Bomzh.3809
Description Bomzh.3809
It is a very dangerous memory resident encrypted parasitic stealth virus. It hooks 17h, 21h and writes itself to the end of EXE files that are executed, renamed or closed. While opening an infected file the virus disinfects it. When a file compressing utility is run, the virus disables its stealth routine. The list of these utilities looks as follows: RAR.EXE PKZIP.EXE ARJ.EXE ICE.EXE HA.EXE
The virus deletes the files: VSWAP.WL? ILLURIA.MAP *.WAD
While printing a file the virus includes a word in Russian into the data . The virus also contains text strings in Russian.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Lemon
Description Macro.Word.Lemon
This is an encrypted macro virus. It contains two macros that have different names in documents and NORMAL.DOT: Documents NORMAL.DOT AutoOpen AutoOpen Lemon Melon
Depending on the system date and random counter, the virus displays the MessageBox: !!LEMON!!!!MELON!! !!MELON!!!!LEMON!!
The Lemon (Melon) macros contains only comments: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!MELONLEMONMELONLEMONMELONLEMONMELONLEMONMELONLEMONMELON!! !!MELONLEMONMELONLEMONMELONLEMONMELONLEMONMELONLEMONMELON!! . . . !!MELONLEMONMELONLEMONMELONLEMONMELONLEMONMELONLEMONMELON!! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Macro.Word.Ler
Description Macro.Word.Ler
This is an encrypted macro virus. It contains two macros in documents: AutoOpen, hitler; and four macros in NORMAL.DOT: AutoExec, AutoOpen, Autoeopen, hitler. The virus replicates on opening a document. On April 15 the virus displays the MessageBox: Hitler India Is Great
The virus creates random named directories on the C: drive and creates the HITLER.TXT file in there. These files contain the text: MSWORD is infected by a new virus HITLER Date = <current date> Time = <current time>
|