02.08.2013 Views

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

PC<br />

WEED - v1.0<br />

VARIANT:HLLP.5850<br />

MS-DOS/PC-DOS Computer <strong>Virus</strong>es<br />

This is a minor variant of the HLLP.3263 (Weed) virus. This version displays a starfield on the<br />

screen.<br />

HLLP.5850 displays this text:<br />

I need milk. My flakes toas<br />

Name: Hooter<br />

Aliases: Hooter, Hooter.4676, HLLP.4676, HLLP.Hooter Type: Program.<br />

Disk Location: EXE application.<br />

COM application.<br />

Features: Deletes or moves files.<br />

Damage: Deletes or moves<br />

files.<br />

Size: 4676 See Also:<br />

Notes: While searching for files to infect, the virus deletes files that match the filters: chklst.* and<br />

anti-vir.dat<br />

The virus creates a file named HOOTERS.EXE when decrypting itself. It deletes this file before<br />

ending.<br />

It triggers if it can not find any files to infect. Depending on the clock, it may display the following<br />

message:<br />

"Hooters, hooters, yum, yum, yum. Hooters, hooters, on a girl that’s dumb. - Al Bundy."<br />

Infected files, including Windows files, appear as DOS executables after infection and are run as<br />

DOS applications.<br />

Infected files also contain the following text: "Wow - you’ve found the hidden message (like it’s<br />

hard!) Made in Auckland, New Zealand, in 1996. Contains the greatest saying of all time.<br />

Dedicated to the few truly great pairs of luscious hooters."<br />

See the <strong>Virus</strong> Bulletin 1/97 for an analysis.<br />

Name: Horror<br />

Aliases: Horror Type: Program.<br />

Encrypted/Stealth The virus<br />

actively hides.<br />

Disk Location: COM application.<br />

Features: Unknown, not analyzed yet.<br />

EXE application.<br />

Damage: Unknown, not<br />

analyzed yet.<br />

Notes:<br />

Size: 1112<br />

1137<br />

1182<br />

See Also:<br />

210 CIAC Computer <strong>Virus</strong> <strong>Information</strong> Update May 21, 1998

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!