Content
XM/Compat.A
- Type
- Virus
- SubType
- Macro
- Discovery Date
- Length
- Not Known
- Minimum DAT
- 4002 (12/02/1998)
- Updated DAT
- 4002 (12/02/1998)
- Minimum Engine
- 5.1.00
- Description Added
- 11/30/1998
- Description Modified
- 11/30/1998 12:00 AM (PT)
Tab Navigation
Characteristics
XM/Compat - polymorhic Excel95 (version 5 and 7) virus. Known to be in the field. It does not spread on systems where Office97 is installed, however Excel97 will convert the virus into a slightly different form. This upconverted form does not replicate but the payload may still work. The virus drops a file called "Off97com.xla" into the ....\Excel\Library directory within the Office installation and registers it as an add-in for Excel. On a Macintosh the name of the file is "Office 97 Compatibility". The virus also creates a harmless file in the ...\Excel folder named "VBA_XL.TXT". This file contains just a text of the VBA program virus is using. The XM/Compat viruses have extremely nasty payload. Starting on 31 August 98 when Excel is being closed the virus selects a random sheet in a workbook (avoiding the active sheet). Then it checks to see if the cells in use are not protected, that they contain numeric values (no text, no formula) and then the virus goes through all cells in the used range (but not more then 1000 cells) changing each of them with 1% probability. The change of the number is random, but always within +-5% without changing the number of digits (length of original value is preserved). The only way to restore the contents of spreadsheet after payload has been activated is to use a backup
Symptoms
Not Known
Method of Infection
Not Known
Removal
All Users :
Script,Batch,Macro and non memory-resident:
Use current engine and DAT files for detection and removal.
PE,Trojan,Internet Worm and memory resident :
Use specified engine and DAT files for detection. To remove, boot to MS-DOS mode or use a boot diskette and use the command line scanner:
Additional Windows ME/XP removal considerations
Users should not trust file icons, particularly when receiving files from others via P2P clients, IRC, email or other mediums where users can share files.
AVERT Recommended Updates :
* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch )
* scriptlet.typelib/Eyedog vulnerability patch
* Outlook as an email attachment security update
* Exchange 5.5 post SP3 Information Store Patch 5.5.2652.42 - this patch corrects detection issues with GroupShield
For a list of attachments blocked by the Outlook patch and a general FAQ, visit this link .
Additionally, Network Administrators can configure this update using an available tool - visit this link for more information .
It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.
Variants
Variants
- XM/Compat.B
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- XM/Import
Characteristics
Characteristics -
XM/Compat - polymorhic Excel95 (version 5 and 7) virus. Known to be in the field. It does not spread on systems where Office97 is installed, however Excel97 will convert the virus into a slightly different form. This upconverted form does not replicate but the payload may still work. The virus drops a file called "Off97com.xla" into the ....\Excel\Library directory within the Office installation and registers it as an add-in for Excel. On a Macintosh the name of the file is "Office 97 Compatibility". The virus also creates a harmless file in the ...\Excel folder named "VBA_XL.TXT". This file contains just a text of the VBA program virus is using. The XM/Compat viruses have extremely nasty payload. Starting on 31 August 98 when Excel is being closed the virus selects a random sheet in a workbook (avoiding the active sheet). Then it checks to see if the cells in use are not protected, that they contain numeric values (no text, no formula) and then the virus goes through all cells in the used range (but not more then 1000 cells) changing each of them with 1% probability. The change of the number is random, but always within +-5% without changing the number of digits (length of original value is preserved). The only way to restore the contents of spreadsheet after payload has been activated is to use a backup
Symptoms
Symptoms -
Not Known
Method of Infection
Method of Infection -
Not Known
Removal -
Removal -
All Users :
Script,Batch,Macro and non memory-resident:
Use current engine and DAT files for detection and removal.
PE,Trojan,Internet Worm and memory resident :
Use specified engine and DAT files for detection. To remove, boot to MS-DOS mode or use a boot diskette and use the command line scanner:
Additional Windows ME/XP removal considerations
Users should not trust file icons, particularly when receiving files from others via P2P clients, IRC, email or other mediums where users can share files.
AVERT Recommended Updates :
* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch )
* scriptlet.typelib/Eyedog vulnerability patch
* Outlook as an email attachment security update
* Exchange 5.5 post SP3 Information Store Patch 5.5.2652.42 - this patch corrects detection issues with GroupShield
For a list of attachments blocked by the Outlook patch and a general FAQ, visit this link .
Additionally, Network Administrators can configure this update using an available tool - visit this link for more information .
It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.
Variants
Variants -
- XM/Compat.B