Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Compat


Aliases:


Compat

Malware
Virus
W32

Summary

XM/Compat.A is a polymorphic macro virus. The virus changes its appearance so it looks different in every infected file. This is done by inserting random comments into the virus code.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

The virus consists of 11 subroutines: Auto_Open, Auto_Close, Auto_Exit, Auto_Help, Macro1, Macro2, Macro3, Macro4, Macro5, Macro6, and Macro7. They are in one module which has polymorphic name.

The virus puts the following comment in the beginning of its code:

 Macro recorded (month)/(day)/(year) by (user) 

The variables (month), (day), (year) and (user) are different for every environment and replication. The virus saves its code in different files and paths depending on the environment.

On Macintosh, the files are "Office 97 Compatibility" and "MS Excel Visual Basic Example", but on Windows 95 they are "Off97com.xla" and "Vba_xl.txt".

The virus builds its code as Add-In in Off97com.xla file. Compat works only in Excel 95. It does not infect Excel 97.

Compat has a payload which activates after 31 August 1998. After that date, the virus modifies the contents of random cells by changing the values slightly. This can have disasterous effects.







Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.