Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.UnderGroun Viruses Information

Name: Macro.Word.UnderGroun
Category: Viruses
Description: Details
Macro.Word.UnderGround

This is an encrypted macro virus. It contains two macros. Their names are Macro7 and AutoClose in NORMAL.DOT. In documents their names are randomly selected: , (for example: T45, E53).
The virus infects the documents that are closed (AutoClose). To infect the global macros area (NORMAL.DOT) on opening an infected document, the virus sets one of random named macros in document as the auto-macro. As a result, the macros in infected document do not have any auto-name, but they are executed while opening this document as the AutoOpen auto-macro.
While infecting the virus creates a temporary macro. While infecting the NORMAL.DOT the virus displays the MessageBox and asks a user for permission:
SoftWare UnderGround
Can I install myself into your NORMAL.DOT
[YES] [NO]

In case of "YES" the virus infects the NORMAL.DOT, displays the statistic information about current document and document author's name.



Top Viruses Visited Pages:
Invader. - 234 visits
not-a-virus:RiskWare.Tool.RegPatch. - 71 visits
Worm.P2P.Harex. - 65 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 59 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 47 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
OS2.MyNam
Tiddle
Macro.Word.Talon.
AllFools.65
Worm.Win32.Lovesan.
Fanthomas.144
TrojanDownloader.Win32.Dyfuca.
Gallery.63
I-Worm.Lovgate.a
Ichthum.102


 


© 2006-2008 spyware32.com - Privacy Policy