Prevent Online Threats

Macro.Word97.Carrie

Details
Macro.Word97.Carrier

This virus contains three macros in one class “ThisDocument”: Document_Close, Document_New, Document_Open, and two in module “Agent”: AutoOpen, FileSaveAs.
The virus replicates on documents opening, closing or creating. The replication routine used Import/Export functions via the C:\NORMAL.BAS in case of NORMAL.DOT and C:\DOCUMENT.BAS file in case of documents.
The virus has the comment which is used to detect already infected files:
REM WRITTEN BY LORD ARZ

The virus sets the caption for all windows:
Infected by the Carrier virus (a trooper has already landed)

Related Posts

  • Macro.Word97. Appder, Cap, Concept, Czech, Muck,
  • ...
  • Macro.Word97.Apmr
  • ...
  • Macro.Word97.Claud
  • ...
  • Macro.Word97.Baw
  • ...
  • Macro.Word97.Minima
  • ...

    Leave a Reply


    Spyware Removal Spyware Protection Tools