Virussen
Technische documentatie van Symantec over het Ping-virus.
W97M.Ping.A
Aliases: |
W97M.Ping.A, W97M.Koyaanisqatsi |
Infection Length: |
1259 bytes |
Area of Infection: |
Microsoft Word 97 documents |
Likelihood: |
Common |
Region Reported: |
Worldwide |
Characteristics: |
Infects Word documents and pings 4 hosts |
Target Platform: |
Microsoft Word 97 |
Trigger: |
None |
|
|
Description:
The W97M.Ping.A virus is a macro virus. The macro virus works in Microsoft Word 97 and potential later versions. This macro virus infects the This Document module inside of Microsoft Word 97 such that you may not see an additional macro under Tools | Macro | Macro like traditional macro viruses. Other than replicating, the W97M.Ping.A virus will attempt to ping four different hosts indefinitely potentially causing a denial of service and network congestion.
The W97M.Ping.A virus replicates when opening an infected document. First, W97M.Ping.A will deactivate the macro virus protection feature in Microsoft Word 97. This feature prompts you when opening a document with macros.
Next, the virus checks to see if the document or global template is already infected. The virus does this with a simple infection length check. If the length of the module exceeds the length of the virus, the virus assumes it is already infected. Thus, the virus may not infect all documents or templates.
If the document or template is not already infected, the virus copies itself into the This Document module. After successfully replicating itself, the virus then executes its payload.
The payload pings four different hosts. The pings are executed indefinitely with a static buffer size. These pings can cause network congestion and a denial of service.
Norton Antivirus will repair by removing all the code in the This Document module.
Write-up by: Eric Chien
Date of write-up: March 29, 1998
Zie ook: www.symantec.com/avcenter/venc/data/melissa.html
|