Main Menu
Home
Bookmark
Contact Us



 
Macro.Word97.Metamorp Viruses Information

Name: Macro.Word97.Metamorp
Category: Viruses
Description: Details
Macro.Word97.Metamorph

It is a stealth macro virus. It contains five functions in documents in the one module "Metamorph": AutoOpen, FileTemplatesTemp, ToolsMacroTemp, ViewVBCodeTemp, AutoExecTemp. In the NORMAL.DOT the virus contains six functions in one random named module: FileSaveAs, AutoOpenTemp, FileTemplates, ToolsMacro, ViewVBCode, AutoExec. The name of this module is saved in the METAMORPH.INI file in section [Infected] in line Reponse.
The virus infects the global macros area on opening an infected document. Other documents get infection on saving with new name (FileSaveAs). The code of virus is different in documents and NORMAL.DOT - the virus modifies it while copying itself into the system. It creates new infection function FileSaveAs and stealth-functions ToolsMacro and ViewVBCode. While infecting documents the virus imports its original code from the C:METAPH.LOG which is created when the virus infects the system.
When Word starts the virus changes the names of menu items "File", "Edit", "View", "Format" with their french variants. Depending on the system date and time the virus displays the MessageBoxes:
Virus Metamorph
Attention, j'ai contaminé votre ordinateurall
Virus metamorph
Il est
L'heure de metamorph
Virus Metamorph
Au revoir...
Virus Metamorph
Poufffff!!!!!!

On displaying the last MessageBoxes the virus erases the files:
C:WindowsSystem*.*
C:WindowsCommand*.*
C:Windows*.Com
C:Dos*.*



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Enculator.108
Poem.182
Rabbit.
Win32.Sandman.409
Trojan-Downloader.JS.Mine
Konkoor.307
Green.103
MME-based viruse
Abba.9849.
Simbioz.33


 


© 2006-2008 spyware32.com - Privacy Policy