Win.Tentacle.1958
Description Win.Tentacle.1958
It is not a dangerous nonmemory resident parasitic virus. It searches for NewEXE-files in current and C:WINDOWS directories, then writes itself to the end of the file. While infecting the virus creates temporary C:TENTACLE.$$$ file, then modifies and copies blocks of original file to temporary one, then copies temporary file to original one, and then deletes temporary file. From 0:0am till 0:15am the virus checks the just infected file for the Resources, and searches for Icon resource. If such Resource is there, the virus overwrites it with another icon which is contained in the virus body. The virus contains the internal text string: C:TENTACLE.$$$ C:WINDOWS*.EXE
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Fries.a
Description Macro.Word.Fries.a
This Word macro virus contains six macros: Documents NORMAL.DOT
AutoOpen AutoOpenf Begin Beginf AutoClosex AutoClose AutoOpenx AutoOpen AutoOpenx AutoNew Fri13x Fri13
The virus infect the document on closing and the global macros area on opening an infected document. The virus affects the system macros in three seconds after opening, to repform this delay it hooks Timer events. In 32 seconds it also checks the system data and on Friday 13th deletes *.DOC file in the current directory and all files in the root of C: drive. The virus then displays a message in Russian.
Macro.Word.FunFun
Description Macro.Word.FunFun
This Word macro virus contains three macros with random selected names. To access these macros the virus writes their names to the WIN.INI file in section [Intl] in strings Info1, Info2, Info3 (in case of infected system - NORMAL.DOT) or in internal document's variables VirName, VirNameDoc, VirNamePayload (in case of infected document). To force Word to run its macros the virus assigns them to a random selected key, i.e. the virus takes control only when that key is pressed. There are several modifications of this virus. They display the MessageBoxes: "Funfun.a": funfunfun "Funfun.b": DARKTREMOR Dark Tremor Polytest Virus ist Aktiv !!!
"Funfun.b" also drops multipartite virus "Smile".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|