Virus Database


Macro.Word97.Nail.a

Description Macro.Word97.Nail.a

This macro virus spreads its copies through the E-mail. While replicating it sends opened (infected) document to everyone in the user's address book. It also sends a message to somebody at "chainnail@hotmail.com" that contains all addresses from user's address book and random selected message from the Inbox.
While infecting the virus does not copy its code into documents or templates, but writes to victim files reference to AUTO.DOT template (attached template, see "Macro.Word97.ATU". When Word opens such document, it looks for attached templates, and loads them. The virus' template AUTO.DOT is stored on a hacker's Internet Web site, and as a result the virus author can "upgrade" the main virus code at any time.
The virus code contains the comments:

Automated Chain Mail v0.1

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Apparition

Description Macro.Word.Apparition

This is quite a primitive virus. It is dropped by Windows EXE virus "Win.Apparition". It contains three macros: WWUpdated, AutoOp (AutoOpen), FileOpen.
WWUpdated is the virus ID-macro. The virus detects its presence in the system by using this name. Macro AutoOp (AutoOpen in NORMAL.DOT) installs the virus macros into the system on opening an infected file. Macro FileOpen infects files on opening.
The virus contains the text strings, but does not use them in any way:
Presence of AVP for winword
AVP for Winword is a nice tutorial
(C) 2 Rats Soft.
this macro loaded in normal template as FileOpen
AVPcopyright$ AVP for WinWord v1.0
sQuestion$ Would you like to

Macro.Word.Appder.a

Description Macro.Word.Appder.a

This Word macro virus contains two original macros, but while infecting documents copies them to three macros:
NORMAL.DOT Infected files
Appder -> Appder, AutoOpen
AutoClose AutoClose

The virus infects the global macros area on AutoOpen and writes itself to documents on AutoClose. It also creates the "NTTHNTA=value" line in the "[Microsoft Word]" section in WINWORD6.INI file and increases this value while infecting any document. When this value reaches 20, the virus deletes the files:
C:DOC*.EXE
C:DOC*.COM
C:WINDOWS*.EXE
C:WINDOWSSYSTEM*.TTF
C:WINDOWSSYSTEM*.FOT

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Salong Birath
Nacka Akustik Och Montage
GimsbÄrke Bil & Ac
Need For Speed Kommanditbolag
Lavett Creative Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com