Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Avarta.A - First Microsoft Publisher Virus appears

Kaspersky has noted the 1st MS/Publisher virus to appear in the wild.  PUB file extensions will most likely be necessary to include in scanning routines.

Avarta.A - First Microsoft Publisher Virus appears
http://www.viruslist.com/en/viruses/encyclopedia?virusid=117864

This is the first known virus that infects MS Publisher (*.pub) documents. It is a very simple overwriting virus, written in Visual Basic for Applications (VBA). The virus uses a rather crude replication method - it searches for Publisher documents and copies itself over them, thus destroying their content. Avarta gets the location which it will scan for Publisher documents to infect by opening the registry and fetching the key for the recently used files in Publisher. It sets the macro Security Level in Publisher to Low. This is a common technique in macro viruses.