Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Threats » W97M/Marker.A

Overview

Threat Risk LOW LOW
Destructivity NONE NONE
Payload
Detection files published
Description created 17 Apr 2000 03:00:00
Description updated 17 Apr 2000 03:00:00
Malware type VIRUS
Alias
Spreading mechanism FILE_INFECTION
Summary None

W97M/Marker.A

Spreading

The first action taken by this virus is disabling the virus protection in Word. Before infecting any files W97M/Marker.A will check whether either the global template (usually Normal.dot) and the opened document already are infected. To do this, the virus uses a constant marker at the start of the viral code. If the template or document do not contain the marker, they will be infected. To infect files the virus exports its viral code to C:\Netldv.vxd and imports this file into clean documents. C:\Netldv.vxd is deleted after the infection. Finally this variant append the system time and date and the current username and address at the end in its code.

Payload Details

n/a

Analysis

n/a

Removal

n/a


Last Updated: 12 Nov 2015 11:06:14