Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.Showof Viruses Information

Name: Macro.Word.Showof
Category: Viruses
Description: Details
Macro.Word.Showoff

text (c) Michal A. Egler
This virus contains the following encrypted macros: Hayo, AutoOpen, Nomercy2, Organizer, ToolsMacro, FileTemplates.
On the 13th day of any month the virus creates the file C:WINDOWSSYSTEMNOMERCY.DLL. This file contains a debug script with the NoMercy.575 DOS parasitic virus dump code. By using this script the virus creates the virus dropper NOMERCY2.COM.
Next the virus deletes files:
C:*.BAT
C:*.SYS
C:WINDOWS*.GRP
C:WINDOWS*.DRV
C:WINDOWS*.DLL
C:WINDOWSSYSTEM*.DRV
C:WINDOWSSYSTEM*.DLL

It also inserts the following commands into the AUTOEXEC.BAT file to execute the virus dropper:
@echo off
nomercy2.com

After restarting the computer the virus code stays resident and infects each executed COM and EXE file.
The virus displays a UserDialog containing the text:
No Mercy II [Hell on WinWord], The Madness Continuesall..
wall
NoMercy II ©1997 by CrazybitS
From the land of Smoking Vulcanoes and Gamelan Orchestras
This Macro Virus Was Released for follow his brother No Mercy

Sometimes the virus changes names of macros:
Nomercy = AutoOpen
AutoClose = Nomercy2
AutoExec = Hayo
ToolsMacro = ToolsMacro
Organizer = Organizer
FileTemplates = FileTemplates

Sometimes the virus displays a UserDialog with the text:
No Mercy II Was Distrub !
Mmmmm.... you just lost your files !
Don't do it again !



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Goblin.175
Ghh.48
MusicBu
Signed Famil
Pages Famil
VBScript.77
Arianna.337
Macro.Word.Ech
BAT.8Fis
Macro.Word.Berti


 


© 2006-2008 spyware32.com - Privacy Policy