Yelet.2098
Description Yelet.2098
It is a harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. While installing memory resident the virus also infects the C:WINDOWSWIN.COM file, if it exists. The virus checks the file names and does not infect the files: SC*.*, AV*.*, TB*.*, F-*.*, FI*.*. The virus does not manifest itself in any way. It contains the text string: YeLeT 0.9, just another bug in your Micro$oft Systemall
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Spooky
Description Macro.Word97.Spooky
This macro-virus contains one macro Document_Close, and spreads on document closing. While infecting the global macros area (NORMAL.DOT), the virus appends to the end of its code the additional information about the current user: system date and time, UserName and UserAddress. On the1st of each month, the virus saves this information to the HSF.SYS file (where "number" is a randomly generated number), then sends this file by FTP client under "user anonymous" to the incoming directory on the ftp server with the address 209.201.88.110. It seems that this address can be accessed by the virus writer that will get information about the speed of virus spreading. The virus code contains the ID-strings: <- this is a marker! Logfile -->
Spooky.d (Caligula) On the 1st run on a computer, the virus searches on the disk for a SECRING.SKR file containing PGP private keys. Then it sends this file by FTP client under "user anonymous" to the incoming directory on the ftp server with the address 209.201.88.110. On the 1st of each month, the virus displays the message: WM97/Caligula (c) Opic [CodeBreakers 1998] No cia, No nsa, No satellite, Could map our veins.
The virus also changes Summary Info of documents: Author Opic Title WM97/Caligula Infection Subject A Study In Espionage Enabled Viruses. Comments The Best Security Is Knowing The Other Guy Hasn't Got Any. Keywords Caligula, Opic, CodeBreakers
Macro.Word97.Steroid
Description Macro.Word97.Steroid
This virus contains eleven macros in one module "Inject". It infects system and documents on run any of this macros and also changes volume label on drive C: to "Testicle". On exiting Microsoft Word it infects all documents in the current directory. On entering the "Help/Aboutall" menu it displays two messages: VMPCK v2.0 Beta / SR-1 Compatable Can I have a bottle of warm Diet Mountain Dew?
W97M/Steroid.Poppy Shout Out! ...Slage Hammer, Spanska and the entire _Kim_Liberation_Army_
On opening the Visual Basic Editor the virus infects all documents in the current directory and displays Microsoft Word dialog widows in random order. The code of virus contains the comments: The VicodinES Macro.Poppy Construction Kit v2.0 Beta Code Written by VicodinES-VV/---------------------- Poppy ID : 75637833-270----/---Compatable with SR-1 Steroid.Poppy.II-----------/--Never Begins Tomorrow
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
ALTECO AB TIDNINGSHUSET KVÄLLSSTUNDEN AB KÅLLEKÄRR BILCENTRUM AB Image Uploading Skyveporter
|