|
|
Macro.Word97.ATU famil Viruses Information
| Name: |
Macro.Word97.ATU famil |
| Category: |
Viruses |
| Description:
|
Details
Macro.Word97.ATU family
The viruses of this family use an uncommon way of spreading. Instead of copying their macro program to the macro area in victim documents, they just write to documents a reference to a template (attached template) which contains virus macros. MS Word97 when opening a such document detects the reference to the attached template, opens it and executes its macros. The virus macro gets control and runs infected procedure. As a result the infected documents have no macro code, but on their opening the virus macro code is loaded by Word97 and executed.
In the known versions of this virus the reference to attached template points to a file on a remote Internet site (virus-writers Web site). As a result, MS Word97 on opening an affected document downloads and processes the template that is placed in the Internet zone. Because of that virus author(s) are able to "upgrade" virus code by replacing the template on their Web site.
This way of spreading allows the virus to bypass the anti-virus protection (VirusWarning) in old versions of MS Word97. These Word97 versions have a security breach: the anti-virus protection is not activated by Word97 to scan attached templates for macro code. This bug in MS Word97 was fixed in the beginning of 1999.
"ATU.b": this virus version does not copy entire code from the template to global macros area, but only the code necessary to infects documents.
The viruses contain the comments:
"ATU.a":
Active Template Update
"ATU.b":
Active Template Update v0.2 /1nternal |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Rch.113
Worm.P2P.Mandragor
AJ famil
Macro.Word.C
Kiss.67
Trojan.JS.Seeke
Gene.143
Andry.56
Win32.Cabana
AEP.62
|
|