Lcv.864
Description Lcv.864
It is a harmless nonmemory resident parasitic virus. It searches for .COM files of a current directory and writes itself to the beginning of the file. It contains the text "*.COM".
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.ATU family
Description Macro.Word97.ATU family
The viruses of this family use an uncommon way of spreading. Instead of copying their macro program to the macro area in victim documents, they just write to documents a reference to a template (attached template) which contains virus macros. MS Word97 when opening a such document detects the reference to the attached template, opens it and executes its macros. The virus macro gets control and runs infected procedure. As a result the infected documents have no macro code, but on their opening the virus macro code is loaded by Word97 and executed. In the known versions of this virus the reference to attached template points to a file on a remote Internet site (virus-writers Web site). As a result, MS Word97 on opening an affected document downloads and processes the template that is placed in the Internet zone. Because of that virus author(s) are able to "upgrade" virus code by replacing the template on their Web site. This way of spreading allows the virus to bypass the anti-virus protection (VirusWarning) in old versions of MS Word97. These Word97 versions have a security breach: the anti-virus protection is not activated by Word97 to scan attached templates for macro code. This bug in MS Word97 was fixed in the beginning of 1999. "ATU.b": this virus version does not copy entire code from the template to global macros area, but only the code necessary to infects documents. The viruses contain the comments: "ATU.a":
<!--1nternal--> Active Template Update
"ATU.b":
<!--1nternal--> Active Template Update v0.2 /1nternal
Macro.Word97.AutoDestructor
Description Macro.Word97.AutoDestructor
This virus contains seven macros in one module "AutoDestructor98": AutoExec, AutoOpen, CpteAReb, FileSaveAs, FileTemplates, ToolsMacro, and ViewVBCode. The virus infects the global macros area upon the opening of an infected document and spreads to other documents upon saving them with a new name. While infecting NORMAL.DOT, the virus displays the following Balloon: Virus AutoDestructor98 HAHA !!!, votre ordinateur est infecté par un nouveau virusall
On the 15th of any month, the virus hides ScrollBar, and installs in the window caption the following text: Les barres de scrollings ont disparu...
Upon starting Word on July 13, the virus formats the hard drive and displays the following Balloon: Virus AutoDestructor98 Attention, le compte à rebours est lancé... Plus que 10 secondes
Before formatting, the virus prints the following numbers to the status bar: 10, 9, 8, 7, ... 1, 0 - one number per second. The same counting is displayed upon entering the Tools/Macro or File/Templates menus, and the virus then displays several messages and forces Word to terminate.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Rechtsschutzversicherung Svenskt FÅgelkÖtt Ab Herbal Supplements How To Make Money Online Jubels Golv Ab
|