Main Menu
Home
Bookmark
Contact Us



 
Macro.Word97.Jim. Viruses Information

Name: Macro.Word97.Jim.
Category: Viruses
Description: Details
Macro.Word97.Jim.b

Upon document closing, the virus checks running applications and if one of the following applications is found: Outlook, Internet Explorer or ICQ, the virus collects information about a computer and tries to send it to one of the FTP servers on the Internet.
The collected information includes:
First found .PWL file on drive C:
User name
Time document infected
Application
Country code
Free disk space
Generation of virus
Processor type
Operating system
The virus also searches for a Pegasus Mail application, and if it find one, it creates a message with an attached infected document.
If the MIRC client is installed on a computer, the virus drops a script that instructs MIRC to send an infected document to every computer joined to the same IRC channel as the infected computer.
The virus has a payload procedure that is triggered on second day of the month. This procedure inserts a text into the active document:
[Mr Jim/SeptiC/TI] - Do you have what it takes to become an international
bussiness man!?
[Mr Jim]/SeptiC/TI '99



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Exterminator.42
Macro.Word.Sido
Win95.Gara.91
Macro.Word97.FootPrin
HTML.Interna
FOG.AirRaid.172
VLAD.Tasha.203
VLAD.QMagick.43
I-Worm.Stapl
Win95.Chimera.154


 


© 2006-2008 spyware32.com - Privacy Policy