Deicide.358
Description Deicide.358
These are non-memory resident parasitic infectors. They search for .COM files and write themselves to their beginnings. Deicide.358 and 359 These are harmless viruses. They contain the internal text string: "Dutch [Breeze] by Glenn Benton". Deicide.622,623 These are harmless viruses. From the 3rd until the 18th of August, they display the following message: This Personal Computer has been struck by the uncurable disease that is called "The Doom of Morgoth".
Deicide.665 and 666 These are dangerous non-memory resident overwriting viruses. When started, they overwrite .COM files of the current directory and type: "File corruption error.". If .COM files are not present, the infector erases the C: disk FAT and types: "Glenn (666) says : BYE BYE HARDDISK!!". They also contain the strings: "DEICIDE!", "Next time be carufull with illegal stuffall...", "*.COM", "This experimental virus was written by Glenn Benton to see if I can make a virus while learning machinecode for 2,5 months. (C) 10-23-1990 by Glenn. I keep on going making virusses.". Deicide.693 This is a virus. This virus types one of the following messages: Brotherhood... I am seeking my brothers "DEICIDE" and "MORGOTH"... Found my brother "MORGOTH"!!! Found my brother "DEICIDE"!!! *** Glenn Benton ***
Deicide.1335 This is a non-memory resident, benign virus. It searches for a .COM files and writes itself to their beginnings. This virus types: As the good times of DEICIDE will be remembered, I started to make a new virus. You are now facing the dark tombs of "Morgoth". Humble regards to : Pazuzu Kingu Absu Mummu Tiamat | | Baxaxaxa Baxaxaxa Yog Sothoth Iak Sakkath | | Kutulu Humwawa Xaztur | | Hubbur Shub Niggurath --+--|--+-- | Also my lovely regards go to Stephanie, the only one who | makes my heart beat stronger. Want to make love with a --+-- Morbid Angel? Glenn greets ya. | Press a key to start the program... (This time no damage!).
Deicide.2404, 2405, 2569, and 2570 These benign viruses. After infection, they type one of the following messages, for example: Cycle sluts from hell Virus Mania IV 2 Live Crew is fucking cool Like Commentator I, HIP-HOP sucks Dr. Ruth is a first-class lady! Dont be a wimp, be dead! This dick was made for laying girls. No virus entry, just me! Dont bite it, you horny bitch! Stroke my keys, oh YES! Sex Revolution 4000 Buck Rogers is fake (C) by Glenn Benton Registration number required The fly is alive Dont fuck with me, or I will kick some ass... Hey, dont hit the keys that hard! You will feel me... BEER BEER BEER BEER BEER BEER BEER!!! YOU HAVE A VIRUS, BWAH AH AH EH EH HEH ARF! I would alter Michael Jacksons face with my fists... WIM KOK IS STILL A COMMUNIST! Welcome to COMMENTATOR II Commentator I & II released! Legalize ABORTUS! Ronald McDonald goes Oude-Pekela! Source code soon aveable... Dont use a rubber against this virus! Swimming holiday in Bangladesh! Neo Nazis are a pile of shit. Virus researchers are a pile of meat on the street. World Championship Cat-Throwing Yo Yo Yo Yo Yo Yo Yo, James Brown is DEAD! Yech, you are reminding me of my mother-in-law... How is the weather out there? Indalis is a fat bitch who looks like a glass-bin. Lubbers should be castrated for a long time ago. Legalize hookers (at a low prize!) Fist fucking sounds irrelevant to you, eh? I will be Back... Today it is..... JUDGEMENT DAY!!! Never mind the dog, beware of owner. You still owe me a CO-PROCESSOR! Do not drink and drive Last name ALMIGHTY, first name DICK Frodo lives! The leech lives Hey, Cracker Jack! Nice virus you made! A depressive Prince Claus looks like fun! Happy Eastern Thank god for AIDS Art is incredible stupid Out of semen error Incorrect BEF version Of je stopt de stekker erin?!? Jean Claude van Damme kicks ass. Cannabis expands the mind What is this memory? EMS XMS LIM HMA UMB? NOOOOOO NOT AN IBM SYSTEM, PLEASE!!!!! Dutch Virus Research Laboratory
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Wazzu
Description Macro.Word.Wazzu
This virus contains only one macro autoOpen and infects files when MS Word opens them, and copies its macros to Global area (NORMAL.DOT) when MS Word opens an infected document. The virus is not encrypted and may be easily detected by scanning for text strings: RndWorddo wazzu do RndWorddRgV
After infecting a document or installing into the system the virus takes a random selected word from document and moves it to random selected position. The virus repeats that up to three times depending on the random counter. Then it also depending on the random counter inserts the string "wazzu " at random selected position within document. In detail: the virus has three subroutines in its macro: MAIN - it is main routine and it takes control when autoOpen macro is executed Payload - is called by MAIN, replaces words and inserts "wazzu". RndWord - is called by Payload, sets random selected position within document
The virus modifies the document with the probabilities (p): replacing words - three times with p=1/5, inserting "wazzu" - p=1/4. Wazzu-related viruses The original "Wazzu" ("Wazzu.a") virus is one of the most widespread viruses on the world. The possible reason is that this virus was placed on the Microsoft WWW site, infected documents also were (are) distributed on several CD disks. As a result there are several dozens of related viruses, and the number of such related viruses is increasing every month. Below short descriptions are given, to name viruses CARO standard names are used (AVP does detect and disinfect majority of these viruses as "Wazzu.a"). "Wazzu.b,i" differ from original one only by included comment: < - - - - - - here 's the payload
"Wazzu.c,t,ac" do not manifest themselves in any way - they have no Payload subroutine (RndWord subroutine presents in virus, but is never called). "Wazzu.d,f,q,w,ad" do not have both Payload and RndWord subroutines. "Wazzu.f" is a shortest virus in the family - its code (binary data in infected file) has only 318 bytes of length. "Wazzu.e,h" are encrypted variants of original "Wazzu". "Wazzu.h" is slightly corrupted and may halt MS Word or cause an error message. "Wazzu.g,r" are encrypted viruses. "Wazzu.g" contains EatThis subroutine instead of original Payload. With probability 1/10 these viruses display a MessageBox with the text: Microsoft Word This one's for you, Bosco.
"Wazzu.k" is corrupted "Wazzu.a". "Wazzu.l" do not have any subroutines in macro except MAIN. With probability 1/10 it appends the string " wazzu!" to the end of document. "Wazzu.m,s" have no Payload subroutine, but call it. That will cause Word's error message. "Wazzu.u,aa,ad" are the same as "Wazzu.a", but do not insert the "wazzu" string. "Wazzu.x" does not contains any subroutines except MAIN. It contains the text: The Meat Grinder virus - Thanks to Kermit the Frog, and Kermit the Protocol
"Wazzu.y,z" are the same as "Wazzu.a", but code of these virus is slightly modified, for example all TAB (09h) symbols are replaced with 8 spaces in "Wazzu.y".
Macro.Word.White
Description Macro.Word.White
This Word macro-virus contains a different number of macros in documents and template. In documents, there are three macros with names selected from six variants: AutoOpen, AutoClose, FileTemplates, ToolsMacro, FileOpen, Einstein. While infecting the system, the virus creates the infected NARMOL.DOT template in the Word start-up directory. In this template the virus copies four macros: Einstein, FileOpen, FileTemplates, Show. The virus contains the comments: Einsteinium v.1.1. (White Virus) Solidarity M Forever Medan 1997
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Fight Club DEROME TIMBER AB Homepage Erstellen Billig Strom Microsoft Sql Server It Schulung
|