<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Prevent Online Threats</title>
	<atom:link href="http://www.preventonlinethreats.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.preventonlinethreats.com</link>
	<description>Educate yourself on what you can do to prevent online threats</description>
	<pubDate>Wed, 05 May 2010 03:41:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Macro.Word.Doggie</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-doggie/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-doggie/#comments</comments>
		<pubDate>Sat, 24 Jan 2009 00:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5971</guid>
		<description><![CDATA[Details
Macro.Word.Doggie.a
This macro virus contains three macros: Doggie, AutoOpen and FileSaveAs. It display the message box with the text &#8220;Doggie&#8221;.
]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-doggie/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Buer</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-buer/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-buer/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 20:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5970</guid>
		<description><![CDATA[Details
Macro.Word.Buero
This is an encrypted virus. It contains two macros:
NORMAL.DOT      Infected files
DateiSpeichern  AutoOpen
BuroNeu         BuroNeu
This virus infects the system on AutoOpen and writes itself to files on FileSave (DateiSpeichern).
If the current date is above than 15.8.96, the virus renames the system file IO.SYS [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-buer/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Breede</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-breede/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-breede/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 16:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5969</guid>
		<description><![CDATA[Details
Macro.Word.Breeder
The virus contains one macro &#8220;AutoOpen&#8221; in documents and infects the global macros area on opening an infected document. In NORMAL.DOT this macro is renamed to &#8220;FileSave&#8221; and the virus infects the files that are saved. The virus does not manifest itself in any way, it contains the comments:
BREEDER BY -=>NEMESIS]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-breede/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Box</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-box/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-box/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 12:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5968</guid>
		<description><![CDATA[Details
Macro.Word.Box.a
This macro virus contains seven macros: AutoOpen, AutoClose, Box, Dead, FilePrint, FilePrintDefault, ToolsMacro. On AutoOpen and AutoClose the virus infects the global macros and documents. ToolsMacro macro is used to disable Tools/Macro menu. Other macros contain infection and trigger routines.
The virus manifests itself in several ways. It inserts a text in Chinese into documents that [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-box/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Boo</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-boo/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-boo/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 08:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5967</guid>
		<description><![CDATA[Details
Macro.Word.Boom
This virus is encrypted, it contains four macros: AutoOpen, DateiSpeichernUnter, System, AutoExec. It infects the system on opening an infected file (AutoOpen) and documents that are saved by FileSaveAs (DateiSpeichernUnter).
On MS Word startup (AutoExec) the virus sets the System macro as triggered at 13:13:13. At this time MS Word calls this macro and the virus [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-boo/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Boogi</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-boogi/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-boogi/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 04:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5966</guid>
		<description><![CDATA[Details
Macro.Word.Boogie
This macro virus contains four macros:
Documents     NORMAL.DOT
vExit         FileExit
vFSav         FileSaveAs
vMacro        ToolsMacro
AutoOpen      Boogie
The virus infects the global macros area on opening an infected document (AutoOpen). [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-boogi/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Bon</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-bon/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-bon/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 00:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5965</guid>
		<description><![CDATA[Details
Macro.Word.Bond
This is a silly macro virus. It contains three macros that have very close code: AutoClose, BONE, BOND. The virus replicates on document&#8217;s closing. It displays the MessageBox:
Any  Problem ?   Call  Mr.BoND,   OkEmi  ThanK  U
]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-bon/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.Blas</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-blas/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-blas/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 20:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5964</guid>
		<description><![CDATA[Details
Macro.Word.Blash
This is an extremely short Word macro virus. It contain only one macro AutoOpen and replicates itself on opening a document. It writes the string to the Subject field in document FileSummaryInfo:
DEMONS STRIDE AT THE GATE OF BLASHYRKH
]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-blas/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.BlackEn</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-blacken/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-blacken/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 16:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5963</guid>
		<description><![CDATA[Details
Macro.Word.BlackEnd
This is an encrypted virus, it contains five macros: BlackEnd, AutoNew, AutoClose, AutoExec, AutoOpen. The system and files get infection on AutoOpen and AutoExec. The virus also infects the files on AutoNew and AutoClose.
On May 22nd the virus creates new template and inserts the string to there:
You are infected with the BlackEnd Virus! [D.K.]
Then it [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-blacken/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Macro.Word.BlackDeat</title>
		<link>http://www.preventonlinethreats.com/virus-threats/macro-word-blackdeat/</link>
		<comments>http://www.preventonlinethreats.com/virus-threats/macro-word-blackdeat/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 12:15:00 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
		
		<category><![CDATA[Virus Threats]]></category>

		<guid isPermaLink="false">http://www.preventonlinethreats.com/blog/?p=5962</guid>
		<description><![CDATA[Details
Macro.Word.BlackDeath
This is an encrypted Word macro virus. It contains three macros: AutoExec, AutoOpen, BlackDeath. The virus replicates itself when documents are opened (AutoOpen).
On Friday 13th it prints the text to the status line:
Please waitall Scanning disk!
and deletes the files:
C:\*.COM
C:\WINDOWS\*.INI
It then prints:
Please wait&#8230; Reading directories!
and deletes the files:
C:\AOL30\ORGANIZE\*.*
C:\AOL30\IDB\*.*
C:\WINDOWS\*.COM
C:\WINDOWS\*.HLP
C:\WINDOWS\*.CPL
C:\WINDOWS\*.BMP
C:\*.EXE&#8221;.
It then displays the MessageBoxes:
Your computer is now lost [...]]]></description>
		<wfw:commentRss>http://www.preventonlinethreats.com/virus-threats/macro-word-blackdeat/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
