home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Collection of Hack-Phreak Scene Programs
/
cleanhpvac.zip
/
cleanhpvac
/
CCTX0497.ZIP
/
MVUPDAT9.ZIP
/
SLOVDICT.ZIP
/
README.TXT
< prev
next >
Wrap
Text File
|
1997-03-10
|
3KB
|
71 lines
Nasty Lamer & Ugly Luser
proudly present
■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■
WordMacro.SlovakDictator virus
■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■
simply the best Word macro virus which has been ever written
the virus of the new generation ...
■■■■■■■■■■■■■■
Main features:
■■■■■■■■■■■■■■
- the first slovak macro virus !
- the first world true polymorphic virus !
Its body is mutated, each copy of the virus has a different size
- each copy of the virus is absolutely different !
It will be very hard to detect it by using signatures, because all
variables are fully mutated !
No typical virus signature !
No more exact macro virus detection !
- it doesn't use any commands for copying macros !
- known AV programs do not detect it !
- it fools all heuristics scanners !
- it uses LME (Lamer's Macro Engine) ver. 1.00 to generate polymorphic
macro viruses
- it uses special infection techniques !
- If AVers look at the source code of the virus, they will be shocked !
80% of the virus is internaly encrypted by a different encryption
constant !
■■■■■■■■■■
Infection:
■■■■■■■■■■
The virus contains only one unecrypted macro AutoClose. It infects all
documents or global templates while they are being closed.
No destructions or other actions ! (good for testing purposes)
Occassionally (every 4th and 11th day of each month) it displays a message
box with a virus warning.
It infects ONLY Word 7.x documents. Due to its special infection techniques
it isn't able to infect Word 8.0 documents.
The virus is language-dependent (it creates macro ...), tested with
the english version of Word 7.0 only (it works well).
■■■■■■■■■■■■■■
Disadvantages:
■■■■■■■■■■■■■■
- process of infection is very slow, it may take over 15 seconds on
a slow PC
- Although the virus prevents the ESC key from interrupting the macro,
pressing keys while the virus is running may cause a bug in creating
mutated names of variables and due this reason a bug in the executing
macro may occure. (it will be fixed in version for Word 8.0)
■■■■■■■■■■■■■■
Coming soon:
■■■■■■■■■■■■■■
LME (Lamer's Macro Engine) ver. x.xx for Word 8.0 (generating and creating
undetectable macro viruses !). This will be a real nightmare for all AVers !
■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■
(c) 1-mar-1997, Nasty Lamer & Ugly Luser
■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■