Virus Database


Macro.Word.Jaja

Description Macro.Word.Jaja

This is an encrypted macro virus. It contains 10 macros:
AutoOpen, FileOpen, FileSaveAs, FilePrint, ToolsMacro, FileTemplates,
FormatStyle, ViewToolbars, ToolsCustomize, VictorWidjaja

When an infected document is opened (AutoOpen), the virus infects the global macros area. Then it writes itself to documents that are opened (FileOpen) or saved with a new name (FileSaveAs). The ToolsMacro and FileTemplates are the stealth macros - they disable the corresponding Word menus.
On printing a document (FilePrint) the virus erases its contents and inserts the message:
+------------------------------------------------------------+
| Welcome to Victor Widjaja Virus |
|Your computer has been totally infected by ''Victor Widja|
| ja'' WordMacro Virus |
| Don't go anywhere !!! |
| I'll be back soon to DESTROY your disk data !! |
| Copyright 1996 Virus Research Labs. |
+------------------------------------------------------------+

Then the virus prints the message to the status line:
[ Welcome to Victor Widjaja `WordMacro' Virus - Programmed & Created
by Victor Widjaja the HACKER - Virus Research Labolatory ]

On November 1st the virus prints the same message, then displays the MessageBox:
Attention
Victor Widjaja lives in your PC now

The virus then checks the system timer, and if current seconds counter is equal to 1 or 11 the virus calls the disk erasing function:
Format C: /U /C /S /AUTOTEST > NUL

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Defender

Description Macro.Word.Defender

This macro virus contains six macros:
Documents: AutoOpen, Defend, Module1, Module2, Module3, Module4
NORMAL.DOT: FileSaveAs, ToolsMacro, FileOpen, Defender, Module1, Module2

It infects the global macros area on opening an infected document (AutoOpen), and writes itself to documents that are saved with new name (FileSaveAs). While entering the ToolsMacro menu the virus requests for a password. The password is the same as the active document file name.
The virus disables several viruses or warns a user: while infecting a document or NORMAL.DOT the virus checks it for "Concept" virus macros and several other macros, then it deletes them. Depending on several conditions the virus displays the MessageBoxes:
Defender
ALERT! Autorunning macro (possibly virus)
detected in document. Press OK to disable
Defender
WARNING: Active macro virus found. Defender will now exit Word.
You must then restart Word and try to load the document again

The virus contains the comments:
*****************************************************************
Macro : Defender
Created : August 29, 1995 (modified on October 1 1996)
Copyright (c) 1995 Microsoft Corp.
Description : On FileOpen, detect documents containing autorunning
macros and remove them
*****************************************************************

Macro.Word.Delword

Description Macro.Word.Delword

This virus contains eight macros: Fake, Payload, AutoOpen, FileSave, AutoClose, FilePrint, FileSaveAs, StealthActivate. The virus infects the global macros area (NORMAL.DOT) on opening or closing an infected document and writes itself to documents that are saved or saved with new name.
While printing a document the virus:
on 29th of any month deletes all words within document and displays the MessageBox:
Mwahahahaall Bye bye Report...I hope you didnt work on this for too long :)

in october cancels printing and displays the MessageBox:
No Printing Today!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Bromma FÖnsterputs Ab
Karlslunds Glas & Aluminium
Dalby Billackering Bras Ab
Tages Trafikskola
StÄd & LacktjÄnst Yngve Eriksson

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com