Virus Database


Macro.Word97.Bench.c

Description Macro.Word97.Bench.c

This virus runs its infection routine when any of its auto-macros. As well as Macro.Word97.Bench.a virus it disables macro viewing menus. It also sets the security level to minimal one.
If global macros area is already infected, the virus displays the text "-=([B]MV.F)=-" to the application caption, and the text "-=([Bench] Macro Virus - Strain F)=-" to the status bar.
On exiting MS Word the virus searches and infects all documents in current folder. On document saving it looks for anti-viruses NAV and F-PROT on the C: drive and remove their files, displays to the application's caption "-=([B]MV.F])=-" and "-=([B]MV.F)=- / SAiNTS ViRii Dept. - Test Version" to the status bar.
On entering the Visual Basic Editor the virus denies the operation and displays balloon with message:
[Bench] Macro Virus - F
You're not permitted to go there! Now you're gonna pay!
Then it saves the active document with the "[Bench]" password, drops on the disk and executes a file infected by the Win95.CIH virus, and then displays another balloon with the message:
[B]MV.f
I have just attempted to install the CIH virus on your system.
I just felt like warning youall

Check other viruses! Be aware! Use Antiviral Software

DenZuk.a

Description DenZuk.a

These are dangerous viruses, 9 sectors long. They infect floppy disks Boot-sectors during access (INT 13h, ah=2,3,4,5). The viruses make no check when place their second parts on a disk, so they can destroy some information at the 40th track.
The viruses hook INT 9, 13h. On a warm reboot they display their name "Den Zuk" in big letters (graphics video mode). The viruses replace the label of the infected disk with "Y_C_1_E_R_P". They don't have a destructive function, but they are dangerous because of the possibility to erase information at the 40th track of the infected disk. The viruses contain the text: "Welcome to the C l u b --The HackerS-- Hackin' All The Time", "The HackerS".

DerWolf.2219

Description DerWolf.2219

This is a dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM files (except COMMAND.COM) that are executed.
On the 14th of any month, the virus erases sectors on the D: drive, and displays the message:
Although two days ago,
And I have made a New Vir
Still you didn't listen
And thought it was nothing.
Nothing happens..Now THE WULF, under the shining sun
Shall proceed and make you run.
HeHeHe - said the poet.

The virus also has a routine that opens the C:COMMAND.COM file, scans it for the "Bad command or file" text and replaces it with the "[DER WOLF GERMANY]" text. This routine never gains control.
On the 11th of any month, the virus tries to spread itself through an mIRC channel. The virus creates its dropper file (LUCKY.COM) in the C:MIRC directory, and writes 15 instructions to the SCRIPT.INI mIRB script file that spread the virus to the mIRC channel and display messages. The virus has a bug here, and mIRC is not infected. In case the virus script is correctly written to the file, it actually sends a virus dropper to the channel and sends the following message there:
Lucky is back
LUCKY B.R.D 1994-99

The virus script also sends another message to the "virus" mIRC channel:
Yeah this is a New Production
From LUCKY & DER WOLF
Thx: Markus K, LEE & ALU, NEUROBASHER, EMPIRE, BoZo
and all other fine Vir Writers

It also sends a third message to channels:
Dear Christoper Pile thanks idee with your Smeg Patrol Service
there is the best that you wantall..Thanks for every all....
Listen to me..where is the Best Anti Vir Scanner...?
AVP is the best...F-Prot is the second...VSP are the third...
Sophos, Nav, Panda, Ikarus are all bad..has many bugs...
Vote AVP for the Best Anti Vir Scanner...

The virus also contains the text strings:
THE FIRST ARTAbnormal
program termination.
Please consult your Virscan Maker

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Darwin Apartments
Travelglobe
Wage Advance Loans
Criacao De Sites
Dyner

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com