Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.Nomvi Viruses Information

Name: Macro.Word.Nomvi
Category: Viruses
Description: Details
Macro.Word.Nomvir

This is a very dangerous virus. It contains ten macros: AutoExec, AutoNew, AutoOpen, DateiSpeichern, DateiSpeichernUnter, DateiBeenden, ExtrasOptionen, DateiDokvorlagen, FuckIt, and DateiDrucken.
Upon AutoNew and AutoExec, it infects the global macros area. Upon DateiSpeichern and DateiSpeichernUnter (FileSave, FileSaveAs), it infects a document.
The virus looks for the "Nomvir=" parameter in the "Compatibility" section (WIN.INI file), and does not perform any action if there is "Nomvir=0x0690690". The virus also creates a counter "iCount" in the "intl" section, and increases it when any document is printed. Depending on the counter, the virus deletes the C:AUTOEXEC.BAT and C:CONFIG.SYS files. Depending on the system date, the virus replaces some words in documents with "hell" or appends to the end of the document the following text:
Fuck Microsoft & Bill Gates

On January 1st, December 25th, on the 23rd of any month, and on Saturday 13th, it deletes the following files:
C:WINDOWSUSER.DA0
C:WINDOWSSYSTEM.DA0
C:WINDOWSUSER.DAT
C:WINDOWSSYSTEM.DAT

Depending on the system time, the virus sets randomly selected passwords for documents. Upon accessing Tools/Macro and the DateiDokvorlagen menu, the virus displays the MessageBoxes:
Nicht genügend Arbeitsspeicher !
Interner Fehler !



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Trojan.Win9x.Angrif
Ghost_2.500
Pcflu.214
Apri
DeathBoy.91
Exorcist Famil
Viva.70
Macro.Word.Pi
DirII.TheHndv.
Trojan.HTML.Probo


 


© 2006-2008 spyware32.com - Privacy Policy