Virus Database


Macro.Word.Want

Description Macro.Word.Want

This is Chinese Word macro virus. It contains 5 macros: AutoOpen, dom, free, ToolsMacro, want. The virus replicates itself on opening documents.
Starting from 15th of any month, in case of an error in macros the virus writes to the C:AUTOEXEC.BAT file the command that will format the hard drive:
FORMAT C:/S/U/V:VFS>NUL

The virus also creates the files OUT.COM, DOM.COM, KOS.COM that are infected by viruses "Ph33r", "Hare.7786", "Natas.4746" and copies these files with the names C:MSAV.COM, C:KILL.COM, C:GMOUSE.COM. The virus also inserts calls to these files into the C:AUTOEXEC.BAT file.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Jedi_Magic

Description Macro.Word97.Jedi_Magic

This virus contains two functions AutoOpen and AutoExit in single module Jedi_Magic. It replicates on documents opening. While infecting the global macros area the virus resets system variables:
UserName = "O.B.1. Canobi"
UserInitials = "OBC"
UserAddress = "BOOGZI BARBERS all Food Buster!!!"

The virus detects already infected documents by the Force variable in which it saves the text: "567374-Joseph.A.D.G.". On exiting Word the virus resets its module's attributes:
VB_Description = "Macro created 03/12/98 by Membership & Registry Division"
VB_ProcData.VB_Invoke_Func = "Normal.Jedi_Magic.AutoExit"

Macro.Word97.Jim.b

Description Macro.Word97.Jim.b

Upon document closing, the virus checks running applications and if one of the following applications is found: Outlook, Internet Explorer or ICQ, the virus collects information about a computer and tries to send it to one of the FTP servers on the Internet.
The collected information includes:
First found .PWL file on drive C:
User name
Time document infected
Application
Country code
Free disk space
Generation of virus
Processor type
Operating system
The virus also searches for a Pegasus Mail application, and if it find one, it creates a message with an attached infected document.
If the MIRC client is installed on a computer, the virus drops a script that instructs MIRC to send an infected document to every computer joined to the same IRC channel as the infected computer.
The virus has a payload procedure that is triggered on second day of the month. This procedure inserts a text into the active document:
[Mr Jim/SeptiC/TI] - Do you have what it takes to become an international
bussiness man!?
[Mr Jim]/SeptiC/TI '99

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Try A Bob Hairstyle
Freelance Web Design
Credit Card Offers
Der Versicherungsvergleich
Debt Relief

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com