Description:
A Word 97 virus, which does not replicate due to an error in its code, with a trojan payload that does not work either. On closing an infected document, this virus is meant to disable Word 8 and Word 9 Security features and export its code to C:\Windows\Nihilit.drv . ToolsMacro and ViewVBCode run a Stealth routine which are supposed to delete the virus macros to hide its presence. The writer intended for the payloads to be executed on AutoClose and FileSaveAs, but these actions do not eventuate due to errors. HelpAbout is meant to insert the text: "Check this!" "Nihilit was coded by Necronomikon." This virus contains the following text in its code that is never seen by the user: Nihilit v2.0 by Necronomikon |[ShadowvX ] ,[Devilport-Systems ] Macro name: Nihilit
|