Virus.MSWord.Lucifer
| Alert Level : | High |
| Discovered: | Mar 07 2000 |
| Tag: | Macro Viruses |
| Discoverer and Source: | http://www.kaspersky.com/ |
Malware Behavior and Technical Description
This is an encrypted Word macro virus. It contains three macros in documents: Close, Lucifer, AutoOpen. In NORMAL.DOT it contains six macros: AutoOpen, AutoClose, Close, ToolsMacro (stealth), FileTemplates, Lucifer.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are closed (AutoClose).
On 15th of any month the virus copies the C:\AUTOEXEC.BAT file to C:\AUTOEXEC.LUS and writes to AUTOEXEC.BAT the commands:
@Echo Off" CD\WINDOWS\" Ren *.dll *.lus" CD\WINDOWS\SYSTEM\" Ren *.dll *.lus" CD\" Ren C:\AUTOEXEC.LUS C:\AOTUEXEC.BATIt then displays the message and a BMP-picture:
Code Name : Lucifer Again!!!, from Darkside on Yogyakarta I'll cross your heart !! lucifer@Sulthans_Palace.comOn entering the Tools/Macro menu the virus displays the DialogBox:
Message from Lucifer We knew that the first WordMacro virus was created by McNamara. But, somebody tried to convince that he was the conceptor!! His name is: MILKY WAHYUDI WIDJAJA His speech like bullshit!! I'm the one of MV creator call him VIRUS CLAIMER, NOT VIRUS MAKER !! isn't he Phardera ? Greeting to Everyone Notice : this is not a virus, just a message don't kill me!!
0
Removal Virus.MSWord.Lucifer instructions:
0
Need help? Live computer support via remote at SupportSpace |

