Bel.2124
Description Bel.2124
It is a very dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or opened. The virus checks file names and does not infect files: CO*, DR*, WE*, AI*, AD*, VB*, AV*, HI*, CH*, CC*. Depending on the system date the virus deletes files with extensions: .CFG, .TIC, .PAC, .PAK, .SAV, .WAD and some other. The virus contains the text strings: * reBEL.P1 * üâô (Belarus). Hi, Mr. Kolyada!
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.WallPaper
Description Macro.Word.WallPaper
This is an encrypted macro virus. It contains two original macros, but while infecting global macros area the AutoOpen macro is copied to four macros: Documents NORMAL.DOT FilePrint -> FilePrint autoOpen -> autoOpen ToolsMacro FileTemplates ToolsCustomize
The virus infects the documents on all calls that are listed above (opening or printing a file, entering menus File/Templates, Tools/Macro, Tools/Customize) and copies itself to global macros on opening an infected document. The virus drops the SK2.BMP file that contains an image of a death's head.
On the 31th of any month the virus modifies the profile section [Desktop] (the WIN.INI file): [Desktop] Wallpaper=SK2.BMP TileWallPaper=1 SK2=
and increases SK2 value on each infection. It also creates the C:WINDOWSREGSK2.REG and writes the text to there: REGEDIT4 [HKEY_CURRENT_USERControl PanelDesktop] "TileWallpaper"="1" "Wallpaper"="C:\WINDOWS\SK2.BMP"
The virus then appends the following commands to the C:AUTOEXEC.BAT file : @echo off c: cd c:windows copy /y SK2.BMP c:windowssk2.bmp >nul regedit regsk2.reg >nul
On the same date (31th) the virus, depending on the system time, displays the dialog: [!!!PIRATE VIRUS!!!]-- Active! The [PIRATE VIRUS] has pillaged your computer! GO BACK TO MS-WORD??
Macro.Word.Wannabe
Description Macro.Word.Wannabe
This is an encrypted Word macro virus. It contains one macro AutoOpen and replicates itself when documents are opened. Only the files get infection that are listed in the recently used file list, i.e. the virus does not copy itself to global macros area. The virus' actual code is placed in document's variable, and AutoOpen macro gets that code from variables, creates new macro HONOR, inserts code into it, executes and then deletes. The HONOR macro looks for documents in file list and infects them. The virus contains the comments: After FutureNot, AntiFWIN, SlovakDictator and the NB Virii's comes now my contribution against the av-scanners. HERE IS >>>>> HONOR <<<<<
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Search Engine Sdk Face Shape Tips For Bob Hairstyles Russian Women Billiga Fönster Irene Anderssons HÅrvÅrd
|