Virus Database


DBCE.3403

Description DBCE.3403

DBCE.3403 is a not dangerous memory resident encrypted parasitic virus. It hooks INT 8, 9, 21h and writes itself to the end of COM- (except COMMAND.COM) and EXE-files that are executed. On typing "virus" on the keyboard, the virus replaces it with "clankswerk", it also changes the "virus" string to "clank" on the screen. It contains the internal text strings:
COMMAND.COM
[DBCE]

and displays the messages:
Amidst Dale Beaudoin's
driveling
clank clunking crap
rubishy rubish
the following wisdom spews forth:
You have the Dale Beaudoin Clankswerks Engine by pseudoVirus writer Virotech!
This crude clankswerks was quickly and sloppily put together just like
Dale's Fido messages.
In my assesment there is ways and means to break new ground in the
computer sciences. virus not= virus. virus = clankswerks engine!
A "virus" or "trojan" that attempts to do a DIRECT WRITE bypassing the
operating system is not a virus. It is a mathclanking engine.
The clankswerks "appears" to have a measure of stealth by passing DOS but
the intent is more deliberate than stealthy. The "formula" or "equation"
is designed with a directive.
PseudoViruses deliberately mathclank other software programs. They are
not true viruses.
Computer "virus" (clankswerks) do not replicate, they iterate,
decrementally and incrementally through a math engine dependent on a
specific order of operations.
RPM is not software intergrated. IDE drives I have worked with often
have the platter scored after subject to a clankswerks. If the controller
would to do a seek in a tight loop the harmonics would be enough to allow
the heads to crash through the air-bearing.
The purity of the overall engine is mathclanked by the deliberate
alteration of one of the subsets. That alteration is dependent on the
works of an human idiot math-clanker. It is illegal and not natural.
Any so called virus that can take instrucution to lift attributes has to
be artificially intelligent.
If a pseudoVirus consults the COMSPEC to find the original copy of
COMMAND.COM, all you have to do is use debug and rename COMSPEC and
COMMAND.COM. Change the varialbe and tell your virus to decipher it! If
it does consult or decipher then it's AI, not virus.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Dreams.a

Description Macro.Word97.Dreams.a

This virus contains five functions in one module "Dream": AutoOpen, FileOpen, FileNew, FilePrint, FileExit. The virus replicates itself on any function activating, i.e. on documents opening, creating or printing. To copy its code the virus uses export/import functions via the temporary C:CONFI~1.~YS file.
On Word exiting the virus depending on the system random counter saves the current document with one of the names: HARDCORE.DOC, HEROINKILLS.DOC, LESBIANS.DOC, DESIRE.DOC, GRAVITYKILLS.DOC, R.I.P-TALON.DOC, HOPE.DOC. Depending on the system date it saves it either on the M: drive (before 15th of month) or on the F: drive (starting from 15th).
The virus erases the menu items "Tools/Macro" and "Tools/Templates and add-insall". On 21st of any month it creates the C:WINDOWSDREAMS.TXT file and writes the text to there:
.-=BadDReAms=-.
When you sleep
Do you see an angel in the dying light
Or can you see someone standing outside
Trying to set you alight.
Maybe you`ve seen Someone Somewhere before
That I might have loved had I never loved you
But you only see Me In bad dreams

Macro.Word97.Dworld

Description Macro.Word97.Dworld

Programmiert von RinCeWinD~[m@G]~ aka zWeiBLuM
Kontakt: Rincewind_mg@hotmail.com

---------------------------------------------------

|Danke an Lz? (besonders IarRagèN & LRay), BeTa CreW|
|und alle die mich kennen! |
|FæRDERT EURE LOKALE SZENE! |

---------------------------------------------------

Weitere Infektionen:
-----------------------------------------------------------------------
DateiName: Datum: Uhrzeit:

It also changes the properties:
UserName = "RinCeWinD~[m@G]~"
UserInitials = "~[m@G]~"
UserAddress = "Kontakt: rincewind_mg@hotmail.com"

The virus infects other documents upon their opening or creating (AutoOpen, AutoNew). For each infected document, the virus writes one line to the "DWORLD.INI" file with the name of an infected document, date and time of infection.
The virus turns off the Word virus protection (the VirusProtection option). It also disables the Tools/Macro menus and blocks Visual Basic editor (stealth).
Upon printing documents, if the date is the 24th of the month, the virus replaces all words "der" in the active document with the "der ~[m@G]~" string in 20% of the cases. With the same probability, it displays the message "Des Zauberer?s Finger sind im Spiel!", and appends the following text to the document:
allDie aufgekl€rten Brìder der schwarzen Nacht sagen:...
-HOOOOOLLDRIIOOOOO!!!-

If the date is the 12th of the month, the virus displays the message: "Des Zauberer?s Finger sind im Spiel!", and hides the mouse cursor.
The virus contains the following comments:
DiscwèrlD MakrèViruS -Dwèrld.MV.B- der magischen Gilde
Prègrammiert von Rincewind~[m@G]~
Kontakt: | rincewind_mg@hotmail.com |
!FæRDERT EURE LOKALE SZENE!
Ausgesetzt im J€nner 99
Danke an alle die mich kennen | besènders NJèker[SLAM] | cèRDy & LRay
Dwèrld.MV ist FleTsCheR und IarRaGèN gewidmet

????????????????????????????????????????????????????????????????????????
? !" %&/()=?->DiE auFgeKL€rTeN BRìdeR dER sCHwaRzeN NaCHt<-?=()&%$ "! ?
????????????????????????????????????????????????????????????????????????

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Pa-15
Germany Phone Cards
Reciprocal Link Software
Stearn Foster Mattress
Raucher Berlin

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com