Macro.Excel97.Papa.a
Description Macro.Excel97.Papa.a
This macro virus is based on the code of Word macro virus "Melissa" . The virus replicates under Excel97, but it does not infect other workbooks. Instead of this the worm sends own copies in Email messages by using MS Outlook. Because of its infection method, this is much more worm than ordinary macro virus. The worm code contains one procedure Workbook_Open in module ThisDocument that automatically runs on opening workbook. To send its copies via email the virus uses VisualBasic abilities to activate other MS Windows applications and use their routines: the virus gets access to MS Outlook (if it is installed on the computer) and calls its functions. The virus gets from each Outlook address list of up to sixty addresses and sends to them a new message. This massage has: The subject: "Fwd: Workbook from all.net and Fred Cohen". Message body: "Urgent info inside. Disregard macro warning." The message also has attached workbook - it is current (worm's) workbook, and it is infected. Depending on the system random counter (in one case from 3) the worm floods either web site "Fred Cohen & Associates" or site with IP address 24.1.84.100.
Check other viruses! Be aware! Use Antiviral Software
Pkunk.1586
Description Pkunk.1586
It is a harmless nonmemory resident partly encrypted parasitic virus. It searches for COM and EXE files, then infects them. While infecting the virus uses one of four possible methods: infecting COM files to the file end or header, infecting EXE to the file end with two possible methods. The infection method is selected by the virus depending on the system and software installed on the system. The virus looks for DOS*, WIN*, GAM*, QWE* directories on the C: drive, and depending on their presence selects the infection method. The virus contains the text string: [PKUNK v1.0] (c) Wet Milk
PL0006.480
Description PL0006.480
It is not a dangerous nonmemory resident parasitic virus. It searches for COM files and writes itself to the end of the file. Depending on the system date it reboots the computer. It contains the text string: PL*.com PL006 Virus
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Schody Best Pc Rpg Der Versicherungsvergleich Car Shipping Company
|