Virus Database


Macro.Word97.AutoDestructor

Description Macro.Word97.AutoDestructor

This virus contains seven macros in one module "AutoDestructor98": AutoExec, AutoOpen, CpteAReb, FileSaveAs, FileTemplates, ToolsMacro, and ViewVBCode. The virus infects the global macros area upon the opening of an infected document and spreads to other documents upon saving them with a new name.
While infecting NORMAL.DOT, the virus displays the following Balloon:
Virus AutoDestructor98
HAHA !!!, votre ordinateur est infecté par un nouveau virusall

On the 15th of any month, the virus hides ScrollBar, and installs in the window caption the following text:
Les barres de scrollings ont disparu...

Upon starting Word on July 13, the virus formats the hard drive and displays the following Balloon:
Virus AutoDestructor98
Attention, le compte à rebours est lancé...
Plus que 10 secondes

Before formatting, the virus prints the following numbers to the status bar: 10, 9, 8, 7, ... 1, 0 - one number per second. The same counting is displayed upon entering the Tools/Macro or File/Templates menus, and the virus then displays several messages and forces Word to terminate.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Angus

Description Macro.Word.Angus

It is an encrypted Word macro virus, it contains nine macros:
Document NORMAL.DOT
FileClose FC
AutoOpen NOpen
FileSave
7 other FileSaveAs
with random FilePrint
names FilePrintDefault
FileTemplates
ToolsMacro
FileExit
PCGURU4

It infects global macros area on opening or closing an infected document (AutoOpen, FileClose). It infects documents on saving and saving with new name (FileSave, FileSaveAs). While infecting documents the virus stores renames its macros (see above) with random names and saves references to them to document's variables.
On October 23rd on printing documents the virus appends to the end of documents the message:
NAENBGOURSG
Hello from GREECE

On October 24th the virus creates and spawns the PCGURU4.BAT file that contains the instructions:
@echo off
Rem PcGuru4 virus by NAENBGOURSG
Rem Golden Version 4.3
type PcGuru4.bat >> PcGuru4.bat

Macro.Word.Anti-IVX

Description Macro.Word.Anti-IVX

It is not a dangerous semi-polymorphic macro virus. In infected documents it contains one macro AutoOpen that infects global macros area while opening an infected document. In infected NORMAL.DOT in contains two macros. The first macro is a copy of AutoOpen macro and has a random selected name. The second macro has the name FileSaveAs and infects documents that are saved with new name.
The virus is semi-polymorphic - while copying its AutoOpen macro it renames its internal values to other names, generates random name for copy of AutoOpen macro. While creating FileSaveAs macro the virus inserts commands that are selected from several variants and inserts random selected comments.
While infecting global macros area the virus creates the IVX.NOT file in the directory of the host file and writes the text to there:
IVX detects all macro viruses, past, present, and future.

It adds the command to the C:AUTOEXEC.BAT file that clears the Read-Only attribute of NORMAL.DOT file:
@ATTRIB -R WordDirectoryNORMAL.DOT > NUL"

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Latin Wife
Www Proxy Server
Vindu
TEKNIKPARTNER NORR AKTIEBOLAG
Handelsjuristen I GÖteborg Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com