Virus Database


Win32.Levi

Description Win32.Levi

It is not a dangerous nonmemory resident encrypted parasitic Windows32 virus. It searches for PE EXE files (Windows executable files) in the current directory, then writes itself to the end of the file. While infecting the virus writes itself to the end of last file section, increases its size and modifies program's startup address.
Starting from the 30th generation the virus displays the message window, they are different in different virus versions:
"Levi.3040":
Win32.Wildfire (c) 1998 Magnic
I am/I can - The Wildfire virus.
-d e c o d e-
idwhereamif73hrjddhffidosyeudifr
ghfeugenekasperskydjfkdjisfatued
938rudandmydickisgrowingehdjfggk
"Levi.3236":
Hey stupid !
Win32.Leviathan (c) 1999 by Benny
This is gonna be your nightmareall
30th generation of Leviathan is here... beware of me !
Threads are stripped, ship is sinkin'...
Greetz: Darkman/29A
Super/29A
Billy Belcebu/DDT
and all other 29Aers...
Special greet:
Arthur Rimbaud
New milenium is knockin on the door...
New generation of viruses is here, nothing promised, no regret.

While infecting the virus runs seven threads from its main procedure. Each thread performs only limited set of actions and passes control to next thread: one thread checks system conditions and enables second thread that searches for files, then third thread checks the file structure, then next thread writes the virus code to the file, e.t.c.
To get access to Windows Kernel32 functions the virus scans victim files for GetModuleHandleA and GetModuleHandleW imported functions. In case no these exports found, the virus does not affect the file. Otherwise is stores functions' addresses and uses them in its installation routine.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Makrone

Description Macro.Word.Makrone

This is a primitive German-specific Word macro virus. It contains two macros:
Documents NORMAL.DOT
AutoOpen AutoOpen
Makrone DateiSpeichern

It infected the system on opening an infected document, and files on saving them. The virus does not manifest itself in any way.

Macro.Word.Malaria

Description Macro.Word.Malaria

This is an encrypted Chinese Word macro virus. It contains 8 macros: AutoExec, AutoOpen, Outbreak, Organizer, ToolsMacro, ZlockMacro, FileTemplates, ToolsCustomize. The virus also creates temporary macros "Malaria".
On 12th of any month the virus displays the DialogBox:
About Plasmodium . . . .
You've infected by MALARIA parasite-----
The most deadly parasite in the world !!!

Depending on the system random counter the virus moves all files from random selected directory on C: drive to FILE directory and renames them to names <four digits>.CHK.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



L T R Bil & BilvÅrd Aktiebolag
Karlstad's DÄcktjÄnst
Ängeland
Dufvenmark, Eva Kristina
Tps BiltvÄtt Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com