Virus Database


Macro.Word97.Trojan.Thief

Description Macro.Word97.Trojan.Thief

This Trojan uses remote template vulnerability of MS Word 97. The URL is sent to some IRC channels that contain a HTML file that automatically loads and opens an MS Word document that contains reference to another MS Word template-containing Trojan macro. MS Word opens this template without any warnings.
This Trojan macro steals information from the system registry. It extracts the registered name and company of a Windows user, information about AOL users registered on this computer, and also account information of the Internet Account Manager. The collected information the Trojan sends to a site on the Internet.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.TheSecond

Description Macro.Word97.TheSecond

This Word97 macro-virus contains one macro, AutoClose, and as a result, it infects the system macro area and documents upon closing documents. Before a print of the document, the virus searches for a word Russian and replaces it on other word. After printing, it changes back.
The virus contains the following copyright string:
"The Second, 2000"

Macro.Word97.ThisDocument

Description Macro.Word97.ThisDocument

This virus contains six macros in one module "ThisDocument": AutoExec, AutoOpen, FileSaveAs, FileTemplates, ToolsMacro, ViewVBCode.
The virus infects the global macros area on opening an infected document, and while infecting, the virus also exports its code to the C:THISDOC.LOG file and displays the MessageBox:
Virus ThisDoc
Attention, ThisDocument est infectÊall

The virus infects documents on saving them with a new name, and it also displays the following MessageBox while infecting:
Virus ThisDoc
Je suis une Nouvelle GÊnÊration de Virus de Macro...

On entering the Tools/Macro menu, the virus displays the MessageBox:
Microsoft Word
Erreur SystÉme
Veuillez rÊessayer plus tard

On calling the ViewVBCode macro, it displays the MessageBox:
Microsoft Word
Ce programme a rÊalisÊ une opÊration illÊgale et va Ëtre interrompu.

On the 15th and any month, it displays the MessageBox:
Virus ThisDoc
ZeMacroKiller98 est heureux de vous prÊsenter sa nouvelle crÊation...

If the day number is equal to the hour, the virus displays the MessageBox:
Virus ThisDoc
Vos donnÊes vont Ëtre dÊtruites...

and erases the files:
C:Windows*.INI
C:Windows*.COM

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Gustaf Erikssons Recond
Sempore I NykÖping
Larsson, Magnus
Envikens Bil O Motor
Studio Q

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com