Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.ShareFu Viruses Information

Name: Macro.Word.ShareFu
Category: Viruses
Description: Details
Macro.Word.ShareFun

This encrypted Word macro virus contains nine macros:
AutoExec - does nothing
autoOpen - infects current document or global macros area
FileClose - -//-
FileExit - -//-
FileSave - -//-
FileOpen - -//-
FileTemplates - -//-
ToolsMacro - -//-, disables Tools/Macro menu (stealth)
ShareTheFun - trigger routine

It infects the system and documents on opening, closing and accessing Tools/Macro menu. It manifests itself in very unusual way - it sends infected documents via MicrosoftMail, if it is installed.
On opening a document or template (AutoOpen) the virus with probability 1/4 calls the ShareTheFun macro. This macro saves the current (already infected) document to the C:DOC1.DOC file, activates Microsoft Mail by WordBasic instruction AppActivate, gets three random selected addresses from addresses list and sends them the infected C:DOC1.DOC file with the subject line:
You have GOT to read this!

If Microsoft Mail is not included in the running tasks, the virus shuts down Windows.



Top Viruses Visited Pages:
Invader. - 233 visits
not-a-virus:RiskWare.Tool.RegPatch. - 70 visits
Worm.P2P.Harex. - 65 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 59 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 47 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
CheckSum Famil
Bastard.197
Macro.Word.KillDo
Trojan.Win32.FireAnvi
Worm.P2P.Lolol.
Nic
Vortex.Elvis.98
Porridge.138
Tremo
Terminator.327


 


© 2006-2008 spyware32.com - Privacy Policy