x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

Prilissa

 
Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Prilissa
Technical name:W97M/Prilissa
Threat level:Low
Alias:Melissa; Melissa.W; W97M/Melissa.W; W97M/Melissa.AG; W97M/Pri.Q; W97M/Antisocial.G; W97M/Pri.Q-mm
Type:Virus
Effects:   It carries out damaging actions on the affected computer. It infects Word's global template and documents. It does not spread automatically using its own means.
Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

Detection updated on:June 11, 2001
StatisticsNo
Family:MELISSA

Brief Description 

    

 This is a macro virus, belonging to the W97M family of viruses, which infects Microsoft Word 97 documents and the NORMAL.DOT global template that this application uses. This virus triggers its payload on 25 December of any year. When this action takes place the virus will proceed to format the hard disk the next time the system is started. This action will only take place on Windows 95/98 systems.

Visible Symptoms 

    

This virus triggers its payload on 25 December (it will format that hard disk on that date) and it makes some changes to the AUTOEXEC.BAT (batch file that is run every time the system is started). The virus will insert some instructions in this file, which will enable the virus to format the hard disk (all the information will be irretrievably lost) as well as to display messages in MS-DOS mode.

After having modified the AUTOEXEC.BAT file, the virus will display the following dialog box:


Upon pressing the Accept button the virus will display the image shown below in the current document as long as the system date stamp is 25 December.



The virus will remain active on the computer until users manage to remove it from the system by means of an antivirus program. The virus inserts the following commands lines in the AUTOEXEC.BAT file:

"@echo off" ;
"@echo Vine...Vide...Vice...Moslem Power Never End..."
"@echo Your Computer Have Just Been Terminated By -= CyberNET =- Virus !!!"
"ctty nul"
"format c: /autotest /q /u"


The virus uses the first three lines to display the dialog box mentioned before. The only difference is that the message will be displayed in MS-DOS mode. The last line is used to format the hard disk (C:\). Once this action has been carried out all the information will be lost. It is important to note that this action will not be carried out on systems running under Windows NT. It will only work under Windows 95/98.