Macro.Word.ShareFun
Description Macro.Word.ShareFun
This encrypted Word macro virus contains nine macros: AutoExec - does nothing autoOpen - infects current document or global macros area FileClose - -//- FileExit - -//- FileSave - -//- FileOpen - -//- FileTemplates - -//- ToolsMacro - -//-, disables Tools/Macro menu (stealth) ShareTheFun - trigger routine
It infects the system and documents on opening, closing and accessing Tools/Macro menu. It manifests itself in very unusual way - it sends infected documents via MicrosoftMail, if it is installed. On opening a document or template (AutoOpen) the virus with probability 1/4 calls the ShareTheFun macro. This macro saves the current (already infected) document to the C:DOC1.DOC file, activates Microsoft Mail by WordBasic instruction AppActivate, gets three random selected addresses from addresses list and sends them the infected C:DOC1.DOC file with the subject line: You have GOT to read this!
If Microsoft Mail is not included in the running tasks, the virus shuts down Windows.
Check other viruses! Be aware! Use Antiviral Software
MGUL.1953
Description MGUL.1953
This is a dangerous memory resident parasitic stealth virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. It also hooks INT 1, 3, 8. On June 11th and November 30th, it erases the hard drive MBR. It reboots the computer if the virus is under a debugger. It contains the following string: MGUL. v2.5
MGUL.1962
Description MGUL.1962
This is a dangerous memory resident parasitic stealth virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. It also hooks INT 1, 3, 8. On June 11th and November 30th, it erases the hard drive MBR. It reboots the computer if the virus is under a debugger.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Halmstad Day Spa Ab Stallarna Aktiebolag Riva's JÄrvsÖ SjÖfart & Diverse Handelsbolag Strandberg, Daniel
|