|
|
Macro.Excel97.Phanto Viruses Information
| Name: |
Macro.Excel97.Phanto |
| Category: |
Viruses |
| Description:
|
Details
Macro.Excel97.Phantom
This is a stealth Excel97 macro-virus. It infects Excel97 spreadsheets (XLS-files). The virus contains two modules: ArtiLife and Replicator. The ArtiLife module contains the auto-function "auto_open". When an infected sheet is opened, the "auto_open" function takes control, infects Excel and sets the DeliverPayload function on execution at 16:00:00. While infecting Excel, the virus creates the infected ~XL.XLA in the Excel Start-up Path directory.
The virus is quite an unusual for macro-viruses: it has a parasitic-virus-like stealth mechanism - the virus removes its modules from sheets upon opening them and infects them again upon closing.
The DeliverPayload that is executed at 16:00 outputs the texts to the StatusBar:
The Phantom
Is watching you!
Beware! |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Rest.158
I-Worm.Lodin
I-Worm.Unis.
Kadavr.50
Uck.47
Win32.IKX.100
Trojan.Sabi
CopCom.28
Datacrime.148
Steatoda famil
|
|