Main Menu
Home
Bookmark
Contact Us



 
Macro.Word97.Mam Viruses Information

Name: Macro.Word97.Mam
Category: Viruses
Description: Details
Macro.Word97.Mamm

This stealth macro virus contains one empty module "MAMM" and eighteen procedures in module "aviro": AstMaster, Mhapus, Mcopy, Action, FileOpen, AutoOpen, ViewVbCode, AutoExec, AutoExit, ToolsMacro, FileTemplates, FormatStyle, Refresh, AutoClose, FileExit, ToolsOptions, WBT, WBF.
It infects the global macros area on opening an infected document. The virus also creates in MS Word startup folder two infected files:
MAMM.dot
MAMM.src

On each document opening the virus checks all already opened documents and infects them. It also infects documents on their closing.
Starting from 15 May 1998 the virus activates its payload procedure. It sets its call on time 45 minutes after document opening. Payload procedure only displays the message box:
To: MAMM
If you delete this, you have no heart

The virus hooks menus "ToolsMacroMacrosall" and "ToolsMacroVisual Basic Editor". On click of these menus the virus displays "Record Macro" dialog box with macro description:
'If you delete this, you have no heart'



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Win32.InvictusDLL.200.
Turner.327
Hell.112
Osiris.29
Tiso.94
Flash Famil
KPI.32
Win32.HLLW.Scare
Marzia.2048.WW.
Trojan-Downloader.Win32.VB.j


 


© 2006-2008 spyware32.com - Privacy Policy