Verwolf Family
Description Verwolf Family
These are not dangerous(?) nonmemory resident parasitic polymorphic viruses. They search for EXE files and write themselves into the middle or to the end of the file. While infecting a file they trace and hook INT 13h and install themselves as device driver (I see not for what reason). Sometimes they leave the memory resident program that hooks INT 21h and triggers while opening some files. The viruses contain the text strings: "Verwolf.3308": My name is VERWOLF ! "Verwolf.3502": My name is VERWOLF1 !
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Skammy
Description Macro.Word.Skammy
This virus contains two identical macros: AutoOpen, Skammy. It replicates itself on opening a document. It contains the commented string: SkamWerks Labs Presents the Generic Concept Created by Skam
Macro.Word.Slow
Description Macro.Word.Slow
This is a harmless polymorphic macro virus. It contains only one macro AutoClose and infects the global macros area and documents on Close call. On each infection the virus' polymorphic engine renames internal virus variables to other random selected names with random selected lengths. As a result there are no constant search strings to detect the virus.
|