Slubdestr.1024
Description Slubdestr.1024
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and when any file is executed or terminated, the virus searches for two .COM files of the current directory and writes itself to the end of the file. After infection it checks the system timer and on 10am and 5pm it renames C:AUTOEXEC.BAT file to C:SLUBDESTR.N23. It contains the text string: c:autoexec.bat c:slubdestr.n23
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Dreams.a
Description Macro.Word97.Dreams.a
This virus contains five functions in one module "Dream": AutoOpen, FileOpen, FileNew, FilePrint, FileExit. The virus replicates itself on any function activating, i.e. on documents opening, creating or printing. To copy its code the virus uses export/import functions via the temporary C:CONFI~1.~YS file. On Word exiting the virus depending on the system random counter saves the current document with one of the names: HARDCORE.DOC, HEROINKILLS.DOC, LESBIANS.DOC, DESIRE.DOC, GRAVITYKILLS.DOC, R.I.P-TALON.DOC, HOPE.DOC. Depending on the system date it saves it either on the M: drive (before 15th of month) or on the F: drive (starting from 15th). The virus erases the menu items "Tools/Macro" and "Tools/Templates and add-insall". On 21st of any month it creates the C:WINDOWSDREAMS.TXT file and writes the text to there: .-=BadDReAms=-. When you sleep Do you see an angel in the dying light Or can you see someone standing outside Trying to set you alight. Maybe you`ve seen Someone Somewhere before That I might have loved had I never loved you But you only see Me In bad dreams
Macro.Word97.Dworld
Description Macro.Word97.Dworld
Programmiert von RinCeWinD~[m@G]~ aka zWeiBLuM Kontakt: Rincewind_mg@hotmail.com
---------------------------------------------------
|Danke an Lz? (besonders IarRagèN & LRay), BeTa CreW| |und alle die mich kennen! | |FæRDERT EURE LOKALE SZENE! |
---------------------------------------------------
Weitere Infektionen: ----------------------------------------------------------------------- DateiName: Datum: Uhrzeit:
It also changes the properties: UserName = "RinCeWinD~[m@G]~" UserInitials = "~[m@G]~" UserAddress = "Kontakt: rincewind_mg@hotmail.com"
The virus infects other documents upon their opening or creating (AutoOpen, AutoNew). For each infected document, the virus writes one line to the "DWORLD.INI" file with the name of an infected document, date and time of infection. The virus turns off the Word virus protection (the VirusProtection option). It also disables the Tools/Macro menus and blocks Visual Basic editor (stealth). Upon printing documents, if the date is the 24th of the month, the virus replaces all words "der" in the active document with the "der ~[m@G]~" string in 20% of the cases. With the same probability, it displays the message "Des Zauberer?s Finger sind im Spiel!", and appends the following text to the document: allDie aufgekl€rten Brìder der schwarzen Nacht sagen:... -HOOOOOLLDRIIOOOOO!!!-
If the date is the 12th of the month, the virus displays the message: "Des Zauberer?s Finger sind im Spiel!", and hides the mouse cursor. The virus contains the following comments: DiscwèrlD MakrèViruS -Dwèrld.MV.B- der magischen Gilde Prègrammiert von Rincewind~[m@G]~ Kontakt: | rincewind_mg@hotmail.com | !FæRDERT EURE LOKALE SZENE! Ausgesetzt im J€nner 99 Danke an alle die mich kennen | besènders NJèker[SLAM] | cèRDy & LRay Dwèrld.MV ist FleTsCheR und IarRaGèN gewidmet
???????????????????????????????????????????????????????????????????????? ? !" %&/()=?->DiE auFgeKL€rTeN BRìdeR dER sCHwaRzeN NaCHt<-?=()&%$ "! ? ????????????????????????????????????????????????????????????????????????
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Ibs Cure Turkey Flat Butchers Julklappar Företag Projekt Konsult I Dalarna Aktiebolag
|