|
|
Macro.Word.Scho Viruses Information
| Name: |
Macro.Word.Scho |
| Category: |
Viruses |
| Description:
|
Details
Macro.Word.Schoo
This is an encrypted virus. It contains 7 macros:
Documents NORMAL.DOT
GRBack GetRid
AutoOpen AutoOpen2
FileSave FileSave
VerIdent2 VerIdent
FileSaveAs FileSaveAs
BJTradeMark BJTradeMark
ToolsSpelling ToolsSpelling
It infects the global macros area on opening an infected document. It infects files that are saved with new name.
The virus adds new commands to Word auto-correction:
school -> schoo'
recognize -> reckonize
recognized -> reckonized
assembly -> assemily
CHS -> Crowley High Schoo'
Since 28 of May 1998 the virus displays many MessageBoxes, for example:
Microsoft Word Virus Alert
Warning: The 'Big Johnson' Virus has been detected.
On 28 may 1998 it display the MessageBox:
Microsoft Word Virus Alert
Transferring control to virus subroutine:
Virus initializingall
It's the last day of school!
On all following days it displays the MessageBox:
Microsoft Word Virus Alert
Transferring control to virus subroutine:
Virus initializing...
School's out! |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
IRC-Worm.Claw.251
Backdoor.Win32.Surila.
Slavery.92
Companion.26
Trojan.Win32.Antige
Coconut.132
ArjViru
Macro.Word.Co
Armagedon.20
Macro.Word97.Trojan.Tvangest
|
|