Macro.Word97.Bench.c
Description Macro.Word97.Bench.c
This virus runs its infection routine when any of its auto-macros. As well as Macro.Word97.Bench.a virus it disables macro viewing menus. It also sets the security level to minimal one. If global macros area is already infected, the virus displays the text "-=([B]MV.F)=-" to the application caption, and the text "-=([Bench] Macro Virus - Strain F)=-" to the status bar. On exiting MS Word the virus searches and infects all documents in current folder. On document saving it looks for anti-viruses NAV and F-PROT on the C: drive and remove their files, displays to the application's caption "-=([B]MV.F])=-" and "-=([B]MV.F)=- / SAiNTS ViRii Dept. - Test Version" to the status bar. On entering the Visual Basic Editor the virus denies the operation and displays balloon with message: [Bench] Macro Virus - F You're not permitted to go there! Now you're gonna pay! Then it saves the active document with the "[Bench]" password, drops on the disk and executes a file infected by the Win95.CIH virus, and then displays another balloon with the message: [B]MV.f I have just attempted to install the CIH virus on your system. I just felt like warning youall
Check other viruses! Be aware! Use Antiviral Software
DenZuk.a
Description DenZuk.a
These are dangerous viruses, 9 sectors long. They infect floppy disks Boot-sectors during access (INT 13h, ah=2,3,4,5). The viruses make no check when place their second parts on a disk, so they can destroy some information at the 40th track. The viruses hook INT 9, 13h. On a warm reboot they display their name "Den Zuk" in big letters (graphics video mode). The viruses replace the label of the infected disk with "Y_C_1_E_R_P". They don't have a destructive function, but they are dangerous because of the possibility to erase information at the 40th track of the infected disk. The viruses contain the text: "Welcome to the C l u b --The HackerS-- Hackin' All The Time", "The HackerS".
DerWolf.2219
Description DerWolf.2219
This is a dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM files (except COMMAND.COM) that are executed. On the 14th of any month, the virus erases sectors on the D: drive, and displays the message: Although two days ago, And I have made a New Vir Still you didn't listen And thought it was nothing. Nothing happens..Now THE WULF, under the shining sun Shall proceed and make you run. HeHeHe - said the poet.
The virus also has a routine that opens the C:COMMAND.COM file, scans it for the "Bad command or file" text and replaces it with the "[DER WOLF GERMANY]" text. This routine never gains control. On the 11th of any month, the virus tries to spread itself through an mIRC channel. The virus creates its dropper file (LUCKY.COM) in the C:MIRC directory, and writes 15 instructions to the SCRIPT.INI mIRB script file that spread the virus to the mIRC channel and display messages. The virus has a bug here, and mIRC is not infected. In case the virus script is correctly written to the file, it actually sends a virus dropper to the channel and sends the following message there: Lucky is back LUCKY B.R.D 1994-99
The virus script also sends another message to the "virus" mIRC channel: Yeah this is a New Production From LUCKY & DER WOLF Thx: Markus K, LEE & ALU, NEUROBASHER, EMPIRE, BoZo and all other fine Vir Writers
It also sends a third message to channels: Dear Christoper Pile thanks idee with your Smeg Patrol Service there is the best that you wantall..Thanks for every all.... Listen to me..where is the Best Anti Vir Scanner...? AVP is the best...F-Prot is the second...VSP are the third... Sophos, Nav, Panda, Ikarus are all bad..has many bugs... Vote AVP for the Best Anti Vir Scanner...
The virus also contains the text strings: THE FIRST ARTAbnormal program termination. Please consult your Virscan Maker
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Darwin Apartments Travelglobe Wage Advance Loans Criacao De Sites Dyner
|