Free Web Hosting Provider - Web Hosting - E-commerce - High Speed Internet - Free Web Page
Search the Web

Database : WM.Nuclear
WM.Nuclear
Virus Name: WM.Nuclear
Aliases: None known
Type: MS Word macro virus
Resident: Yes, within Word environment
Stealth: No
Trigger: There are three different triggers for three different payloads. Only one works, as described below.
Payload:

The first time Word is started after infection at a time between 5pm and 5:59pm, a macro is run which attempts to infect the system with a DOS virus, Ph33r. Fortunately, the macro is corrupt and the attempt fails.

There is also a macro, called PayLoad, which on the 5th of April attempts to destroy important system files (IO.SYS, MSDOS.SYS and COMMAND.COM). This does not work fully either - only the IO.SYS file is destroyed.

The final trigger works. Each time a document is printed, there is a 1 in 12 chance that the virus will add the words:

And finally I would like to
say:
STOP ALL FRENCH NUCLEAR TESTING
IN THE PACIFIC

to the end of the document as it prints.

Comments:

WM.Nuclear is a destructive Word macro virus which is in the wild. It infects and spreads in the normal way - via an AutoOpen macro on infected documents which is run when the document is opened, infecting the NORMAL.DOT template.

It is fortunate that Nuclear's author did not have the equipment or the foolhardiness to test his creation - it could have been much worse.

Copyright © 2001, All Rights Reserved.
Created & Maintained by VQUEST.