|
|
Macro.Word.Showof Viruses Information
| Name: |
Macro.Word.Showof |
| Category: |
Viruses |
| Description:
|
Details
Macro.Word.Showoff
text (c) Michal A. Egler
This virus contains the following encrypted macros: Hayo, AutoOpen, Nomercy2, Organizer, ToolsMacro, FileTemplates.
On the 13th day of any month the virus creates the file C:WINDOWSSYSTEMNOMERCY.DLL. This file contains a debug script with the NoMercy.575 DOS parasitic virus dump code. By using this script the virus creates the virus dropper NOMERCY2.COM.
Next the virus deletes files:
C:*.BAT
C:*.SYS
C:WINDOWS*.GRP
C:WINDOWS*.DRV
C:WINDOWS*.DLL
C:WINDOWSSYSTEM*.DRV
C:WINDOWSSYSTEM*.DLL
It also inserts the following commands into the AUTOEXEC.BAT file to execute the virus dropper:
@echo off
nomercy2.com
After restarting the computer the virus code stays resident and infects each executed COM and EXE file.
The virus displays a UserDialog containing the text:
No Mercy II [Hell on WinWord], The Madness Continuesall..
wall
NoMercy II ©1997 by CrazybitS
From the land of Smoking Vulcanoes and Gamelan Orchestras
This Macro Virus Was Released for follow his brother No Mercy
Sometimes the virus changes names of macros:
Nomercy = AutoOpen
AutoClose = Nomercy2
AutoExec = Hayo
ToolsMacro = ToolsMacro
Organizer = Organizer
FileTemplates = FileTemplates
Sometimes the virus displays a UserDialog with the text:
No Mercy II Was Distrub !
Mmmmm.... you just lost your files !
Don't do it again ! |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Goblin.175
Ghh.48
MusicBu
Signed Famil
Pages Famil
VBScript.77
Arianna.337
Macro.Word.Ech
BAT.8Fis
Macro.Word.Berti
|
|