Virus Database


Experiments.755

Description Experiments.755

It's a not memory resident harmless virus. It hits EXE-files only. This virus contains the text "---- Small experiments path 2.1 ----".

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Metamorph

Description Macro.Word97.Metamorph

It is a stealth macro virus. It contains five functions in documents in the one module "Metamorph": AutoOpen, FileTemplatesTemp, ToolsMacroTemp, ViewVBCodeTemp, AutoExecTemp. In the NORMAL.DOT the virus contains six functions in one random named module: FileSaveAs, AutoOpenTemp, FileTemplates, ToolsMacro, ViewVBCode, AutoExec. The name of this module is saved in the METAMORPH.INI file in section [Infected] in line Reponse.
The virus infects the global macros area on opening an infected document. Other documents get infection on saving with new name (FileSaveAs). The code of virus is different in documents and NORMAL.DOT - the virus modifies it while copying itself into the system. It creates new infection function FileSaveAs and stealth-functions ToolsMacro and ViewVBCode. While infecting documents the virus imports its original code from the C:METAPH.LOG which is created when the virus infects the system.
When Word starts the virus changes the names of menu items "File", "Edit", "View", "Format" with their french variants. Depending on the system date and time the virus displays the MessageBoxes:
Virus Metamorph
Attention, j'ai contaminé votre ordinateurall
Virus metamorph
Il est
L'heure de metamorph
Virus Metamorph
Au revoir...
Virus Metamorph
Poufffff!!!!!!

On displaying the last MessageBoxes the virus erases the files:
C:WindowsSystem*.*
C:WindowsCommand*.*
C:Windows*.Com
C:Dos*.*

Macro.Word97.Mimir

Description Macro.Word97.Mimir

This is a very dangerous macro virus. The virus uses destructive way of infection. Instead of copying just macro programs to infect other documents (as most of other macro viruses do), this virus overwrites whole documents while infecting them - it copies infected document to the victim ones as disk files. As a result the virus destroys original documents, and they cannot be recovered.
The virus contains one macro Document_Open and activates at the same moment an infected document is loaded by MS Word. The virus gets names of four last recently edited files and overwrites them. Then it searches for files with .DOC filename extension on the C: drive including subfolders, and overwrites them in the same way. As a result all documents on the C: drive may be destroyed.
To spread itself the virus also uses the MS Outlook mail and sends infected messages to the Internet. It gets all contacts from MS Outlook contacts folder and send each of them a message with attached infected document, the body of message has one line of text:
Some nice jokes you got to read!! :))

If the system date is set to April 9th 1999 the virus deletes the C:IO.SYS file and displays the message box:
Oooops
..Sorry..MIMIR has infected your PC..

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Mema Markiser Aktiebolag
Se Optik I LinkÖping Ab
Fast Sailing
Gunilla Lejman Service
Lifepower4u

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com