Threat Description

Arbeit

Details

Aliases:Arbeit
Category:Malware
Type:Virus
Platform:W97M

Summary



W97M/Arbeit is a Word 97 macro virus with a destructive payload.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details




Variant:Arbeit.A

When an infected document is opened, W97M/Arbeit.A disables the built-in macro virus protection, the status bar and the following menus: "Tools/Macros/Macro" and "Tools/Macros/Visual Basic Editor". It also modifies the user name and initials to:

  User name:  NoWork Inc.
 Initials:NWI

Then the virus creates a temporary file "C:\mlpog.sys" that it uses to infect the global template and all documents closed after that.

The virus activates its payload every day after October 15th, when it shows a message box with the following text:

  The technology will be kill humaneness

After the message box has been shown, it deletes all files from the root directory of the "C:" drive.





Description Created: Analysis: Sami Rautiainen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More