Macro.Word.Jaja
Description Macro.Word.Jaja
This is an encrypted macro virus. It contains 10 macros: AutoOpen, FileOpen, FileSaveAs, FilePrint, ToolsMacro, FileTemplates, FormatStyle, ViewToolbars, ToolsCustomize, VictorWidjaja
When an infected document is opened (AutoOpen), the virus infects the global macros area. Then it writes itself to documents that are opened (FileOpen) or saved with a new name (FileSaveAs). The ToolsMacro and FileTemplates are the stealth macros - they disable the corresponding Word menus. On printing a document (FilePrint) the virus erases its contents and inserts the message: +------------------------------------------------------------+ | Welcome to Victor Widjaja Virus | |Your computer has been totally infected by ''Victor Widja| | ja'' WordMacro Virus | | Don't go anywhere !!! | | I'll be back soon to DESTROY your disk data !! | | Copyright 1996 Virus Research Labs. | +------------------------------------------------------------+
Then the virus prints the message to the status line: [ Welcome to Victor Widjaja `WordMacro' Virus - Programmed & Created by Victor Widjaja the HACKER - Virus Research Labolatory ]
On November 1st the virus prints the same message, then displays the MessageBox: Attention Victor Widjaja lives in your PC now
The virus then checks the system timer, and if current seconds counter is equal to 1 or 11 the virus calls the disk erasing function: Format C: /U /C /S /AUTOTEST > NUL
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Defender
Description Macro.Word.Defender
This macro virus contains six macros: Documents: AutoOpen, Defend, Module1, Module2, Module3, Module4 NORMAL.DOT: FileSaveAs, ToolsMacro, FileOpen, Defender, Module1, Module2
It infects the global macros area on opening an infected document (AutoOpen), and writes itself to documents that are saved with new name (FileSaveAs). While entering the ToolsMacro menu the virus requests for a password. The password is the same as the active document file name. The virus disables several viruses or warns a user: while infecting a document or NORMAL.DOT the virus checks it for "Concept" virus macros and several other macros, then it deletes them. Depending on several conditions the virus displays the MessageBoxes: Defender ALERT! Autorunning macro (possibly virus) detected in document. Press OK to disable Defender WARNING: Active macro virus found. Defender will now exit Word. You must then restart Word and try to load the document again
The virus contains the comments: ***************************************************************** Macro : Defender Created : August 29, 1995 (modified on October 1 1996) Copyright (c) 1995 Microsoft Corp. Description : On FileOpen, detect documents containing autorunning macros and remove them *****************************************************************
Macro.Word.Delword
Description Macro.Word.Delword
This virus contains eight macros: Fake, Payload, AutoOpen, FileSave, AutoClose, FilePrint, FileSaveAs, StealthActivate. The virus infects the global macros area (NORMAL.DOT) on opening or closing an infected document and writes itself to documents that are saved or saved with new name. While printing a document the virus: on 29th of any month deletes all words within document and displays the MessageBox: Mwahahahaall Bye bye Report...I hope you didnt work on this for too long :)
in october cancels printing and displays the MessageBox: No Printing Today!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Bromma FÖnsterputs Ab Karlslunds Glas & Aluminium Dalby Billackering Bras Ab Tages Trafikskola StÄd & LacktjÄnst Yngve Eriksson
|