Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.Hunter. Viruses Information

Name: Macro.Word.Hunter.
Category: Viruses
Description: Details
Macro.Word.Hunter.a

These are encrypted German-specific macro viruses. They contain three macros: AutoOpen, DateiNeu, ExtrasMakro. The viruses do not use any copy-macros function to spread themselves. To infect the system they save an infected document to the Winword startup directory with the name:
"Hunter.a": WINWORD.DOT
"Hunter.a,b": AutoStrt

The viruses then register that file as "Add-In" template.
The viruses infect the documents on DateiNeu (FileNew) call. They create new document, insert the infected Add-In and clean its contents. As a result on creating new file the virus loads already infected clean file (template).
The ExtrasMakro (ToolsMacro) macro is used to hide virus macros in infected system.
"Hunter.a,b" depending on the system timer display the MessageBox:

One - You lock the target
Two - You bait the line
Three - You slowly spread the net
And four - You catch the man

"Hunter.c" depending on the system timer inserts into its macros random selected strings.
The virus contains the commented texts, the second line contains different version numbers and dates in viruses:
********************************************************************
*** by Neurobasher, 17.10.1995, Germany ***
*** Boring experimental Winword virus with minor retro & stealth ***
********************************************************************
*** "I'm looking for a man who knows the rules of the game" ***
*** "Who's able to forget them to realize my aim" ***
********************************************************************



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
I-Worm.MyLife.
Riot multipartit
Quox.
VLAD.Dir.75
Backdoor.SdBot.ge
Nomad.888.
Goga.166
TrojanDropper.Win32.ExeBundl
Win95.Vip.429
Sojourn.136


 


© 2006-2008 spyware32.com - Privacy Policy