TestWorm
Description TestWorm
This is encrypted worm virus affecting Tornado BBS (Bulletin Board System). Being run on a machine that has Tornado BBS software installed the worm looks for BBS system file, gets Download directory and FileList file names. The worm then copies itself to Download directory with TESTWORM.COM name, and creates reference to that file in FileList (usually that is the FILES.BBS file). The reference contains the fake text: Internet cracker (NEW) The worm also contains the text: Misdirected Youth
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Oragon
Description Macro.Word97.Oragon
This macro virus infects MS Word documents as they are closed. The code contains the following text string: ORAGON When an MS Word document is closed, the virus copies its code to all open documents and the normal.dot template. The virus contains an internal infection count and increases it by 1 every time it infects a document. It adds blank lines to the end of its macro; the number of blank lines is the number of files infected. It also turns off the Tools/Macro menu so the user will be unable to detect that the virus is present in the document. On the 1st of every month, it changes the header of the current document window to the name of the system user and attempts to start the Office Assistant application.
Macro.Word97.Osm
Description Macro.Word97.Osm
This is a stealth companion macro virus. It contains two modules "NewMacros" and "dlgMyMacs". It does not infect the global macros area and documents in ordinary way. On document saving the virus copies infected template to the document's folder and attaches this template to the document. Next time this document is being opened, the infected template will be automatically loaded by MS Word. On first run on the computer the virus also creates in MS Word startup folder the infected template Startup.dot. This template is automatically activated when MS Word starts. Also only on first run the virus drops on the A: drive, and executes a Windows executable file that contains the "Back Orifice Trojan" which is additionally infected with "Win95.Marburg" virus. If there is no disk in drive A: MS Word can trap on incorrect operation. The virus replaces standard ToolsMacros dialog box by its own empty one (stealth).
|