Virus Database


Zohra.4160

Description Zohra.4160

These are not dangerous memory resident parasitic polymorphic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed. They do not infect files, if file name contains one of sub-strings: TB, AV, SC, IV (TBAV, AVP, NAV, SCAN, all). The viruses also remove themselves from memory if WIN.EXE file is executed and "hide" their TSR code when MEM.EXE is executed.
The viruses use quite complex way to get original address of INT 21h handler - they disassemble code of INT 21h handlers up to the original handler in DOS kernel.
On April 14th the viruses display the message:
Zohra will live forever ! Necromancy with her...

They also contain the text:
[Zohra] virus by Wintermute/29A, dedicated to the best Necromancer of the
Forgotten Realms,... I assure you will live forever, my love... ;)

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Waterfall

Description Macro.Word97.Waterfall

This macro-virus contains two macros, "AutoOpen" and "autonomailer," in one module "waterfall," and replicates upon document opening.
The virus changes the Internet Explorer Startup URL with the new address: "http://www.kevinmitnick.com". The virus also looks for "Internet Mail" active, creates a new message to one of the addresses from the existing list, attaches an active (infected) document, and sends this message. The message Subject field contains the word "Hey," and the message body contains the strings:
Hey
Youve just got to read this!
Peace


Upon infection, the virus checks the current date and time, and in December, if the current time is 12 minutes past the hour, the virus appends to the AUTOEXEC.BAT file commands displaying the following message:
I have committed the sin of hacking and am unfit in the eyes of the Lord.
I confess to acts of witchcraft and art, dissidence and voodoo.
But in my Craft for which you condemn me,
I SURF THE BRAINWAVES OF GOD.

Macro.Word97.Wnw

Description Macro.Word97.Wnw

This macro virus contains seven macros and functions in single module "WNW": AutoExec, AutoOpen, FileSaveAs, WNWP, FileTemplates, ToolsMacro, ViewVBCode. The virus infects the global macros area on opening an infected document. Other documents get infected on opening or saving with a new name.
On Saturdays and Sundays, the virus displays the warning messages:
On est Samedi, aujourd'hui
Je ne travaillerai pasall
On est Dimanche, aujourd'hui
Je ne travaillerai pas...

Depending on the number of such messages, the virus performs several destructive operations (see below). The counter of these messages is stored in the WINWORD8.INI file in the [WNW] section in the Total item.
On the 10th message, the virus displays the MessageBox:
Virus WNW
Vous jouez avec le feu...

and deletes the files: C:WINDOWSBUREAU*.LNK and C:WINDOWSMENU DãMARRER*.*
On the 20th message, the virus displays the MessageBox:
Virus WNW
Je vous avais prÊvenu...

and deletes the files:
C:Windows*.ini
C:Autoexec.bat
C:Config.sys
C:Msdos.sys
C:Io.sys

On the 30th message, the virus displays the MessageBox:
Virus WNW
Vous l'aurez voulu!!!!

and formats the C: drive.
On these days, the virus, depending on the system random counter, also either displays the MessageBox:
Virus WNW
Au revoir...

or draws the text in the header line of Word window:
Je ne veux pas travailler ce weekend, donc, je vais vous en empËcher...

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Restposten
Windy City
Virtual Earth
Funny Facebook Likes
Baby Toys

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com