Win.Pin
Description Win.Pin
This is a very dangerous memory resident parasitic Win16 virus. It infects Win16 NE EXE files (NewExe) and DOS EXE files. It is polymorphic in both Win16 NE and DOS EXE files. While infecting NE files, the virus creates a new section at the end of a file, encrypts and writes its code there, then modifies the necessary NE header fields. While infecting DOS EXE files, the virus writes its code to the end of the file, and modifies the DOS EXE header. The virus infection routine is buggy, and in some cases corrupts NE EXE files. While infecting a file, the virus also checks the system date and time, and starting from the 16th of any month, depending on the system seconds counter, tries to erase data on the A: drive. To stay "memory resident," the virus drops the VxD module that is the main part of its code. This module is dropped to the Windows system directory with the WINP16.386 name, and the virus then registers it in the SYSTEM.INI file in the [386Enh] section to force Windows to load a virus' VxD module upon each booting. The modified entry in SYSTEM.INI file appears as follows: [386Enh] device=winp16.386
When Windows loads this VxD module, the virus memory installation routine takes control. It hooks the INT 21h chain (DOS functions), intercepts file execution and upon any file start, searches for EXE files in the current directory and infects them. The virus checks the file names and does not infect the following files: APV.EXE (mistyped AVP.EXE?), SCAN*.EXE, TBAV*.EXE, DRWE*.EXE, AIDS*.EXE, KRNL*.EXE, WIN3*.EXE, and VICT*.EXE. The virus' "resident" mode works under both Win16 and Win9x, so the virus is able to infect not only Win16 system, but Win9x also, and affect NE EXE files in Win9x directories.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Kompu
Description Macro.Word.Kompu
This macro virus contains two macros: AutoOpen and AutoClose. It infects global macros area on AutoOpen and writes itself to documents on AutoClose. On 6th and 8th of any month it display the InputBox with the message: Tahan kommi! Mul on paha tuju!
and waits for "komm" string. It then prints the string to the status line: Nämm-Nämm-Nämm-Nämm-Amps-Amps-Klõmps-Kröök!
The virus also contains the commented string: Makroviirus Kompu
Macro.Word.Kop
Description Macro.Word.Kop
The virus contains three macros: Document: NORMAL.DOT: --------- ----------- AutoOpen AutoOpenDot kopieren kopieren testmacro DateiSpeichernUnter
The virus spreads on opening documents or saving them with new names. While infecting the virus depending on the system random counter displays the message: Dokument mit den Makros schon infiziert !
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Carb Blocker Hemorrhoids Treatment Dzwonki Mp3 Concrete5 Drive Hand Right Truck
|