On Thu, 12 Oct 2000, Floyd Pierce wrote:

> I'm having a problem with Word documents that are generating a 123
> macro scanner score. Is there an easy way to show the elements
> that caused the score? The documents in question pass Norton AV
> without a problem, and I'm unable to find any macros at all in the
> documents.

 From what I've seen, a lot of A/V tools simply mangle the macro
viruses in-place and don't even try to remove them. This may render it
unrecognizable to Word or other signature-based virus scanners, but
will leave enough bits of VB code in the document to trigger

To truly clean it up, I recommend the document be saved in some format
that does not support macros, such as Rich Text (RTF) or (perhaps)
Word Perfect. Then re-load the document and save it in native format.

To see what's there, edit the document file in vi and search for:


(...where the ^@ is a literal NULL, entered by typing [CTRL]-V,
[CTRL]- at . Lines of vbscript start with a null, followed by plain-text

You should be able to see enough lines of plaintext VBscript doing
things like playing with the macro and security settings, default
document, registry, etc. to recognize that it was infected and, while
defanged, wasn't actually cleaned out. Some of them may appear to be
mangled, which is the A/V tool's disinfecting the document.

