Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 18th, 2002, 09:34 AM
FanJ
 
Posts: n/a
Default WM97/Panggil-C

Name: WM97/Panggil-C
Type: Word 97 macro virus
Date: 18 February 2002

At the time of writing Sophos has received just one report of this virus from the wild.

Description:

WM97/Panggil-C will set the Word application user information as follows:

UserName: Grunge-X Include in
UserInitials: Grunge-X
UserAddress: Grunge-X@usa.net

It can also set a document password of "GRUNGE".

If the user accesses Tools|Macro the virus will use the Office Assistant to display the message:

"GRUNGE Is Block Your System
System Is Disabled By (Grunge)
You Can't Open VBMacro Code On this time, because the System is
Busy
please check on your administrator system.".

The virus can also change the Word application caption to read either "Include Grunge-X, please wait... " or "Keep to Smile".
On Mondays and Fridays it will display the following message when Word exits:

"The Sun Is Gone But I Have I Light (1967-1994)".

WM97/Panggil-C creates a directory called OSGrunge under the Windows directory in which it keeps an infection log in Grunge1.ini. The virus also creates the non-viral file Engine.dll in the Word application directory.


Read the analysis at
http://www.sophos.com/virusinfo/analyses/wm97panggilc.html

 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:22 PM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums