
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
W97M.Heathen.12288.A is another attempt to combine the macro virus spreading power with Win32 programs. The virus is rather buggy. It does not work under Windows 98 or Windows NT. Even when it works under a Windows 95 system, the modified EXPLORER.EXE becomes unstable. It may also crash MS Word 97 after it infects the system.
Upon opening an infected Word 97 document, the following events occur:
1. AutoOpen routine of the virus creates "HEATHEN.VDO", an OLE storage file, into the WINDOWS directory. This OLE storage file holds the viral macro structure to be added into the targeted Word 97 document.
2. It then proceeds to drop "HEATHEN.VDL", a Win32 program, into the WINDOWS directory. This file contains the routine to infect MS Word 97 documents.
3. The virus modifies EXPLORER.EXE in the WINDOWS directory. The modification adds a loading routine such that HEATHEN.VDL gets loaded every time EXPLORER.EXE is executed.
4. If it fails to modify EXPLORER.EXE (the file is read only, or being used, etc), it will copy EXPLORER.EXE into HEATHEN.VEX. Then, it modifies HEATHEN.VEX. To have EXPLORER.EXE replaced by HEATHEN.VEX, the virus creates a WININIT.INI file that contains:
[rename]
C:WINDOWSExplorer.exe=C:WINDOWSHeathen.vex
This instruction in the WININIT.INI file makes Windows replace EXPLORER.EXE with the HEATHEN.VEX file upon the next startup.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":
NAV detects and repairs infected MS Word 97 documents.
NAV detects the HEATHEN.VDO file as "W97M.Heathen.12288.A". However, NAV will fail to repair because it sees this file as an incomplete (potentially corrupted) MS Word 97 document. NAV stops the repair to prevent further corruption.
NAV detects the HEATHEN.VDL file as "Heathen.12288(DLL)". This file needs to be deleted.
Unfortunately, the modification to EXPLORER.EXE is irreversible. EXPLORER.EXE needs to be restored from a clean copy. A clean copy of EXPLORER.EXE can be found on the Windows Installation CD:
· in WIN95_10.CAB file for Windows 95a
· in WIN95_17.CAB file for Windows 95b
· in WIN98_41.CAB file for Windows 98 (although it does not work in Windows 98)
CAB files may be extracted using a CAB file viewer (downloadable from Microsoft website) or using an archive utility such as WinZip.
Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:
Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.
Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.
As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:
Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps
Easy Management: Quickly and simply configure program, sweep and upgrade options
Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper
Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off
Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."

"This program's dominance is apparent as soon as you install it."