Zerohunter Family
Description Zerohunter Family
These are memory resident harmless stealth parasitic viruses. They infect COM-files which contain the instruction JMP NEAR (E9h) at beginning. The files are infected while they are started. The viruses search the entire files for the zero bytes area and write themselves into this area. So the file length not grown. The viruses use stealth algorithm on Read Handle and FCB functions of INT 21h: the viruses erase their bodies into read buffer after reading. They also restore old 4 bytes at the beginning of the file.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Cebu
Description Macro.Word.Cebu
This is an encrypted macro virus. It contains four macros: AutoExec, AutoOpen, AutoClose, MsRun. It infects the global macro area on AutoOpen and writes itself to documents on AutoOpen and AutoClose. Depending on the system time it replaces the word "Asian" with "Cebu" in current document.
Macro.Word.Ceefour
Description Macro.Word.Ceefour
This is an encrypted Word macro virus. It contains six macros: AutoOpen, FileSave, FileOpen, FileTemplates, ToolsMacro, CFFSA. It infects the global macros area on opening or saving an infected document (AutoOpen, FileSave). It writes itself to the documents that are saved with new name (FileSaveAs). The virus disables the ToolsMacro and FileTemplates menus (stealth). While opening a document the virus checks its name and disables its stealth routine, if the name of document contains the sub-string "TONY". On April 1st the virus erases the files on the C: drive. The virus contains the comments: C-4 By Karl "You are about to have a very bad day." "It looks like C4 in the mothers arm." "We are both professional, This is personal." "And when Alexander saw the bredth of his domain he wept for there were no more worlds to conquer (benefits of a classical education)" quotes from the masters!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|