Ekiam

Threat description

Details

CATEGORYMalware
TYPEVirus

Summary

Ekiam.A is a simple macro virus that infects Word templates and documents during opening, saving and closing.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details


Variant:Ekiam.A

To run, the virus first lowers the security settings. Then it saves its code in a file Maike.sys which it places in Windows System folder. Then Ekiam.A uses this file to import the virus code during the infection.

The payload of the virus activates when the system date is 1st, 14th or 28th of each month. In that case Ekiam.A changes Windows registry so the registered owner, the registered organization and the Product Id are changed respectively to "Maike you are", "the most beautiful", "girl in the world".

The changed regitry are as follows:

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner="Maike you are"  "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOrganization="the most beautiful"  "HKELM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProductId="girl in the world"  

To hide the virus code from the user, Ekiam intercepts Tools Macro, File Templates and View VBCode menus.

Eikam also contains a commented text that it never shows.

Detection

F-Secure Anti-Virus detects Ekiam.A with the heuristics. Exact detection was published in update:

Detection Type: PC

Database: 2003-02-25_01

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info