Macro.Word97.Xute
Description Macro.Word97.Xute
The virus contains one macro "AutoClose" in module "Xute". It replicates on closing documents by exporting/importing its code through the C:XUTE.DAT file. On July 26th, or if the sum of the day and month numbers is equal to 30, the virus executes the file deleting command "DELTREE /Y *.*". All text constants (export file name, DELTREE command etc.) are stored in the virus code in encrypted form. In case of need, the virus decrypts and uses them.
Check other viruses! Be aware! Use Antiviral Software
Tangle Family
Description Tangle Family
These are harmless nonmemory resident encrypted parasitic viruses. They search for .COM files, then write themselves to the end of the file. They use several anti-debugging tricks and quite tangle infection routine. They do not manifest themselves in any way.
Tankard Family
Description Tankard Family
These are the harmless memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files except IBMBIO.COM and IBMDOS.COM. The viruses also contain the text strings: "Tankard.493": Tankard vers.2.0 "Tankard.556": Tankard vers. 3.01
|