Skip to main content

CAP

Classification

Summary

WM/CAP is one of the most common viruses in the world.

For more information on macro viruses, see WM/Concept.

Removal

Technical Details

CAP is a complex Word macro virus. It consists of several encrypted macros: CAP, AutoExec, AutoOpen, FileSave, FileSaveAs, FileTemplates, ToolsMacro, FileClose, FileOpen and AutoClose.

The virus contains these texts in comments:

'C.A.P: Un virus social.. y ahora digital.. '"j4cKy Qw3rTy" (jqw3rty@hotmail.com). 'Venezuela, Maracay, Dic 1996. 'P.D. Que haces gochito ? Nunca seras Simon Bolivar.. Bolsa !

When infecting Word, CAP modifies up to five already-existing menus, redirecting them to the virus code. This creates some problems, as the names of the modified entries are different in different Word installations and different language versions of Word.

One effect of CAP is that all documents are saved in the Word DOC format, regardless of the format you choose. So, for example, if a document is saved as an RTF file, the extension of the document will become RTF but internally the file is still a DOC and does still contain the virus. Normal RTF files do not contain macros at all and are unable to spread macro viruses.

When CAP infects documents, it deletes all existing macros from them. Otherwise CAP does not do anything destructive. However, it does remove the Tools/Macro and Tools/Customize menus and disables File/Templates menu in order to protect itself.

WM/CAP.A was reported in the wild in several countries in 1997. It's probably related to the WM/Rapi virus.

Variant:CAP.dam

WM is an abbreviation for WordMacro. This abbreviation is used by Dr. Solomon's antivirus toolkit.

".dam" is an abbreviation for "damaged". This abbreviation is used by Dr. Solomon's antivirus toolkit. Files reported to contain the "WM/CAP.dam" virus are actually documents which have been infected once by CAP but are corrupted or have had the CAP macro deleted. Often such files still contain some macros of the virus, but might not spread. F-Secure anti-virus products do not detect such files separately, as they are considered to be new variants of the virus.

If you want to get rid of the macros, you can copy the texts of the document to a new file or use F-Secure Anti-Virus for DOS with /DISINF /REMOVEALL options on this file.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.