Virus Database


Slubdestr.1024

Description Slubdestr.1024

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and when any file is executed or terminated, the virus searches for two .COM files of the current directory and writes itself to the end of the file. After infection it checks the system timer and on 10am and 5pm it renames C:AUTOEXEC.BAT file to C:SLUBDESTR.N23. It contains the text string:
c:autoexec.bat c:slubdestr.n23

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Dreams.a

Description Macro.Word97.Dreams.a

This virus contains five functions in one module "Dream": AutoOpen, FileOpen, FileNew, FilePrint, FileExit. The virus replicates itself on any function activating, i.e. on documents opening, creating or printing. To copy its code the virus uses export/import functions via the temporary C:CONFI~1.~YS file.
On Word exiting the virus depending on the system random counter saves the current document with one of the names: HARDCORE.DOC, HEROINKILLS.DOC, LESBIANS.DOC, DESIRE.DOC, GRAVITYKILLS.DOC, R.I.P-TALON.DOC, HOPE.DOC. Depending on the system date it saves it either on the M: drive (before 15th of month) or on the F: drive (starting from 15th).
The virus erases the menu items "Tools/Macro" and "Tools/Templates and add-insall". On 21st of any month it creates the C:WINDOWSDREAMS.TXT file and writes the text to there:
.-=BadDReAms=-.
When you sleep
Do you see an angel in the dying light
Or can you see someone standing outside
Trying to set you alight.
Maybe you`ve seen Someone Somewhere before
That I might have loved had I never loved you
But you only see Me In bad dreams

Macro.Word97.Dworld

Description Macro.Word97.Dworld

Programmiert von RinCeWinD~[m@G]~ aka zWeiBLuM
Kontakt: Rincewind_mg@hotmail.com

---------------------------------------------------

|Danke an Lz? (besonders IarRagèN & LRay), BeTa CreW|
|und alle die mich kennen! |
|FæRDERT EURE LOKALE SZENE! |

---------------------------------------------------

Weitere Infektionen:
-----------------------------------------------------------------------
DateiName: Datum: Uhrzeit:

It also changes the properties:
UserName = "RinCeWinD~[m@G]~"
UserInitials = "~[m@G]~"
UserAddress = "Kontakt: rincewind_mg@hotmail.com"

The virus infects other documents upon their opening or creating (AutoOpen, AutoNew). For each infected document, the virus writes one line to the "DWORLD.INI" file with the name of an infected document, date and time of infection.
The virus turns off the Word virus protection (the VirusProtection option). It also disables the Tools/Macro menus and blocks Visual Basic editor (stealth).
Upon printing documents, if the date is the 24th of the month, the virus replaces all words "der" in the active document with the "der ~[m@G]~" string in 20% of the cases. With the same probability, it displays the message "Des Zauberer?s Finger sind im Spiel!", and appends the following text to the document:
allDie aufgekl€rten Brìder der schwarzen Nacht sagen:...
-HOOOOOLLDRIIOOOOO!!!-

If the date is the 12th of the month, the virus displays the message: "Des Zauberer?s Finger sind im Spiel!", and hides the mouse cursor.
The virus contains the following comments:
DiscwèrlD MakrèViruS -Dwèrld.MV.B- der magischen Gilde
Prègrammiert von Rincewind~[m@G]~
Kontakt: | rincewind_mg@hotmail.com |
!FæRDERT EURE LOKALE SZENE!
Ausgesetzt im J€nner 99
Danke an alle die mich kennen | besènders NJèker[SLAM] | cèRDy & LRay
Dwèrld.MV ist FleTsCheR und IarRaGèN gewidmet

????????????????????????????????????????????????????????????????????????
? !" %&/()=?->DiE auFgeKL€rTeN BRìdeR dER sCHwaRzeN NaCHt<-?=()&%$ "! ?
????????????????????????????????????????????????????????????????????????

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Ibs Cure
Turkey Flat Butchers
Julklappar Företag
Projekt Konsult I Dalarna Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com