Main Menu
Home
Bookmark
Contact Us



 
Macro.Word97.Groovi Viruses Information

Name: Macro.Word97.Groovi
Category: Viruses
Description: Details
Macro.Word97.Groovie

This virus contains twenty macros in one module "Groovie": ID_Status, Install_Status, The_Groovie_Core, DocCodeCore, NormCodeCore, OrbitCoreCode, Groovie_Run, AutoOpen, AutoClose, AutoExit, FileSaveAs, filesave, fileclose, fileprint, IP_Love_You, mscript, viewvbcode, ToolsMacro, FileTemplates, Check_For_Doc.
The virus infects the system or documents when auto-macro is activated. It infects the system not only by infecting the NORMAL.DOT file, but also by creating the infected DATA.DOT file in the Word Startup directory. The DATA.DOT file contains module named ORBIT. While infecting the virus uses VBA export/import functions and save/read virus code to/from temporary C:GROOVIE.SYS file.
The virus deletes the menus "Tools/Macro" and "Tools/Templates and add-insall". On entering the ViewVBCode menu the virus displays the MessageBox:
ALT-F11 says...
It's GROOVIE

It also sets the "groovie" label on the C: drive. On Windows NT depending on the random number the virus tries to create machine IP configuration to the C:IP.TXT file and sends it to FTP server of FRISK International anti-virus company (F-PROT).



Top Viruses Visited Pages:
Baboo - 678 visits
Invader. - 540 visits
Firstling.199 - 265 visits
Macro.Excel.Hidemo - 241 visits
Spartak.110 - 237 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 233 visits
Coito.64 - 227 visits
Worm.P2P.Harex. - 227 visits
Small.58. - 217 visits
DDoS.Win32.Kozo - 199 visits

Random Viruses Pages:
I-Worm.Tanatos.
Candy.99
Exorcist Famil
Rape.2877.
Babe.158
Tula.41
OS2.MyNam
Bach.49
Bootache.204
Funeral Famil


 


2006-2008 spyware32.com - Privacy Policy