Macro.Word97.Trojan.Thief
Description Macro.Word97.Trojan.Thief
This Trojan uses remote template vulnerability of MS Word 97. The URL is sent to some IRC channels that contain a HTML file that automatically loads and opens an MS Word document that contains reference to another MS Word template-containing Trojan macro. MS Word opens this template without any warnings. This Trojan macro steals information from the system registry. It extracts the registered name and company of a Windows user, information about AOL users registered on this computer, and also account information of the Internet Account Manager. The collected information the Trojan sends to a site on the Internet.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.TheSecond
Description Macro.Word97.TheSecond
This Word97 macro-virus contains one macro, AutoClose, and as a result, it infects the system macro area and documents upon closing documents. Before a print of the document, the virus searches for a word Russian and replaces it on other word. After printing, it changes back. The virus contains the following copyright string: "The Second, 2000"
Macro.Word97.ThisDocument
Description Macro.Word97.ThisDocument
This virus contains six macros in one module "ThisDocument": AutoExec, AutoOpen, FileSaveAs, FileTemplates, ToolsMacro, ViewVBCode. The virus infects the global macros area on opening an infected document, and while infecting, the virus also exports its code to the C:THISDOC.LOG file and displays the MessageBox: Virus ThisDoc Attention, ThisDocument est infectÊall
The virus infects documents on saving them with a new name, and it also displays the following MessageBox while infecting: Virus ThisDoc Je suis une Nouvelle GÊnÊration de Virus de Macro...
On entering the Tools/Macro menu, the virus displays the MessageBox: Microsoft Word Erreur SystÉme Veuillez rÊessayer plus tard
On calling the ViewVBCode macro, it displays the MessageBox: Microsoft Word Ce programme a rÊalisÊ une opÊration illÊgale et va Ëtre interrompu.
On the 15th and any month, it displays the MessageBox: Virus ThisDoc ZeMacroKiller98 est heureux de vous prÊsenter sa nouvelle crÊation...
If the day number is equal to the hour, the virus displays the MessageBox: Virus ThisDoc Vos donnÊes vont Ëtre dÊtruites...
and erases the files: C:Windows*.INI C:Windows*.COM
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Gustaf Erikssons Recond Sempore I NykÖping Larsson, Magnus Envikens Bil O Motor Studio Q
|