Virus.MSWord.Xute

Class Virus
Platform MSWord
Description

Technical Details


The virus contains one macro “AutoClose” in module “Xute”. It replicates on
closing documents by exporting/importing its code through the C:XUTE.DAT
file. On July 26th, or if the sum of the day and month numbers is equal to
30, the virus executes the file deleting command “DELTREE /Y *.*”.


All text constants (export file name, DELTREE command etc.) are stored in
the virus code in encrypted form. In case of need, the virus decrypts and
uses them.

Find out the statistics of the threats spreading in your region