Virus Database


Xak.3132

Description Xak.3132

It is a dangerous memory resident parasitic virus. It hooks INT 1Ch, 21h and writes itself to the end of COM files that are executed. While executing a file the virus also checks it for the code of several anti-virus immunizers, and does not infect such files, or deletes them. The virus contains the text strings:
+-------------------------------------------------------------------+
¦ This code, called Xak version 0012, is the ???? generation from ¦
¦ the original code of the same version number and was created by a ¦
¦ predecessor code on the ?? day of the month of ?? of the year ¦
¦ ???? at ?? hours, ?? minutes, and ?? seconds. ¦
+-------------------------------------------------------------------+

where "??" are the digits, these positions are filled according to the virus generation, the date and time of infection. The virus also contains the strings:
<ILove&wantUnow>
SYSTEM+Z
ßon 1.3 Copyr Nsn 1.3
Central Point An

Check other viruses! Be aware! Use Antiviral Software

Macro.Excel.Disaster

Description Macro.Excel.Disaster

This virus infects Excel sheets (XLS files). It contains five macros in one module "Disaster": Auto_Open, Infect, Unvisible, Butterfly, Auto_Close.
While loading an infected document Excel executes auto macros auto_open, and the virus takes control. The virus auto_open macro contains just one command, which defines the Unvisible macro as a handler of OnSheetActivate routine. As a result the virus hooks the sheet activate routine, and while opening a sheet the virus (the Unvisible macro) takes control.
When the Unvisible macro takes control, it executes the Infect macro which infects all active Workbooks. While closing an infected document Excel executes the Auto_Close macro. This macro erases all sheets except having the "Sheet" at the beginning of the name. This macro then saves infected sheet to the Excel Startup directory with the BOOK1.XLS name.
On Monday that falls on 1-5th day or month, or on Friday starting from 25th of month the virus on closing files executes the Butterfly macro that creates new sheet named "A" and deletes all other.

Macro.Excel.Don

Description Macro.Excel.Don

This is an Excel macro virus. It contains one module DON that contains one function AutoOpen. The infection routine present in the virus code consists of 49 encrypted text strings. In case of need (on infection) the virus decrypts them, saves to the DON.TXT file, then copies this file to the macros area with name "Replicate" and executes it. After executing (i.e. after infecting a file or system) the virus deletes the "Replicate" module.
If an infected file is opened from Excel startup directory (i.e. the system is already infected) it sets its AutoOpen function on sheets deactivating (OnSheetDeactivate function) and infects the Workbooks on changing active sheet. Otherwise the virus creates an infected file with name <number>.DON in Excel startup directory, i.e. infects the system.
The virus can be easily detected by the presence of a <number.DON> file in the XLSTART directory. The virus also creates the DON2.TXT file and writes to there the name of active Workbook.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Time Management Tips
Ibs
Dessous
Ammepude

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com