Uploaded September 2011 | Updated September 2026, 2 weeks ago
This trojan is similar to batch, however it's just a package... Long time ago there was Packaging tool in Windows, which managed to... well, pack files inside some executable I guess. I was playing with that before, but never managed to understand how to do it. I think it's still available in Windows. It's very easy to reveal what it contains, though some people can be fooled easily... I guess that tool never became popular as nobody seems to talk about it. It seems that trojan just runs deltree.exe and deletes only Windows folder, but not other ones...
Aliases:
Trojan.Win32.KingSolaris (Kaspersky Lab)
(TODO)
This trojan is similar to batch, however it's just a package... Long time ago there was Packaging tool in Windows, which managed to... well, pack files inside some executable I guess. I was playing with that before, but never managed to understand how to do it. I think it's still available in Windows. It's very easy to reveal what it contains, though some people can be fooled easily... I guess that tool never became popular as nobody seems to talk about it. It seems that trojan just runs deltree.exe and deletes only Windows folder, but not other ones...
Aliases:
Trojan.Win32.KingSolaris (Kaspersky Lab)
(TODO)

![Trojan Horse (Windows): Macur
In general it drops itself to %windir% with filename pic.exe, edits a line in Win.ini to load that file at every boot (load=pic.exe), and then it creates about 1,410 folders named with zeros, ones, twos, threes, fours and fives, and it keeps stacking number by number using this pattern:
0
00
000
...
00000000000000000000000000000000... (Its pretty much difficult to count...)
After it came to maximum, it continues to next number (1):
1
11
111
...
Another interesting thing is that it checks the folder name of current folder with specific pattern. If the 1st letter is W or 5th letter is O and 6th letter is W, it will not show fake error message. Note that it does check even parent folders as far its noticed when trojan was launched on desktop.
Aliases:
Trojan.Win32.Macur (Kaspersky Lab)
Trojan: Macur (McAfee)
Troj/Macur (Sophos)
Trj/Macur (Panda)
W32/Trojan!028f (FPROT)
Trojan:Win32/Macur (MS(OneCare))
Trojan.Macur (DrWeb)
Win32/Macur trojan (Nod32)
Trojan.Win32.Macur (BitDef7)
Trojan.Macur.B (VirusBuster)
Win32:Trojan-gen (AVAST)
Trojan.Win32.Macur (Ikarus)
Generic.KSI (AVG)
TR/Macur.A (AVIRA)
Trojan.Macur (NAV)
W32/Macur.A (Norman)
Macur (NAI)
TROJ_MACUR.A (PCCIL)
Trojan.Macur (Rising)
Trojan.Win32.Macur [AVP] (FSecure)
TROJ_MACUR.A (TrendMicro)
Trojan.Macur.B (VirusBusterBeta) Trojan Horse (Windows): Macur](https://i.ytimg.com/vi/_apjJyW5TSc/mqdefault.jpg)








