Virus Database


Macro.Word97.Antisocial

Description Macro.Word97.Antisocial

Dangerous "Melissa" -like macro virus. It infects documents and global macros area (Normal template) on document closing. This virus also spreads via email in the same way as "Melissa" does: On first infected document opening on a computer the virus attempts to send itself to the first sixty entries from the Outlook address book. The virus' message has infected document in attachment and:
Subject line: Important Message From
Text: Look what I foundall

After first attempt to send itself via email the virus sets registry key value:
HKEY_CURRENT_USERSoftwareMicrosoftOfficeSixtieth Skeptic = "Where's Jamie?"

Next time the virus checks this key to prevent duplicate sending.
In additional the virus drops its code into file "C:SS.BAS" and creates Visual Basic Script in file "C:SS.VBS" that reinfects the Normal template on each system reboot.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Maf

Description Macro.Word.Maf

This is a silly Word macro virus. The only virus macro AutoOpen infects the system macros area and current document on opening. The virus detects its presence in documents by macro description comment: "McAfee Antivirus".
The virus adds auto-corrections strings:
genial genital
geniale genitale
genialt genitalt

Macro.Word.Magnum

Description Macro.Word.Magnum

This encrypted macro virus contains three macros: Magnum, ToolsMacro, ExtrasMakro. The virus does not have any auto-macro, but gets control in another way. While infecting a document or global macros area the virus copies its macros to there and assigns the SPACE key with "Magnum" macro. MS Word saves such information and restores it on loading global macros or opening an infected document.
As a result, when MS Word is opening an infected document or loading global macros, it sets "Magnum" macro as routine that will be executed on SPACE keystroke.
After infecting global macros the virus displays a message box with the text:
MaGnUm

The ToolsMacro and ExtrasMakro macros are there to hide the virus in system - on selecting Tool/Macro the virus displays dummy menu that on any item (except CANCEL) displays the error messages:
WordBasic Err = 7
Not enough memory!
WordBasic Err = 7
Nicht genügend Arbeitsspeicher!

The virus drops the DOS virus "HLLO.Havoc" by using the trick with DEBUG utility - writes hexadecimal virus dump to disk and runs DEBUG to convert it to DOS executable file HTC.COM. Then the virus appends to the end of the C:AUTOEXEC.BAT file the commands:
@echo off
htc.com
cls

and then creates and writes to system profile (WIN.INI) the text:
[DosVirus]
Installed=Yes

On April 13 it creates the NORMAL.DOT file and writes the strings to there:
Schon mal im blasen Mondlicht mit dem Teufel getanzt?
;-))
The Magnum Virus! NJ 1996

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Byggson I Varberg
Kent Lundmarks Trafikskola Aktiebolag
GÄvleborgs Isolering Och PlÅt
T P M Entreprenad Aktiebolag
Fredrik Aronssons Fukt & El

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com