On Wed, 23 May 2001, Chris Edsall wrote:

> We appear to be getting quite a few MS Word .doc files rejected
> with high scores because they get 99 points from the string
> VirusProtection. If we save these out and open them on a machine
> with Norton AntiVirus and current definitions, NAV doesn't
> complain and there don't appear to be any malicious macros.

Take a look at the file in a text editor (e.g. vi).

It has been my experience that AV tools simply mangle the macros into
submission and leave them in the document. The scanner doesn't know a
whit about the structure of Office documents, so it doesn't know to
scan just valid macros, so it can generate hits off the bits of the
virus that remain.

You may want to suggest that they save the document as RTF and reload
it in order to strip all remaining bits of the virus out.

You can also decide to rely on your desktop antivirus tool and disable
the macro scanner.

> Are we safe to comment that line out, or will it leave us open to
> some other (extremely, judging from the score) nasty files?

Doing so reduces the capability of the scanner to detect infected
documents. Whether or not you do this is your decision.

