Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

what is W97M.Marker.C.3?

User's Apple ID has been shutdown by Apple for reasons of security.


A scan of the iMac with ClamXAV finds 50 threats of one kind or another, mostly among downloaded email.


Also, many Office 2004 and earlier Word files are quarantined with the Infection Name: W97M.Marker.C.3


My guess is that this indicates a threat embedded in a Word macro.


I'd also like to know if the infected files on this iMac have anything to do with the shutdown this user's Apple ID.


Hardware Overview:


Model Name: iMac

Model Identifier: iMac12,2

Processor Name: Intel Core i5

Processor Speed: 2.7 GHz

Number of Processors: 1

Total Number of Cores: 4

L2 Cache (per Core): 256 KB

L3 Cache: 6 MB

Memory: 4 GB

System Software Overview:


System Version: Mac OS X 10.7.5 (11G63)

Kernel Version: Darwin 11.4.2

Boot Volume: Macintosh HD



MacBook Pro (15-inch 2.4/2.2 GHz), Mac OS X (10.7.2), Mac Mini, VMWare XP Pro, Win 7, HP and Dell desktops, iPhone

Posted on Apr 4, 2013 1:30 PM

Reply
Question marked as Best reply

Posted on Apr 4, 2013 2:04 PM

It's a macro virus which infects Word documents. Norton has this info on it:


W97M.Marker.damaged Also Known As: W97M.Marker.Gen, W97M/Marker.KC, W97M/Marker.go, W97M/Marker.AO, WM97/Marker-GO


The virus is activated when you close a document that is infected with W97M.Marker.damaged. It replicates in a corrupted form.


When it is executed, W97M.Marker.damaged performs the following actions:


1. It changes a Microsoft Word option, so that when you open a document that contains a macro, the warning message no longer appears.

2. It drops the log file C:\hsf????.sys, (where ???? is a string of four random numbers from 0 to 7), which contains a list of previously infected users.

3. Next, it drops the text file C:\Netldx.vxd with the commands to upload the log file to a remote FTP server.

4. Finally, it runs the Windows file Ftp.exe and passes the file C:\Netldx.vxd as a parameter in an attempt to perform the log file upload. This operation will fail because the IP address of the FTP server cannot be contacted.


As you can see, it's yet another piece of Windows malware that only works on Windows computers. You can be a carrier, but that's all. Stripping the macro out of your documents is the real work on your end. Macros also usually attach themselves to the default template so every new document also gets the macro attached.

2 replies
Question marked as Best reply

Apr 4, 2013 2:04 PM in response to Quentin Leo

It's a macro virus which infects Word documents. Norton has this info on it:


W97M.Marker.damaged Also Known As: W97M.Marker.Gen, W97M/Marker.KC, W97M/Marker.go, W97M/Marker.AO, WM97/Marker-GO


The virus is activated when you close a document that is infected with W97M.Marker.damaged. It replicates in a corrupted form.


When it is executed, W97M.Marker.damaged performs the following actions:


1. It changes a Microsoft Word option, so that when you open a document that contains a macro, the warning message no longer appears.

2. It drops the log file C:\hsf????.sys, (where ???? is a string of four random numbers from 0 to 7), which contains a list of previously infected users.

3. Next, it drops the text file C:\Netldx.vxd with the commands to upload the log file to a remote FTP server.

4. Finally, it runs the Windows file Ftp.exe and passes the file C:\Netldx.vxd as a parameter in an attempt to perform the log file upload. This operation will fail because the IP address of the FTP server cannot be contacted.


As you can see, it's yet another piece of Windows malware that only works on Windows computers. You can be a carrier, but that's all. Stripping the macro out of your documents is the real work on your end. Macros also usually attach themselves to the default template so every new document also gets the macro attached.

Apr 4, 2013 10:49 PM in response to Quentin Leo

Quentin Leo wrote:


A scan of the iMac with ClamXAV finds 50 threats of one kind or another, mostly among downloaded email.

Never use ClamXav (or any other A-V software) to move (quarantine) or delete e-mail. It will corrupt the mailbox index which could cause loss of other e-mail and other issues with functions such as searching. It may also leave the original e-mail on your ISP's e-mail server and will be re-downloaded to your hard drive the next time you check for new mail.


So, if you choose to "Scan e-mail content for malware and phishing" in the General Preferences, make sure you do not elect to either Quarantine or Delete infected files.

what is W97M.Marker.C.3?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.