Virus Database


Macro.Word.Lucifer

Description Macro.Word.Lucifer

This is an encrypted Word macro virus. It contains three macros in documents: Close, Lucifer, AutoOpen. In NORMAL.DOT it contains six macros: AutoOpen, AutoClose, Close, ToolsMacro (stealth), FileTemplates, Lucifer.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are closed (AutoClose).
On 15th of any month the virus copies the C:AUTOEXEC.BAT file to C:AUTOEXEC.LUS and writes to AUTOEXEC.BAT the commands:
@Echo Off"
CDWINDOWS"
Ren *.dll *.lus"
CDWINDOWSSYSTEM"
Ren *.dll *.lus"
CD"
Ren C:AUTOEXEC.LUS C:AOTUEXEC.BAT

It then displays the message and a BMP-picture:
Code Name : Lucifer
Again!!!, from Darkside on Yogyakarta
I'll cross your heart !!
lucifer@Sulthans_Palace.com

On entering the Tools/Macro menu the virus displays the DialogBox:
Message from Lucifer
We knew that the first WordMacro virus was created by McNamara.
But, somebody tried to convince that he was the conceptor!!
His name is: MILKY WAHYUDI WIDJAJA
His speech like bullshit!!
I'm the one of MV creator call him VIRUS CLAIMER, NOT VIRUS MAKER !!
isn't he Phardera ?
Greeting to Everyone
Notice : this is not a virus, just a message don't kill me!!

Check other viruses! Be aware! Use Antiviral Software

Hermetica.975

Description Hermetica.975

This is a dangerous non-memory resident parasitic virus. It searches for EXE files, then writes itself to the end of the file. On Tuesdays, the virus sets the INT 13h handler to the original INT 13h handler's code in the DOS kernel that may halt the computer if some specific disk drive is used. The virus contains the following encrypted text string:
*.EXE ..
HERMETICA VIRUS, by Int13h [Diabolical Kreations!]
Dedicado al EXcelente grupo thrasher argentino.
Ricardo Iorio: escribes muy bien!
# Virus coded in Paraguay #
Girls, Beer, Turbo Assembler and Heavy Metal from here to the eternity!
¡¡¡TASM luego existo!!!! Long life to Borland

Hero.394

Description Hero.394

These are not dangerous memory resident parasitic viruses. They copy themselves to the Interrupt Vectors Table at the address 0000:0200, hook INT 21h, and write themselves to the end of the files that are executed.
"Hero.394" infects only EXE files, "Hero.506" infects both EXE and COM files. As a read/write buffer these viruses use video memory.
While setting Interrupt Vector (INT 21h, AH=25h) with a number greater than 7Fh, "Hero.506" disinfects itself in the memory.
On the 1st of any month these viruses decrypts and display the following messages in Russian: "GLORY TO HEROES!" or "The author of the virus is a cretin" depending on the version of the virus.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Bad
Toyota Gaffeltruck
Cheap Calling Cards
Mobiler - Noika Ericsson Ringsignal
Key West Travel

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com