Virus Database


Reboot.715

Description Reboot.715

This is a dangerous nonmemory resident parasitic virus. It searches for .COM files of the subdirectory tree, then it writes itself to the end of the file and writes to the beginning of the file the Jmp-Virus commands (MOV AX,FFF0h; JMP Loc_Virus). Depending on the system time the virus reboots the computer.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Lucifer

Description Macro.Word.Lucifer

This is an encrypted Word macro virus. It contains three macros in documents: Close, Lucifer, AutoOpen. In NORMAL.DOT it contains six macros: AutoOpen, AutoClose, Close, ToolsMacro (stealth), FileTemplates, Lucifer.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are closed (AutoClose).
On 15th of any month the virus copies the C:AUTOEXEC.BAT file to C:AUTOEXEC.LUS and writes to AUTOEXEC.BAT the commands:
@Echo Off"
CDWINDOWS"
Ren *.dll *.lus"
CDWINDOWSSYSTEM"
Ren *.dll *.lus"
CD"
Ren C:AUTOEXEC.LUS C:AOTUEXEC.BAT

It then displays the message and a BMP-picture:
Code Name : Lucifer
Again!!!, from Darkside on Yogyakarta
I'll cross your heart !!
lucifer@Sulthans_Palace.com

On entering the Tools/Macro menu the virus displays the DialogBox:
Message from Lucifer
We knew that the first WordMacro virus was created by McNamara.
But, somebody tried to convince that he was the conceptor!!
His name is: MILKY WAHYUDI WIDJAJA
His speech like bullshit!!
I'm the one of MV creator call him VIRUS CLAIMER, NOT VIRUS MAKER !!
isn't he Phardera ?
Greeting to Everyone
Notice : this is not a virus, just a message don't kill me!!

Macro.Word.Lunar

Description Macro.Word.Lunar

This is an encrypted macro virus. It contains seven macros: autoexec, autoopen, filesave, autoclose, filesaveas, toolsmacro, filetemplates.
The virus infects the global macros area on opening (AutoOpen) or closing (AutoClose) an infected document. It infects the documents that are saved (FileSave) or saved with new name (FileSaveAs).
The virus creates the LUNAR.INI file and writes the text to there:
[virus]
lunar=<number of generation>
author=Hyperlock

This is a stealth-virus - it hooks File/Templates and Tools/Macro, on entering these menus the virus displays the MessageBox:
Microsoft Word
Not enough memory to perform this operation

The virus contains the commented text strings:
WM.Lunar virus
AutoExec macro

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Short Mens Haircuts
Windy City
Provillus
Custom Fitting Golf
Versicherungsmakler

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com