Threat Description

Kompu

Details

Aliases: Kompu, Kommi
Category: Malware
Type:
Platform: W32

Summary


For more information on Word macro viruses, see WordMacro/Concept.

WordMacro/Kompu was found from Estonia in December 1996. It spreads when infected DOC files are opened to Word. After this, all other documents will get infected when they are opened or closed.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.



Technical Details


On the 6th or 8th of any month, the virus activates. When any document is opened on these dates, the virus will display a dialog box with the title "Mul on paha tuju!" and the question "Tahan kommi!". These texts are in Estonian and mean "I'm in a bad mood" and "Give me a candy". The virus will not let the user continue working until he writes the word 'komm' (candy) to the window. After this, the virus changes the Word status bar text to read:

Namm-Namm-Namm-Namm-Amps-Amps-Klomps-Kraak!  

Kompu.A has been reported to be in the wild in several European countries.


Variant:Kompu.I (Spreader)

Origin:Estonia

This is another variant of Estonian virus Kompu. It was found in November 1997.

Kompu.I activates by switching to normal view and setting document magnification to 200 percent.

This happens every time an infected document is opened. At this time virus also displays a message box with the following text:

Still don't see the text ? I'll fix that problem ;)  

The virus body contains this text:

       ================================        = INFORMATION ABOUT THIS VIRUS =        ================================        Reason: Educational        Name: Spreader        Made in Estonia        Made by the TPAR team        ================================ 	    	   




Technical Details:Mikko Hypponen and Katrin Tocheva, F-Secure Ltd


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More