Threat Description

FF

Details

Aliases:FF
Category:Malware
Type:Virus
Platform:W97M

Summary



W97M/FF is a simple Word class infector.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details




Variant:FF.AMacro.Word97.Lys.i

When an infected document is opened, W97M/FF.A deletes the "Tools/Macros" menu and disables the built-in macro virus protection first. Then the virus creates a temporary file, "C:\FF.sys", and infects the global template.

Afterwards every opened document is infected.

the virus activates its payload on the first day of every month. It alters the "c:\msdos.sys" file by changing the

  BootGUI=1

line to

  BootGUI=0

This causes Windows 95/98 to start in command line mode after boot, instead of graphical user interface (GUI).


Variant:FF.C

This variant is functionally identical with W97M/FF.A.





Technical Details: Sami Rautiainen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More