LAROUX

=======


This virus description comes from V-Base, a hypertext virus information database of over 8,000 viruses.  V-Base is included on the Encyclopedia of Computer Security CD-ROM, from Seven Locks Software.


Summary: The first Excel macro virus reported in the wild.  There may be only one or two copies in organizations today, and this is NOT a threat.  However, many vendors have gotten the public excited about this "threat", and there is great curiosity and concern.  Microsoft is now working on a version of Excel that will prevent auto_open macros from executing.

Synonyms: ExcelMacro/Laroux, Excel Macro virus, ExcelMacro.Laroux.  

Date of Origin: July 15, 1996 or earlier.  

Prevalence: According to McAffee, reported at one site in Alaska and one site in Africa.   Probably extremely rare.  Because Excel is less commonly used than Word, and because spreadsheets are less often shared than Word documents, this virus will likely remain extremely rare.  

Infects: This virus is able to infect users of Microsoft Excel 5.x for Windows(r) 3.x, Microsoft Excel 5..x for Windows NT(r) and Microsoft Excel 7.x for Windows 95 and Windows NT.  It also infects non-English versions of Excel.  Does not infect under any version of Microsoft Excel for Macintosh(r) or Microsoft Excel 3.x or 4.x for Windows.  

Symptoms: One source reports that Excel spreadsheets open in the standard way, but hang if you type Alpha characters into cells (numbers work fine.) 

Damage: None reported.  Simply appends a macro sheet called "laroux" to workbooks.  It does not affect data or anything else in the workbook.  

Propagation: 

Infects Excel sheets (XLS files).  Propagates across machines when infected files are transmitted as e-mail attachments, distributed on floppy disks, or shared on networks.  

1.  Contains two macros: auto_open and check_files.  When Excel first loads an infected document, Excel executes the auto macro "auto_open", giving the virus control.  The auto_open virus macro contains a single command that defines the macro "check_files" as a handler of the OnSheetActivate routine.  With this simple change, the virus has hooked the sheet activate routine, and any further opening of worksheets gives the virus temporary control through the check_files macro.  

2.  The check_files macro contains instructions to search for PERSONAL.XLS in the Excel Startup directory and check the count of modules in the current Workbook.  

3.  When the virus is executed for the first time, the virus attempts to create PERSONAL.XLS in the Excel startup directory if it does not exist (explaining the error that occurs if the spreadsheet is loaded from a write-protected floppy.) Once this file exists, the virus copies its code to a module named "laroux" in PERSONAL.XLS using the SaveAs command.  

4.  When Excel loads its modules, it automatically loads all .XLS files located in the Startup directory.  So on the next loading of Excel, the PERSONAL.XLS file containing the virus will load.  At this time, the virus again hooks the OnSheetActivate routine.  

5.  Once the Excel environment is infected, the virus is active whenever MS Excel is loaded.  All new Excel workbooks, and any that are accessed, will be infected by copying the "laroux" module to all workbooks that are created or opened and saved..  

PERSONAL.XLS is the default filename for any macros recorded under Excel.  Thus you might have PERSONAL.XLS on your system even though you are not infected by this virus.  The startup path is by default set as \MSOFFICE\EXCEL\XLSTART, but it can be changed from Excel's Tools| Options| General| Alternate Startup File menu option.  

Detection: 

You may detect Laroux with the following scan strings: 0021 0060 0027 206A 0020 206A 00AD 0001 005C 0011 or 6C61 726F 7578 

Using these strings, scan all files with the extension .XL?.  

Here are steps for manual detection: 

1.  Start Microsoft Excel.  

2.  Click Macro on the Tools menu.  

3.  Infection is likely if the following macro names are listed: 

* Auto_Open 

* Check_files 

* PERSONAL.XLS!auto_open 

* PERSONAL.XLS!check_files 

4.  If you have any infected workbooks open in the background, you may also see the following names listed: 

* 'bookname'!auto_open 

* 'bookname'!check_files 

* (where 'bookname'! is the name of the open workbook)..  

Before disinfecting your files, confirm the existence of the macro by clicking Unhide on the Window menu and unhide the Personal.xls file.  This should make the Personal sheet visible, and display "laroux" on the sheet tab.  


Removal: 

1.  Start Microsoft Excel.  

2.  Click Macro on the Tools menu.  

3.  Delete any of the following macro names that appear in your workbook: 

* Auto_Open 

* Check_files 

* PERSONAL.XLS!auto_open 

* PERSONAL.XLS!check_files 

4.  Click Save on the File menu and re-save the file.  Click Exit on the Microsoft Excel File menu and click Yes to save all changes.  Microsoft Excel is now clean.  

5.  Open all infected workbooks one by one, keeping the left shift key depressed while opening them (according to Excel documentation, this bypasses automacros, but unfortunately it doesn't seem to always work).  

6.  For each workbook, click Macro on the Tools menu, and delete the virus macros, and re-save the file.  

It is not likely that anti-virus vendors will offer removers for this or other Excel macro viruses anytime soon.  Excel uses a proprietary file format.  Because Microsoft offered no help to anti-virus vendors who needed to understand the format of Word documents, we are not optimistic concerning their help with the Excel format.  

A free tool that detects and cleans infected documents is currently being developed and will be available shortly from  

False Alarms: If your search for macros reveals 'auto_open' but no macro named 'check_files', the file is not infected by Laroux.  Auto_open is a perfectly legitimate and common macro name in Excel.  

Prevention: 

1.  When examining new spreadsheets you have received, copy them to a floppy disk, write-protect the diskette, and then load them.  Watch for write-protect error messages when you open the file with Excel.  If such an error occurs, you might have this virus - or some other macro in the spreadsheet which is attempting to write to disk.  The virus will not spread if it cannot write to the current drive.  

2.  Reset the attributes for PERSONAL.XLS to read-only, preventing infection.  If PERSONAL.XLS does not exist on your system, create an empty PERSONAL.XLS file and write-protect it.  

Notes: written in Visual Basic for Applications (VBA), a macro language based on the Visual Basic language from Microsoft.  

Research by: Sarah Gordon, Vesselin Bontchev, Mikko H.  Hyppnen, David Stang.  

Last Revised: July 28, 1996.


Copyright (c) 1996 Seven Locks Software, Inc.  All rights reserved.

More information:
Seven Locks Software, Inc.
9012 Seven Locks Road
Bethesda MD 20817
301-365-4578 voice
301-365-7678 fax
http://www.sevenlocks.com
sales@sevenlocks.com
support@sevenlocks.com
