Thread: ulysses gotera virus,anyone heard of that?

    ulysses gotera virus,anyone heard of that?

    has anyone heard of ulyses gotera virus that attacks mircsoft word files???

    HeadShot Master N1nja Cybr1d
    Yes, its full name is W97M/Opey.m and it was discovered in 99. Its a Macro virus.

    There's several other versions of it out there, but an up to date antivirus will take care of it.

    Here's your solution:

    This is a virus for Word 97 documents and templates. It is able to replicate under the SR-1 release of Word 97. It will turn off the macro warning feature of Word 97. This virus consists of a module called "Antivirus_1_0". It is similar in features as the original WM/Cap virus in that it is designed to remove all macros which may already exist in files during the infection routine - it does this by a simple check if the module exits already in files.
    This virus hooks the system event of opening Word97 by the subroutine "autoexec" thereby running its code. Other system events hooked are "filesave", "fileclose", "fileexit", "filenew", "autoopen", "fileopen" and "filesaveas". Attempts to use menu items of the same name within Word97 will run the macro code routine.

    Below are comments within the macro module:

    ' ------------------------------------------------------------------------------------
    ' Company: FoxChit SOFTWARE SOLUTIONS
    ' Author: Ulysses R. Gotera
    ' Date Created: March 30, 1999 Date Revisions: <>
    ' Note: This macro restores the original toolbars and immunizes other files
    ' ------------------------------------------------------------------------------------

    Before the infection routine, a file modification routine is run, changing file properties of documents and the Word97 environment with the following changes;

    Word97 environment settings:
    User Name = "Ulysses R. Gotera"
    User Address = "FoxChit SOFTWARE SOLUTIONS"
    User Initials = "URG"
    Word97 documents:
    Author = "Ulysses R. Gotera"
    Keywords = "FoxChit SOFTWARE SOLUTIONS"

    Correct these modified settings in documents manually by right-clicking on them and selecting the appropriate property tab.

    Indications of Infection

    Macro warning if opening infected document, increase in size to global template. File property modifications as mentioned above.

    Method of Infection

    Opening infected documents will infect global template

    Removal Instructions

    All Users :
    Script,Batch,Macro and non memory-resident:
    Use current engine and DAT files for detection and removal.
    PE,Trojan,Internet Worm and memory resident :
    Use specified engine and DAT files for detection. To remove, boot to MS-DOS mode or use a boot diskette and use the command line scanner:

    Additional Windows ME/XP removal considerations

    Users should not trust file icons, particularly when receiving files from others via P2P clients, IRC, email or other mediums where users can share files.

    AVERT Recommended Updates :

    * Office2000 Updates

    * Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch )

    * scriptlet.typelib/Eyedog vulnerability patch

    * Outlook as an email attachment security update

    * Exchange 5.5 post SP3 Information Store Patch 5.5.2652.42 - this patch corrects detection issues with GroupShield

    For a list of attachments blocked by the Outlook patch and a general FAQ, visit this link .
    Additionally, Network Administrators can configure this update using an available tool - visit this link for more information .

    It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.


    Antivirus_1_0, FoxChit, Opey.m, W97M/Opey.m

    damn!!!! my brother should have seen this! FYI: Ulysses Gotera is my brother..he was the one created that virus! I'll let my brother join the discussion

    HeadShot Master N1nja Cybr1d
    Thats not a smart thing to say in a public Forum. How old are you amplifiedgirl?

    Senior Member
    oh.. my.. we have a sister to a celebrity in here.. and my sister is married to kevin mitnicks dog..

    yeah sure bring your "brother" in here.. let's all have some fun..
    won't he be mad that you couldn't even spell his first name correctly ? (your first post)

    pleeeeeaaaase.. this is too much.. I can't stop laughing.. maybe a mod can move this to tech humor ? HAHAHAHA...

    Senior Member
    what a coincidence...I used to know a dog that knew a dog that was walked by someone named Kevin Miller...

    man, you better be careful...she spelled his name right in the thread title, so she must be legit, and MUAHAHAHAHAAAAAHAAAA.... dang, you're right... this is just too funny.

    Senior Member
    Ok seriouly do you actually think that anyone is going to believe you ? If it is true would you like to attach the original source code to the virus to prove it ? Since well it is pretty much well useless.

    I am sorry but I have to laugh at this. Thank you for the great laugh.

    What's next your brother coded the CodeRed virus ???
    Operation Cyberslam
    \"I\'ve noticed that everybody that is for abortion has already been born.\" Author Unknown
    Microsoft Shared Computer Toolkit
    Proyecto Ututo EarthCam

    Senior Member
    Guys don't give her ideas, next thing you know she'll be paying her brother to engineer the ILoveYouMelissa/my/SoBigRedBlaster and we're all gonna be booted off the Internet and out selling hot-dogs.

    P.S. sumdumguy No offense but I think Mitnick's dog is cheating, I saw him with this golden cocker spaniel chick.. better tell your sister to be careful. Better yet, why don't you write a virus to fry Mitnick's 'puter, for the kicks of it? I'm sure fellow AOs *cough*guess who*cough* would help.

    I think she/he is just another troll we need to get rid off

    Senior Member
    Ok seriouly do you actually think that anyone is going to believe you ? If it is true would you like to attach the original source code to the virus to prove it ? Since well it is pretty much well useless.
    If you want to look at the source code, its posted up over here-

