Virus Database


Win.Tentacle.1958

Description Win.Tentacle.1958

It is not a dangerous nonmemory resident parasitic virus. It searches for NewEXE-files in current and C:WINDOWS directories, then writes itself to the end of the file. While infecting the virus creates temporary C:TENTACLE.$$$ file, then modifies and copies blocks of original file to temporary one, then copies temporary file to original one, and then deletes temporary file.
From 0:0am till 0:15am the virus checks the just infected file for the Resources, and searches for Icon resource. If such Resource is there, the virus overwrites it with another icon which is contained in the virus body.
The virus contains the internal text string:
C:TENTACLE.$$$ C:WINDOWS*.EXE

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Fries.a

Description Macro.Word.Fries.a

This Word macro virus contains six macros:
Documents NORMAL.DOT

AutoOpen AutoOpenf
Begin Beginf
AutoClosex AutoClose
AutoOpenx AutoOpen
AutoOpenx AutoNew
Fri13x Fri13

The virus infect the document on closing and the global macros area on opening an infected document. The virus affects the system macros in three seconds after opening, to repform this delay it hooks Timer events. In 32 seconds it also checks the system data and on Friday 13th deletes *.DOC file in the current directory and all files in the root of C: drive. The virus then displays a message in Russian.

Macro.Word.FunFun

Description Macro.Word.FunFun

This Word macro virus contains three macros with random selected names. To access these macros the virus writes their names to the WIN.INI file in section [Intl] in strings Info1, Info2, Info3 (in case of infected system - NORMAL.DOT) or in internal document's variables VirName, VirNameDoc, VirNamePayload (in case of infected document).
To force Word to run its macros the virus assigns them to a random selected key, i.e. the virus takes control only when that key is pressed.
There are several modifications of this virus. They display the MessageBoxes:
"Funfun.a": funfunfun
"Funfun.b": DARKTREMOR
Dark Tremor
Polytest Virus ist Aktiv !!!

"Funfun.b" also drops multipartite virus "Smile".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com