
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
W97M.Chantal.B is a variant of W97M.Chantal.A. It utilizes DOS Batch scripting (BAT), Visual Basic for Application (VBA) and Visual Basic Scripting (VBS).
It also uses the Year 2000 as its malicious-payload trigger date.
When opening an infected document, this virus immediately inserts a VBS file, C:WINDOWSSYSTEMMKV2.VBS, and registers it to run every time Windows starts. This VBS file is used to re-infect Microsoft Word Global Template (usually NORMAL.DOT) every time Windows starts. The VBS program uses a temporary text file C:WINDOWSMKV4.VXD in re-infecting MS Word Global Template.
Then, it inserts a DOS Batch file, C:MKV2.BAT, and adds a line in C:AUTOEXEC.BAT to execute this inserted BAT file. This BAT file is a virus on its own. It is a BATch virus that is designed to append itself to every BAT file in the current directory and its parent directory. However, the BAT script is poorly written that it will only append itself to a BAT file in the root directory.
The infection routine of this virus is very ordinary. In fact, Bloodhound heuristic easily detects this macro virus.
Payload
There are several payloads in this macro virus, and one of them is malicious. The malicious payload gets triggered on Year 2000. The payload is to delete all files from C: (the root directory of C: drive) and from the current directory (the directory where the infected document resides). At the same time, it displays a message box entitled MK Words V2 By MKVG 1999 with a message:
Hiding its activity
Similar to most macro viruses, this macro virus tries to hide its activity by disabling the following:
· Tools-Macro menu item
· Prompt to save Normal template
· Confirm conversion at Open
· Macro virus protection
With these options disabled, MS Word 97 does not warn or prompt while saving the NORMAL.DOT or while opening a document with macro in it.
In MS Word 2000, this macro virus also sets the security level to zero.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":
The following files should be deleted:
· C:WINDOWSSYSTEMMKV2.VBS (detected as VBS.Chantal.B)
· C:WINDOWSMKV4.VXD
Please do the following also:
The registry entry that calls MKV2.VBS needs to be removed. To do this, run REGEDIT and search for MKV2.VBS. You may also want to restore the Windows version and the Windows Registered Owner.
C:AUTOEXEC.BAT needs to be edited manually to remove the line @MKV2.BAT that runs the virus file.
The hidden C:MKV2.BAT file must be deleted. Norton AntiVirus detects it as BAT.Chantal.B.
Any BAT-file that Norton AntiVirus detects as BAT.Chantal.B needs to be edited manually to remove the viral code.
Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:
Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.
Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.
As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:
Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps
Easy Management: Quickly and simply configure program, sweep and upgrade options
Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper
Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off
Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."

"This program's dominance is apparent as soon as you install it."