Virus Database


YanShort.1961.a

Description YanShort.1961.a

This is a non memory-resident parasitic virus. It searches for EXE files in all directories of the current disk, then writes itself to the end of the file. It contains the string "motherfucker," and uses this string to separate the infected and uninfected files.
This virus runs itself by playing the "Yankee Doodle Dandy" tune before returning to the host program.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Lafs

Description Macro.Word97.Lafs

The virus code contains six macros in one module: AutoOpen, AutoClose, ToolMacro, ViewVBCode, FileTemplates, exec. In templates module name is "lafs", in documents - "dd".
The virus replicates on opening and closing documents. While infecting it disables VirusProtection option. On closing documents the virus displays its own FileSaveAs dialog.
On June'14 the virus displays the assistant balloon:
Happy Birthday
Selamat Ulang Tahun sayang semoga panjang umur dan tuhan menyertaimu.

On November'6 inserts into documents the lines:
Love at First Sight
Patas AC 19
6 November 1997

Macro.Word97.Layla

Description Macro.Word97.Layla

It is a dangerous stealth macro virus. It contains ten macros in one module "TJ": AutoOpen, LAYLA, AutoExec, AutoExit, AutoClose, FileClose, ToolsMacro, ToolsCustomize, FileTemplates, ViewVBCode.
It infects the global macros area on opening an infected document (AutoOpen) and infects other documents on opening and closing (AutoOpen, AutoClose).
The virus turns off the Word virus protection (the VirusProtection option) and deletes "NewMacros" module that contains user defined macros. It also disables the Tools/Macro, Tools/Customize menus (stealth). On opening the Visual Basic editor the virus closes Word without saving changes in documents.
On 27th or 29th of any month on closing documents the virus runs its payload procedure. On opening Word at these days the virus displays in the status bar the text:
Excellent dayall for me... :)

The payload procedure is also run on opening document at 27th or 29th second of minute. This procedure replaces all digits by text "Tj" or "Layla" depends on day of month. Also it replaces every 9th character in document by Aries sign.
On exiting Word the virus searches in subdirectories of "c:", "c:program files", "d:" and "e:" for files by wildcard "*d*r*w*.*" (looking for DrWeb anti-virus) and deletes all files in directories where suitable files were found. Then it searches for "*a*v*p*.*" and deletes "*.avc" and "*.key" files (AVP anti-virus databases and key file). As a result of quite scrappy wildcards the virus can delete many other files.
The virus also changes following information:
UserName = ""
UserInitials = "TJ_LAYLA"
UserAddress = ""

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



SÖRBY JÄRN & METALL AB
SEKÅ LASTFORDON AB
ALFA LAVAL EUROPE AB
THORDAB AB
New Multimedia Technologies

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com