Threat Description

Kompu

Details

Aliases:Kompu, Kommi
Category: Malware
Type:
Platform: W32

Summary



For more information on Word macro viruses, see WordMacro/Concept.

WordMacro/Kompu was found from Estonia in December 1996. It spreads when infected DOC files are opened to Word. After this, all other documents will get infected when they are opened or closed.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



On the 6th or 8th of any month, the virus activates. When any document is opened on these dates, the virus will display a dialog box with the title "Mul on paha tuju!" and the question "Tahan kommi!". These texts are in Estonian and mean "I'm in a bad mood" and "Give me a candy". The virus will not let the user continue working until he writes the word 'komm' (candy) to the window. After this, the virus changes the Word status bar text to read:

Namm-Namm-Namm-Namm-Amps-Amps-Klomps-Kraak!

Kompu.A has been reported to be in the wild in several European countries.


Variant:Kompu.I (Spreader)

Origin:Estonia

This is another variant of Estonian virus Kompu. It was found in November 1997.

Kompu.I activates by switching to normal view and setting document magnification to 200 percent.

This happens every time an infected document is opened. At this time virus also displays a message box with the following text:

Still don't see the text ? I'll fix that problem ;)

The virus body contains this text:

 ================================
 = INFORMATION ABOUT THIS VIRUS =
 ================================
 Reason: Educational
 Name: Spreader
 Made in Estonia
 Made by the TPAR team
 ================================
	
	




Technical Details: Mikko Hypponen and Katrin Tocheva, F-Secure Ltd


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More