|
|
Macro.Word.Vicinit Viruses Information
| Name: |
Macro.Word.Vicinit |
| Category: |
Viruses |
| Description:
|
Details
Macro.Word.Vicinity
This is an encrypted Word macro virus. It contains three macros: AutoOpen, ExtrasMakro (stealth), QuickSilver. The virus replicates itself when documents are opened (AutoOpen).
The virus replaces the Tools/Macro menu, if there is no text "MFake = no" in the WIN.INI file in the [QuiteVicinity.02] section. If Windows 3.1 is installed, the virus creates the C:SYSLOG1.BAT file and writes to there the command that resets the ReadOnly attribute for some file. The virus then writes the commands to the AUTOEXEC.BAT file:
echo off
call c:syslog1.bat
The virus displays the MessageBox:
Microsoft Word 1.0
Zur Zeit ist keine Dokumentvorlage aktiviert !
Starting from 1997 January 15 the virus searches and replaces: ". SAP" -> ". S+P", "%%%7%%%" -> "%%%8%%%".
Starting from 1997 June 15 the virus creates the C:BOOTLOG.BAT file that is called by AUTOEXEC.BAT and writes the commands to there:
if exist c:w95guardwgfe.exe del c:w95guardwgfe.exe
if exist c:winguardwgfe.exe del c:winguardwgfe.exe
Starting from 1997 August 15 the virus creates the C:SYSLOG2.BAT file with the commands:
echo Datenmuell >> c:netstat.con
attrib -R c:netstat.con
type c:netstat.con >> c:netstat.con |
Top Viruses Visited Pages:
Invader. - 231 visits
not-a-virus:RiskWare.Tool.RegPatch. - 69 visits
Worm.P2P.Harex. - 63 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 55 visits
Small.58. - 55 visits
Coito.64 - 53 visits
I-Worm.Mapson. - 45 visits
Win16.Klon.1177 - 41 visits
Win32.Hidra - 41 visits
Marine.500 - 34 visits
Random Viruses Pages:
Areopag.48
Win32.Rhapsody.260
Syrian Famil
MH.149
not-a-virus:Cracke
Win32.Vampiro.701
Net-Worm.Win32.Mytob.b
Forever.91
Macro.Word.Counte
Win95.Murkry.39
|
|