Virus Database


Bljec Family

Description Bljec Family

These are dangerous, non-memory resident parasitic viruses, which search for COM files of the current directory, and write themselves to their beginnings.
For several viruses of this family, the start code of the virus is the text string "Digital F/X Virus - Created on 2/5/92 by Phoney Phreak" or "XYZ Virus 1.0 - Buddy and Chloe 5/27/89". This string is executed as a code, but this code contains i286/386 instructions.
These viruses also contain the text "*?.com". In September, "Bljec.300" and "307" erase the disk sectors and display: "Sad virus - 24/8/91".

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Cipher

Description Macro.Word97.Cipher
The virus contains seven macros in one module "Cipher": AutoNew, AutoOpen, AutoClose, cphrdoc, hideb, WindowsDirectory, and spreadIB. It replicates upon document creating, opening and closing (AutoNew, AutoOpen, AutoClose).
Depending on the system random counter, the virus sets the password "MisterCipher" on a current document or displays the following MessageBox:
Time Signal
I say to you that it's
It's too late. You must finish to work before next time!!!
Bye,Bye

On Friday the 17th, on the 31st of the month (excluding those with less days), and on the 25th of April, the virus drops a file infected by the the "Italian.578" DOS virus.
Upon closing documents on the 25th of April, or depending on the system random counter, the virus encrypts the text in the current document and displays the following MessageBox:
I want to say to you: L'Italia una ed indivisibile e c' la morte per
chi la divide!!!!!all..
Are you angry because you lost your document?+; Kill Bossi, the fault is his
Mister Cipher reigning

Macro.Word97.Clara

Description Macro.Word97.Clara

It is a polymorphic and stealth macro virus. It contains 8 macros in one module called "Clara": GetRandom, Effect, AutoOpen, AutoClose, ToolsMacro, ViewVBCode, ToolsCustomize, FileTemplates.
It infects the global macros area on opening an infected document (AutoOpen) and infects other documents on opening or saving (AutoOpen, AutoClose).
The virus turns off the Word virus protection (the VirusProtection option). It also disables the Tools/Macro, File/Templates, View/VBCode, Tools/Customize menus (stealth). The virus' polymorphic engine inserts random comments of random length into the virus code while infecting .
On the 1st of any month the virus displays a "Balloon" and MessageBox:
WM97.Clara
Author: Foxz/NoMercyVirusTeam
WM97.Clara
Thanks friends

The virus also contains the comments:
Thanks to Pyro
Thanks Chasm

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com