MACRO VIRUS - REMOVING IT

Subject: MACRO VIRUS - REMOVING IT
From: Bruce Conway <bconway -at- ISLAND -dot- NET>
Date: Mon, 14 Dec 1998 14:28:56 +0000

Some links which cover the Word Macro Virus (and how to remove it):

WORD MACRO VIRUS
http://training.csd.sc.edu/virus/macro.htm
http://www.rcmp-grc.gc.ca/html/macro-e.htm
http://mtpe.gsfc.nasa.gov/eos-mis/wmv.htm

Virus News -- Macro Virus Summary

Government departments and other users of Microsoft Word? Version 6 have
experienced widespread infections of their
systems (i.e Word) with unauthorized macros. One infected, all
subsequent documents created are corrupted with these
macros. Clean systems are infected simply by "opening" an infected
document. These macros meet the definition of
viruses due to their parasitic ability to infect and replicate. These
macros will only affect Word users and do not infect
other word processing systems.

The problem has developed due to the upgraded power of the WordBasic
macro language which was implemented in
Word Version 6 to give users "increased functionality". In order to
compete, other Word processing, Spreadsheet or Mail
packages may implement similar (or even compatible) functionality. The
macro viruses found to date have been named
DMV, Concept, Nuclear and Colors.

Symptoms include users noticing unknown/unauthorized macros (eg. AAAZAO,
AAAZFS, AutoOpen, Payload etc.)
installed in their Normal.dot (global template) file. These macros then
attach themselves to all subsequently saved
documents and get passed (or mailed) from user to user. The Colors
macros reportedly will randomly change a system's
colour settings (in the windows.ini file) after an internal counter
reaches 300.

Many Ant-Virus software developers and Microsoft have attempted to
provide interim solutions. Currently these solutions
involve installing preemptive macros in your system to detect the
presence of executable or malicious macros in your
documents. These tools are available from sites on the Internet or on
the Technical Security Services, Bulletin Board
System in the Virus Files directory. SEIT recommends the implementation
of the latest Microsoft solution. In our
opinion, the problem is compounded by the design of their products and
licensed users should pressure them to provide
adequate solutions. As well, Antivirus software can now be updated with
new drivers or customized signature string files to
detect these known macros. Licensed users should implement these and now
habitually scan their Word documents.

It should be noted that SEIT has received several advisories on the new
macro virus named Colors. No actual reports of
this particular infection have been received from client departments, so
it may be having problems replicating. If the
details are correct however, the solutions referenced above do not
apparently prevent infections of this virus. Developers
are undoubtedly working on updates to their fixes. F-Prot and Dr.
Solomons and others have signature strings to detect it.
As more details are substantiated, notices will be posted on the BBS.

This information is from the developers of F-prot.


--
****************************************************************
Bruce Conway, B.A. (Math/Pol Sci) - Tech Writer/Communicator

Member:
Society for Technical Communication (STC)
Vancouver Island Adv. Technology Centre
(VIATeC)

RESUME: http://www.island.net/~bconway/resume.html
Email : bconway -at- island -dot- net
****************************************************************

From ??? -at- ??? Sun Jan 00 00:00:00 0000=




Previous by Author: NORMAL.DOT
Next by Author: Re: Roll-your-own style guides?
Previous by Thread: NORMAL.DOT
Next by Thread: Re: MACRO VIRUS - REMOVING IT


What this post helpful? Share it with friends and colleagues:


Sponsored Ads