Virus Database


Win32.HLLO.Harrier.18210

Description Win32.HLLO.Harrier.18210

It is a very dangerous nonmemory resident parasitic Windows32 virus written in Borland C++. When an infected program is run, it searches for EXE files in the Windows directory and replaces (overwrites) then with its code. The infected files are not recoverable and should be deleted.
The virus also changes the WIN.INI file to force Windows to load and run infected file on each restart - the new instruction "load=" is written to the [windows] section there, and it points to the infected file. To prevent duplicate run the virus also adds the section [Harrier] to the end of WIN.INI file and writes the string to there: "Infected=Yes". When run the virus checks this section, and skips infection routine if it is set.
The virus then goes to endless loop where it checks the system time and manifests itself with stupid messages that have the same header:
"95&98-th Harrier from DarkLand"

The message body depends on the system time. If minutes=13 the virus displays:
Oops, World, it is Me!
Can You image it? I am the Win32 platform based virus!
Hey,Daniloff! Will You porte Your DrWeb at this platform?
Hmm, Guy, what You think about Watom C++ ?
Greetings goes to Gill Bates and to her Mircosoft Windoze 95 & 98 sucks,
and to rest lame pat of world.
Ugly Lamers MUST DIE!
Who am I? I am the "95&98-th Harrier from DarkLand" !!!
I come from dark, I invade Your PC and now I will invade Your mindall
ZeMacroKiller98
v3.01 Release(3) from 16-Apr-1999y

If [condition] the messages are:
hour=12: System malfunction!
minutes=20: VXDs rings overcrossed!
minutes=30: VCPU mode thunking error!
Attention! Bugs inside computer, use SoftIce.
minutes=45: CPU overclocked, cooler device emergency!
hour=15: Help subsystem is damaged!

The virus then (in the same loop) looks for "System Properties", "Control Panel", "Propriétés Système" and "Panneau de configuration" windows and changes their header line with "95&98-th Harrier from DarkLand". The virus also writes the text to the window:
Manufactured and supported by:
HARRIER FROM DARKLAND

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Pox

Description Macro.Word.Pox

This is an encrypted Word macro virus. It contains only one macro AutoOpen. It replicates on opening a document. The virus display the MessageBox:
POXARAMA
May a PoX be upon your Clan

Macro.Word.Printer

Description Macro.Word.Printer

This is an encrypted Word macro virus. It contains 5 macros in documents and 10 in NORMAL.DOT:
Documents NORMAL.DOT
LPT1 FileOpen, LPT1
LPT2 FilePrint, LPT2
Canon FileSaveAs, Canon
Epson Epson, FileTemplates, ToolsMacro
AutoOpen AutoOpen

The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are saved with new name (FileSaveAs).
On entering the Tools/Macro the virus displays the MessageBox:
Weeee Weeee

On printing documents the virus writes to the status line the message and draws it to right:
Know what Dwira Oktorianto is, before it is too late

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Lundqvists RÖrledningsfirma
Euro Hisservice
SvartnÄs Billackering
GÖteborgs BegravningstjÄnst Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com