Virus Database


Macro.Word.LoneRaider

Description Macro.Word.LoneRaider

This is an encrypted Word macro virus containing only one macro - LoneRaider. This is not an auto macro, and it can be executed only by user's request, i.e. if it is run by Tools/Macro/Run menu item.
When the virus takes control, it replicates itself. While replicating the virus does not use any macro copy commands, but creates and runs new macro named "LoneRaiderTwo" and uses this macro to copy itself to system global macros or a document.
To do that the virus calls the Tools/Macro/Edit menu item to edit new "LoneRaiderTwo" macro, inserts to there WordBasic commands including MakroKopieren (MacroCopy), then it runs this macro and deletes it by Tools/Macro/Run and Tools/Macro/Delete menu items. When executed, the "LoneRiderTwo" macro copies the original "LoneRaider" macro to the destination document or global macros area.
On January 1st the virus creates a new template and inserts the strings to there:
Enjoy the first F/WIN Killer!
LoneRaider!
Nightmare Joker
1996

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Ultras.Joke

Description Macro.Word.Ultras.Joke

These viruses infect the Word documents. The infection is run on documents opening or closing.
The virus sets to "Ultras/Joke/ULTRAS2.usa.net" the Name/Initials/Address in document's UserInfo fields. The virus also makes changes in the Registry:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersion]
"RegisteredOwner"="ULTRAS"
"RegisteredOrganization"="Rioters"
"ProductName"="JoKe By ULTRaS"
[HKEY_CLASSES_ROOTWORD.DOCUMENT.6DefaultIcon]
C:WindowsSystemShell32.dll,31
[HKEY_CLASSES_ROOTWord.TemplateDefaultIcon]
C:WindowsSystemShell32.dll,32

Macro.Word.UnderGround

Description Macro.Word.UnderGround

This is an encrypted macro virus. It contains two macros. Their names are Macro7 and AutoClose in NORMAL.DOT. In documents their names are randomly selected: <letter><number>, <letter><number> (for example: T45, E53).
The virus infects the documents that are closed (AutoClose). To infect the global macros area (NORMAL.DOT) on opening an infected document, the virus sets one of random named macros in document as the auto-macro. As a result, the macros in infected document do not have any auto-name, but they are executed while opening this document as the AutoOpen auto-macro.
While infecting the virus creates a temporary macro. While infecting the NORMAL.DOT the virus displays the MessageBox and asks a user for permission:
SoftWare UnderGround
Can I install myself into your NORMAL.DOT
[YES] [NO]

In case of "YES" the virus infects the NORMAL.DOT, displays the statistic information about current document and document author's name.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Eskilstuna Mur Och Puts
Aktiebolaget Ögat Å Priset
Selma StÄdservice
J.b.w. Service Handelsbolag
Halmstads StÄdservice

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com