WereWolf family
Description WereWolf family
These are dangerous parasitic viruses. Depending on the system timer they corrupt the hard drive sectors, "WereWolf.1500" corrupt the random selected byte in the data buffer while writing to a disk (INT 13h, AH=3). "Werewolf.Wave" are polymorphic viruses. "Wave.2845" has a bug and corrupts COM files while infecting them. The viruses contain the text strings: "WereWolf.658,678": Home Sweap Home (C)1994-95 WereWolf "WereWolf.684.a": CLAWS (C)1994-95 WereWolf "WereWolf.684.b,685": FANGS (C)1994-95 WereWolf "WereWolf.1152": SCREAM (C)1996 WereWolf "WereWolf.1168": SCREAM! (C)1995-96 WereWolf "WereWolf.1192,1193,1208": BEAST (C)1995 WereWolf "WereWolf.1367": FULL MOON (C)1995-96 WereWolf "WereWolf.1450": [WULF] 1996 WereWolf "WereWolf.1500.a": WULF 1996 WereWolf "WereWolf.1500.b": [WULF] (c) 1995-1996 WereWolf "Wave.2662,2845": WAVE v0.9 WereWolf Advanced Viral Encryption [HOWL] (c)1996 WereWolf
"WereWolf.658,678,684,685" are nonmemory resident encrypted viruses. They search for .EXE files, then write themselves to the end of the file. The viruses search for *.MS, *.CPS, ANT*.DAT files, and delete them. "WereWolf.1152,1168,1192,1193,1208,1367,1500" are the memory resident viruses, "WereWolf.1152,1367,1500" are encrypted ones. The viruses hook INT 21h and infect the COM and EXE files that are executed or opened. "WereWolf.1192,1193,1208" write themselves to the beginning COM files, and to the end of EXE file, other viruses write themselves to the end of the COM and EXE files. These viruses do not affect the files: "WereWolf.1152": CLEAN AVP TB V SCAN NAV IBM FINDV GUARD FV CHKDS F- "WereWolf.1208": CLEAN AVP TB QB SCAN COMM NAV V FINDV GUARD FV CHKDS F-PR "WereWolf.1367": CLEAN AVP TB V SCAN NAV IBM FINDV GUARD FV CHKDSK F- "WereWolf.1500": CLEAN AVP TB V SCAN NAV IBM FINDV GUARD FV CHKDS F- "Wave.2662,2845": CLEAN AVP TB V SCAN NAV IBM FINDV GUARD FV F- MEM CHKDSK
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Incarnate
Description Macro.Word.Incarnate
This is the Word macro virus. It contains seven macros: AutoExec, AutoExit, FileSave, AutoClose, FileClose, FileSaveAs, ToolsMacro. The virus infects the global macros area (NORMAL.DOT) on closing an infected document (AutoClose, FileClose) and writes itself to documents that are saved (FileSave) or saved with new name (FileSaveAs). The virus contains a bug and while infecting by FileClose copies the same macros FileSaveAs to new macros FileSave and FileSaveAs. As a result the virus discloses itself on saving a document - instead of saving Word displays the FileSaveAs dialog box. While closing a document the virus also appends the its end the text: To end with, I would like to sayall To defy me is to bring upon my wrath... For I am CyberDarkness I am Darkness Incarnate... I will Not be Denied!!! <year> CyberDarkness
On leaving Word the virus writes new Desktop color set to the WIN.INI file.
Macro.Word.India
Description Macro.Word.India
This is a Word macro virus. It contains two macros: AutoOpen, AutoClose. It infects the system macros area on opening an infected document and writes itself to documents on closing. It displays MessageBox with a file name and the MessageBox: India Hi
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|