Virus Database


DarkLord.273

Description DarkLord.273

This is a harmless memory-resident virus. It affects COM- and EXE-files by standard way whenever they are run (COMMAND.COM is infected according to the "Lehigh" algorithm). The virus contains the text: "Dark Lord, I summon thee! MANOWAR".

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Dworld

Description Macro.Word97.Dworld

Programmiert von RinCeWinD~[m@G]~ aka zWeiBLuM
Kontakt: Rincewind_mg@hotmail.com

---------------------------------------------------

|Danke an Lz? (besonders IarRagèN & LRay), BeTa CreW|
|und alle die mich kennen! |
|FæRDERT EURE LOKALE SZENE! |

---------------------------------------------------

Weitere Infektionen:
-----------------------------------------------------------------------
DateiName: Datum: Uhrzeit:

It also changes the properties:
UserName = "RinCeWinD~[m@G]~"
UserInitials = "~[m@G]~"
UserAddress = "Kontakt: rincewind_mg@hotmail.com"

The virus infects other documents upon their opening or creating (AutoOpen, AutoNew). For each infected document, the virus writes one line to the "DWORLD.INI" file with the name of an infected document, date and time of infection.
The virus turns off the Word virus protection (the VirusProtection option). It also disables the Tools/Macro menus and blocks Visual Basic editor (stealth).
Upon printing documents, if the date is the 24th of the month, the virus replaces all words "der" in the active document with the "der ~[m@G]~" string in 20% of the cases. With the same probability, it displays the message "Des Zauberer?s Finger sind im Spiel!", and appends the following text to the document:
allDie aufgekl€rten Brìder der schwarzen Nacht sagen:...
-HOOOOOLLDRIIOOOOO!!!-

If the date is the 12th of the month, the virus displays the message: "Des Zauberer?s Finger sind im Spiel!", and hides the mouse cursor.
The virus contains the following comments:
DiscwèrlD MakrèViruS -Dwèrld.MV.B- der magischen Gilde
Prègrammiert von Rincewind~[m@G]~
Kontakt: | rincewind_mg@hotmail.com |
!FæRDERT EURE LOKALE SZENE!
Ausgesetzt im J€nner 99
Danke an alle die mich kennen | besènders NJèker[SLAM] | cèRDy & LRay
Dwèrld.MV ist FleTsCheR und IarRaGèN gewidmet

????????????????????????????????????????????????????????????????????????
? !" %&/()=?->DiE auFgeKL€rTeN BRìdeR dER sCHwaRzeN NaCHt<-?=()&%$ "! ?
????????????????????????????????????????????????????????????????????????

Macro.Word97.Edds

Description Macro.Word97.Edds

This virus contains twenty macros in one module - "EddsHead". The virus replicates itself upon execution any of its macros.
The virus contains the comments:
Produced by,
The VicodinES Macro.Poppy Construction Kit v1.0b
================================================
Code Written by VicodinES "Live for Now"
Poppy ID : 24421479963

If the NORMAL.DOT file has the ReadOnly attribute set, the virus creates the C:WINDOWSSTARTM~1PROGRAMSSTARTUPMSFILE.BAT file that upon rebooting clears this attribute and erases the NORMAL.DOT.
The virus replaces the disks' icons. Depending on a random counter, the virus displays the following MessageBox:
Your Computer Has The Edds Head Virus

On February 14 (Valentine's Day), it displays the following MessageBox:
Birthday Greeting!!!
I Hope You Got Your Girlfriend Something Nice !

Depending on a random counter, the virus copies the current file to a randomly selected disk from F: to S: with one of the following names: PORNO.DOC, README!.DOC or SEX.DOC.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



SALLADSKUNGEN AB
VÄG & BYGGNADSGRUS PÅ GOTLAND AB
Versicherungen
SACCI RYGGSÄCKAR AB
Steel Windows

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com