Virus Database


Joke.Win32.DesktopPuzzle

Description Joke.Win32.DesktopPuzzle

text written by Alexey Podrezov, Data Fellows
This is a Trojan written in Delphi. The original file name is SLIDESCR.EXE. Upon being executed under Windows 95, it blocks the task manager and opens a messagebox with the following text:
Slider 1.0
Oops, looks like somebody doesn't like you very much !
You have to finish this sliding tile puzzle before you
can continue whatever it is you're doing !
Use the cursor keys to move the pieces (black piece is
the empty one).

After 'OK' is pressed, the Trojan splits the Windows desktop into several parts, mixes them and waits for the user to restore the original desktop by solving the sliding tile puzzle. It also swaps functions of the cursor keys: 'Up' becomes 'Down', 'Left' becomes 'Right' and this makes solving the puzzle more difficult. There's no way to continue working with other Windows applications until you complete the puzzle.
Under Windows NT, the task manager is not blocked by the Trojan, and the puzzle task could be killed.
If the Trojan is executed from a DOS session (full screen mode), the desktop data is not acquired correctly and the puzzle parts are blank. This happens because the desktop image is acquired by the Trojan before Windows switches from the DOS screen to its desktop.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Four

Description Macro.Word.Four

This virus contains one macros in document AutoOpen, and four macros in NORMAL.DOT: AutoClose, FileTemplates, NoMercy, ToolsMacro.
It infects the global macro area on opening an infected document (AutoOpen), and infects documents that are closed (AutoClose). In some cases it sets on documents a password consisting the current time.
The virus creates the AutoClose, FileTemplates, ToolsMacro macros in NORMAL.DOT by entering lines of text (line by line). At the beginning of each macro there is the comment:
/----------------------------------------------------------| Virus name: 4in1 (Four in One) |
| Origin : Indonesia, Yogyakarta |
| Author : Foxz [NoMercy] July 97 |
| URL&eMail : You Know it !! :) |
----------------------------------------------------------/

Macro.Word.Foxz

Description Macro.Word.Foxz

This virus contains four macros in documents and eight in NORMAL.DOT:
Documents NORMAL.DOT
AutoClose AutoClose
AutoOpen AutoOpen
Action Action
Foxz ToolsMacro, FileTemplates, ToolsMacro, ViewToolbars,
HelpWordPerfectHelp

The virus infects the global macros area on opening an infected document (AutoOpen). It infects documents that are closed (AutoClose).
It modifies the Windows 95 register information. It contains the comments:
/---------------------------------------------------------------| You know Phardera?,he is X-SLAM member who kick out from SLAM |
| and USE my Name [foxz] for spaming SLAM VIRUS TEAM. |
| His real Name is Anton Reinhard Pardede!, he is a "Mikrodata |
| Crewz"(Computer Magazine in my country), as long as I know, he|
| work on Virus Division on that Magazine. |
| By this virus I want everybody know that "the fucking lamer |
| who Spaming SLAM" is not Me [foxz] |
| Regards, |
| Foxz/NoMercyVirusTeam Leader |
---------------------------------------------------------------/
------------------------------------------------------------
Code Name : WM.FoxZ Gn.III also know as "WinFake"
Author : Foxz [NoMercy]
Origin : Yogyakarta
Dedicated : for the fucking lamer "Phardera" who spaming SLAM
VirusTeam with my Name !
Greetz : Cicatrix, SLAM Crewz and NoMercyVirusTeam Crewz
Group : NoMercyVirusTeam
Effect : Change Windows 9x Register !
Thanks to : CJC, Lucifer, Gurita, CrazyMan, Aurodreph and You
who was see this Text !, see you in my Next virus :)
------------------------------------------------------------
October 30 '97
THANKS FOR SLAMVIRUS TEAM FOR THIS INFO !!! (SLAM mag)

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Holmium Laser Prostatectomy
Free Breast Pump
Latino Phone Card
Baldness Symptoms
Moto 4 Usadas

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com