Virus Database


V.1906

Description V.1906

It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM-files that are accessed. The virus checks the file name, and does not infect the files COMMAND.COM and IBM*.COM.
Depending on the system date and its internal counter the virus erases CMOS and disk sectors. The virus contains the internal text string:
COMMAND.IBM

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Argh

Description Macro.Word97.Argh

The virus code contains fifteen macros in one module "NewMacroses". The virus spreads on creating, opening, closing documents as well as on exiting Microsoft Word. On infecting the system the virus copies original NORMAL.DOT to user template directory with the WINDOT.DLL name, and infected NORMAL.DOT with the WININF.DLL name.
On selecting the ToolsMacro menu the virus checks the number of opened documents. If no documents are opened, the virus displays the message:
Microsoft is protecting your normal.dot from virus infection You can
only add macros to other documents

Otherwise the virus removes itself from normal template and on leaving the ToolsMacro dialog window reinfects it.
While infecting the virus with probability 2% displays the assistants balloon:
Help me
I'm not feeling very vell .. AAARGHH!!!

Macro.Word97.Attention

Description Macro.Word97.Attention

These viruses contains only one macro AutoOpen and replicate themselves on opening documents. They contain the comments:
------------------------------
!!!!Attention!!!!Attention!!!!
------------------------------
This is *NOT* a Wazzu Varient!
This Virus is called AntiFWIN!
FWIN's Heuristics do not Work!
------------------------------

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Simple Machines Forum
недвижимость в Москве
Ole Irgens
Call Europe
Business Sites Reviews

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com