Macro.Word.Want
Description Macro.Word.Want
This is Chinese Word macro virus. It contains 5 macros: AutoOpen, dom, free, ToolsMacro, want. The virus replicates itself on opening documents. Starting from 15th of any month, in case of an error in macros the virus writes to the C:AUTOEXEC.BAT file the command that will format the hard drive: FORMAT C:/S/U/V:VFS>NUL
The virus also creates the files OUT.COM, DOM.COM, KOS.COM that are infected by viruses "Ph33r", "Hare.7786", "Natas.4746" and copies these files with the names C:MSAV.COM, C:KILL.COM, C:GMOUSE.COM. The virus also inserts calls to these files into the C:AUTOEXEC.BAT file.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Jedi_Magic
Description Macro.Word97.Jedi_Magic
This virus contains two functions AutoOpen and AutoExit in single module Jedi_Magic. It replicates on documents opening. While infecting the global macros area the virus resets system variables: UserName = "O.B.1. Canobi" UserInitials = "OBC" UserAddress = "BOOGZI BARBERS all Food Buster!!!"
The virus detects already infected documents by the Force variable in which it saves the text: "567374-Joseph.A.D.G.". On exiting Word the virus resets its module's attributes: VB_Description = "Macro created 03/12/98 by Membership & Registry Division" VB_ProcData.VB_Invoke_Func = "Normal.Jedi_Magic.AutoExit"
Macro.Word97.Jim.b
Description Macro.Word97.Jim.b
Upon document closing, the virus checks running applications and if one of the following applications is found: Outlook, Internet Explorer or ICQ, the virus collects information about a computer and tries to send it to one of the FTP servers on the Internet. The collected information includes: First found .PWL file on drive C: User name Time document infected Application Country code Free disk space Generation of virus Processor type Operating system The virus also searches for a Pegasus Mail application, and if it find one, it creates a message with an attached infected document. If the MIRC client is installed on a computer, the virus drops a script that instructs MIRC to send an infected document to every computer joined to the same IRC channel as the infected computer. The virus has a payload procedure that is triggered on second day of the month. This procedure inserts a text into the active document: [Mr Jim/SeptiC/TI] - Do you have what it takes to become an international bussiness man!? [Mr Jim]/SeptiC/TI '99
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Try A Bob Hairstyle Freelance Web Design Credit Card Offers Der Versicherungsvergleich Debt Relief
|