VirDem.1336.c
Description VirDem.1336.c
This is a nonmemory resident parasitic virus. It writes itself to the beginning of COM files of the current or A: drives. The virus contains the text: *.com * Virus Infestation ACTIVE KILLER SOMETHING WONDERFUL HAS HAPPENED !!!
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Psd
Description Macro.Word97.Psd
This is a Word97 macro-virus. It has stealth and polymorphic abilities. In infected documents, the virus has one auto-macro Document_Open and installs itself into the global macros area upon opening an infected document. While installing, the virus copies its macro with the Document_Close name and infects other documents on closing. The virus also creates, in the global macros, its stealth-macro ViewVBCode, which terminates Word on any attempt to view macro code. The virus also disables Word anti-virus protection. On infecting, it randomly renames virus variables and subroutine names (polymorphism). The virus checks the system date and time, and in case the current day number is equal to the current minutes, the virus runs its trigger routine: it displays several figures of random size and random color. The virus versions contain the comments: "Psd.a":
W97M/PSD allporn star dreams? [(c)1998 ALT-F11 code hack] VAMP v1.0 [thanks Vic!]
"Psd.b":
W97M/PSD.II ...logically delicious! [(c)1998 ALT-F11 code hack] VAMP v1.0 [thanks Vic!]
Macro.Word97.Psd
Description Macro.Word97.Psd
This is the first known macro virus infecting Office2000 Word documents. It was discovered in December 1998. The virus uses the same methods of infection as Word/Word97 viruses use. The only difference is that the virus is converted into new Word document format and use few Office2000 specific instructions. The virus affects the global macro area when an infected document is opened. The virus spreads itself into other documents when they are closed. The virus disabled Word anti-virus protection by two ways: by using Basic instruction and by writing to corresponding filed in the system registry. This is the stealth virus. While infecting the system it creates a stealth-macro that disables virus code viewing and exits Word without saving all changes. The virus also uses polymorphic routine that randomly renames virus variables and subroutines names. The virus code is places in one module in the Document_Open macro in infected documents. When an infected document is opened, the auto-macro Document_Open is executed by Word, the virus code takes control and installs the virus into the system. During that the virus copies its code to the global macros area with the Document_Close name and create additional stealth-macro ViewVBCode. The virus checks the system date and time and in case current day number is equal to current minutes, the virus runs its trigger routine: it displays several figures of random size and random color. The virus code contains the comment: W97M/PSD by ALT-F11, VAMP Poly by VicodinES Converted to W2000/PSD by VicodinES
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|