Macro.Word97.Cryptor
Description Macro.Word97.Cryptor
This virus contains six macros in module "CryptorV97": AutoOpen, AutoClose, FileSaveAs, FileTemplates, ToolsMacro, ViewVBCode. It infects the global macro area on opening an infected document and infects documents on saving with new name. The virus disables Word virus protection. On odd days the virus encrypts the document contents. After infecting NORMAL.DOT or a document it displays corresponding MessageBox: Virus CryptorV97 Virus CryptorV97 Attention, modèle normal crypté ???? ZeMacroKiller98 vous remercieall On entering the menu items "Tools/Templates and Add-Ins...", "Tools/Macro" and "Tools/Macro/Visual Basic Editor" the virus displays corresponding MessageBox: Microsoft Word Espace pile insuffisant. Microsoft Word Fonction Sub non défini Microsoft Word Ce programme a réalisé une opération illégale et va être interrompu.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.ZMK.J
Description Macro.Word97.ZMK.J
Analysis by and (c) Paolo Monti This macro-virus was written in VBA (Visual Basic for Applications) for MS Word 8.0 (Office 97). It contains very dangerous payloads, and it displays message and dialogue boxes concerning the World Cup Soccer Championship France 98. The VBA project of the virus contains one form named Pronostic and a module implementing 8 different macros: AutoExec: calls the macro Pronostique or WC98Payload (see below). AutoOpen: infects the global template and displays a messagebox. FileSaveAs: infects new documents, saving them as templates, and displays a messagebox. FileTemplates: displays a messagebox. Pronostique: displays a dialogue box where the user is forced to make a choice, and implements a number of different payloads. ToolsMacro: displays a messagebox, ViewVBCode: shows the MS Word Assistant displaying a message, WC98Payload: modifies the contents of an active document. The following instructions can be found at the beginning of all macros: Disable the possibility to interrupt macro execution Enable the execution of automatic macros Disable the antivirus protection built in Ms Word Disable the confirmation for the global template saving, usually asked before exiting from the program. The automatic macro AutoExec, executed at the startup of MS Word or when a general template is loaded, gets the current system date and time. If the day number is 12 or the seconds of the system clock are at 12, the AutoExec macro calls the macro Pronostique or the macro WC98Payload. The choice between the two macros is applied randomly. Each has a 50% probability to be called from AutoExec macro. The macro Pronostique displays a dialogue box on the screen (the form Pronostic) by which the user is asked to choose among 9 different teams partecipating in the France 98 Championship. If the user chooses the same team selected randomly by the virus, a messagebox of congratulations is displayed on the screen, then the virus goes into an endless loop showing a message in the status bar. Otherwise, the virus applies a randomly selected payload. With a probability of 40%, the virus appends the following lines to the file C:AUTOEXEC.BAT: cls Echo La coupe du monde 98 c'est gÊnial!!!! Echo y|Format c: /u /v:WorldCup98 Echo o|Format c: /u /v:WorldCup98
27% of the time, the virus tries to delete all files in the directories C:DOS and C:WINDOWSCOMMAND and the files C:MSDOS.SYS and C:IO.SYS. In the remaining cases, the virus modifies the text of the active document and prints it. The macro WC98Payload creates in the active document a WordArt object, applies to it a number of rotation effects, and then erases it. Inside the project of the virus there are some messages in French: "VIVE LA COUPE DU MONDE 98!!!!" "Vive le football!!!, Vive la Coupe du Monde 98!!!"
AVP detects/disinfects this virus since weekly update 980706
Macro01.2170
Description Macro01.2170
It is not a dangerous memory resident parasitic virus. It hooks INT 13h, 28h and on INT 28h calls searches for COM- and EXE-files, and then writes itself to the end of the file. Depending on its internal counters the virus decrypts and displays the messages: CRIS-HARDWARE Ai un virus foarte rau Pentru anti-virus scrieti la FAC. de CALCULATOARE din TIMISOARA Daca in 20 de secunde nu opresti PC-ul am sa-ti fac praf HARD-DISKUL
The virus also contains the ID-string: Macro01
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
O-m MiljÖbygg Aktiebolag Halmstad Cleaner Teknik Hair Today Jessica Salong I Huskvarna Sexti5tretti Ab
|