Virus Database


Macro.Visio.Unstable

Description Macro.Visio.Unstable

This is the second macro-virus that also has pretensions to be The Number One in the "Macro.Visio" family. This virus is more complex than Macro.Visio.Radiant - it uses encryption and special tricks to hide its body in infected files.
The virus infects Visio documents, and stencils and templates upon opening an infected document. It enumerates all opened documents, stencils and templates and infects them by coping the virus body into them. To mark already infected documents, the virus writes "Visio2k.Unstable" into their description and does not infect documents with such a mark.
To hide itself, the virus closes all opened widows in the VBA editor, disables Visual Basic Editor's menus and "Standard" toolbar. In case a user tries to edit the macros inside infected documents, he/she will see just the empty editor's main window without any menus, toolbars and child windows.
The virus has a payload that triggers on the 31st, and it displays the message:
Visio2000.Unstable
Unstable, it's hard to be the one who's strong
Who's always got a shoulder to cry on
Who's got a shoulder for me?

The virus contains three procedures in module "ThisDocument" - "Document_DocumentOpened()", "Unstable()" and "ci()". Inside infected documents second procedure is unreadable because of encryption. The virus decrypts this procedure only just before its call.

Check other viruses! Be aware! Use Antiviral Software

Macro.Excel.Tjoro

Description Macro.Excel.Tjoro

This Excel macro virus contains one macro (module) named "NoMercy", the macro contains six functions: Auto_Open, cek_global, infectglobal, inFuckIt, Fuck, Auto_Close.
To infect the system the virus creates the infected GLOBAL.XLM file in Excel startup directory and sets macros Fuck as auto-macro that is called when any sheet is activated. As a result the virus hooks sheets activating, and infects them. While infecting the virus searches for "NoMercy" module to prevent duplicate infection. If there are no such module, the virus copies its code to there.
On 11th of any month the virus displays the MessageBox:
Helloall
Hello there...you are infected with NoMercy!

Macro.Excel.Uedasun

Description Macro.Excel.Uedasun

This is an Excel macro-virus containing eight procedures in the module "A-TDK": Save, auto_open, scan, Status, DO_EVERYTHING, DO_SOMETHING, nexts, and check. The virus infects workbooks upon workbook opening or activating any of its sheets. The infection procedure creates an infected workbook with the name "TDK-MAC.XLS" in the Excel StartUp directory, and also infects the active workbook.
If the value in the "A16384" cell is not the "uedasan" text, the virus starts its payload procedure. In April, it removes all files with the extension ".SYS" from the C: root directory that also have hidden and system attributes set (C:IO.SYS, C:MSDOS.SYS). If the month is later than April and the time hour is less than six a.m., the virus removes all files in the current directory that have hidden and system attributes set.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



MÖbelform I GlimÅkra Ab
Mp3 Downloads Online
Draculaura Doll
Cgi Fire Proxy

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com