|
|
Macro.Excel97.Papa. Viruses Information
| Name: |
Macro.Excel97.Papa. |
| Category: |
Viruses |
| Description:
|
Details
Macro.Excel97.Papa.a
This macro virus is based on the code of Word macro virus "Melissa" . The virus replicates under Excel97, but it does not infect other workbooks. Instead of this the worm sends own copies in Email messages by using MS Outlook. Because of its infection method, this is much more worm than ordinary macro virus.
The worm code contains one procedure Workbook_Open in module ThisDocument that automatically runs on opening workbook. To send its copies via email the virus uses VisualBasic abilities to activate other MS Windows applications and use their routines: the virus gets access to MS Outlook (if it is installed on the computer) and calls its functions. The virus gets from each Outlook address list of up to sixty addresses and sends to them a new message.
This massage has:
The subject: "Fwd: Workbook from all.net and Fred Cohen".
Message body: "Urgent info inside. Disregard macro warning."
The message also has attached workbook - it is current (worm's) workbook, and it is infected.
Depending on the system random counter (in one case from 3) the worm floods either web site "Fred Cohen & Associates" or site with IP address 24.1.84.100. |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Win32.Infinit
Changsh
Vindicator.73
Pcvrs.190
Goblin.175
Trojan-Spy.Win32.Briss.
Macro.Word.Tiny famil
Etop.70
KcVirus.123
LG.
|
|