Virus Database


Macro.Word97.Oetzi

Description Macro.Word97.Oetzi

It is a polymorphic virus. It contains eight macros in module "Modul1": AutoOpen, AutoClose, FileSaveAs, FileSave, ToolsCustomize, Mutate, Retro, Payload. It replicates on activation any of macros: AutoOpen, AutoClose, FileSaveAs, FileSave. The virus polymorphic engine inserts comments at random positions in the virus code.
The virus displays the Balloon:
Wichtig! Lesen sie folgendes genau durch:
He Bedienung! 5 Bier! Auch einen für diesen Schnapsgsicht daall. Danke!

The virus then displays the MessageBox:
W97M.Oetzi.A
Hallo, mein name ist Ötzi. Ihr könnt mich mal besuchen kommen. Für 8-9
Cuba Libre laß ich euch vielleicht gratis rein. UEO!!!
NEGSTE BUDE = 500m !!!!!!

It also erases the anti-virus files:
C:PC-Cillin 95Scan32.dll
c:pc-cil~1*.dll
C:PC-Cillin 95Lpt$vpn.*
C:PC-Cillin 97Scan32.dll
C:PC-Cillin 97Lpt$vpn.*
C:TscPC-Cillin 97Scan32.dll
c: scpc-cil~1*.dll
C:TscPC-Cillin 97Lpt$vpn.*
C:TBAVW95Tbscan.sig
c:Tbavw95Tb*.*
C:Tbavw95Tbavw95.vxd

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Dot666

Description Macro.Word.Dot666

This is a polymorphic German specific macro virus. It does not manifest itself in any way. It contains three macros: AutoClose, ExtrasMakro, DateiDokVorlagen.
AutoClose is auto-macro that is executed on closing any file. The virus uses that hook to replicate itself on documents closing. ExtrasMakro and DateiDokVorlagen are macros viewing/editing functions (File/Templates, Tools/Macro) in German MS Word, they are stealth virus routines.
The virus has quite unusual stealth mechanism. On infecting the global macros area it copies to NORMAL.DOT just one AutoClose macro. Two other macros are written to the 666.DOT file that is placed in the Word startup directory. When any of these macros takes control (on entering File/Templates or Tools/Macro) the virus temporary moves its AutoClose from NORMAL.DOT to the 666.DOT file. On leaving these functions the virus restores AutoClose macro in the NORMAL.DOT. Thereby, the virus protects itself from finding (stealth).
On each replication the virus runs its polymorphic mutation engine. It randomly changes names of all virus variables and functions.

Macro.Word.Dracula

Description Macro.Word.Dracula

This is an encrypted Word macro virus. It contains six macros: AutoExec, AutoOpen, FileSave, FilePrint, FileSaveAs, ToolsMacro (stealth). The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are saved (FileSave, FileSaveAs).
Starting from Jule 4th 1997 while printing a document the virus inserts the string "c Dr. Acula" and sets the password "da". On entering the ToolsMacro menu the virus removes all macros from the current document.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Invicta
Transport
Gourmet Desserts
Kinderspielzeug
Jacob Janssens StÄd Och FÖnsterputs Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com