Rut

Threat description

Details

CATEGORYMalware
TYPEVirus

Summary

W97M/Rut is a Word 97 macro virus.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details


Variant:Rut.A

When an infected document is opened, W97M/Rut.A infects the global template. After that every document that is saved is infected.

During infection, the virus might cause Visual Basic compile errors. Anyway, the virus will still be able to replicate.

The virus activates its payload in every 10th, 18th and 27th day of the month. At this time it displays a dialog with the following text:

Created by F?D         DVD version 1.0         (C)opyright 1997  

This dialog contains two buttons as well. If user selects the "OK" button, no further action is taken. However, if "About" button is selected, the virus asks user to enter a text string which is either

I LOVE HD-LWP  

or

DJAJA HD-LWP is Good  

depending the number of the seconds. If the string is entered correctly, the virus displays yet another message box with the text:

    Terima kasih telah mengetikkan dengan  benar.       Saya dedikasikan kreasi saya ini untuk HD- LWP. Semoga HD-LWP       selalu dilindungi oleh-Nya.  Jangan takut DVD tidak akan merusak data       Anda, apalagi sampai menghapusnya. DVD hanya akan mejeng setiap       tanggal-tanggal tertentu saja.  Created by F?D  

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info