As
Please, enter the name of the file:

The AutoExec macros (on Word startup) assigns the NuclearPower with "Ctrl+Shift+O" keys. This macro being executed displays the MessageBox:
NuclearPower greets you
You are infected by NuclearPower.
But, I swear that I am harmless and
I will protect you from any other macro virus!

The virus also modifies the System Registry, as a result the virus macros are executed on DDE calls.

Macro.Word.Ochoy

Description Macro.Word.Ochoy

This is an encrypted macro virus containing five macros in infected documents and ten macros in global macros area (NORMAL.DOT):
Documents NORMAL.DOT
Ard01, AutoOpen Ard01
Ard02 Ard02, FileSave, AutoClose
Ard03 Ard03, FileTemplates, ToolsMacro, ToolsCustomize
Ard04 Ard04, FileOpen

It infects the global macros area on opening an infected document (AutoOpen) and copies itself to documents that are saved or closed (FileSave, AutoClose). Before infecting the virus deletes all macros in target. The virus stores the counter of infections in document's variable "ard01". Depending on this counter the virus either prints to the status line the text "O C H O Y * P K T B N I", or displays the MessageBox:
BNI - PKT
(c) Ardi Sunardi - 1 9 9 7

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Mobile Affiliate Program
Reines Golv Aktiebolag
Tomcon Bil Aktiebolag
Maruuf Bilservice
Ixat Service Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com