02.08.2013 Views

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

MACRO<br />

<strong>Macro</strong> <strong>Virus</strong>es<br />

Name: AccessiV.b<br />

Aliases: AccessiV.b, A97M.AccessiV.b, Type: <strong>Macro</strong>.<br />

Disk Location: Program overlay files. Features: No damage, only replicates.<br />

Damage: No damage, only Size: Adds macros to See Also: AccessiV<br />

replicates.<br />

DataBase<br />

Notes: AccessiV.b is a variant of AccessiV (See AccessiV.a for more info). There are two main<br />

differences between them.<br />

The AccessiV.b searches and infects databases in the CURRENT, PARENT and ROOT<br />

directories of current DRIVE.<br />

The virus has a payload. Some claim that the virus activates in March, while others claim that is<br />

activated on the 3rd day of every month. So, be aware of these dates.<br />

When an infected database is opened, the virus replicates first, then displays a message-box, which<br />

contains text strings and 3 buttons. The text string is as follows:<br />

{ I am the AccessiV virus, strain B<br />

Written by Jerk1N, of the DIFFUSION <strong>Virus</strong> Team<br />

AccessiV was/is the first ever Access <strong>Virus</strong>!!! }<br />

The buttons are ‘Abort’, ‘Retry’, and ‘Ignore’. When clicking any button, the virus tries to infect<br />

the system by a DOS COM virus called Jerkin.443. Fortunately, it fails in dropping the COM<br />

virus, because a bug exists in the viral code and an error message is displayed.<br />

Name: Detox<br />

Aliases: Detox, TOX, <strong>Macro</strong>.Aceess.Detox Type: <strong>Macro</strong>.<br />

Disk Location: Program overlay files. Features: Deletes or moves files.<br />

Damage: Deletes or moves<br />

files.<br />

Interferes with a running<br />

application.<br />

Interferes with a running application.<br />

Size: Adds <strong>Macro</strong>s to See Also:<br />

DataBase<br />

Notes: The Detox or TOX is the third micro virus that was discovered in April 1998. This virus<br />

is designed to infect Access Database, which is part of the Office95 & Office97 package.<br />

Detox consists of a script called ‘AutoExec’ and a module called ‘TDU’. The TDU module/macro<br />

contains four functions (subroutines) and they are TheDetoxUnit, SetStartupProperties,<br />

ChangeProperty, and Info.<br />

While infecting, the virus replaces the original ‘AutoExec’ scripts by viral ‘AutoExec’ script, and<br />

then it copies ‘TDU’ module/macro to the database<br />

When an infected database files is opened, the ‘AutoExec’ script immediately calls TheDetoxUnit<br />

function. This function searches the CURRENT DRIVE for new victims using ‘*.MDB’ mask.<br />

Before infecting a database, Detox disables, alters, and changes several system parameters. The<br />

virus disables the Options submenu from Tools menu. The virus changes several Access<br />

Properties including AllowSpecialKeys, AllowBreakIntoCode and AllowBypassKey. The<br />

ShowHiddenObjects is disabled, too.<br />

The Info subroutine contains nothing except the following comments:<br />

{ The Detox Unit Access <strong>Macro</strong> <strong>Virus</strong><br />

written by Sin Code IV<br />

(an old friend by any other name...) }<br />

14 CIAC Computer <strong>Virus</strong> <strong>Information</strong> Update May 21, 1998

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!