Download ESET LTd. v1.21s by PC

Added to site2002-12-31
Rating93/100
Votes19


esetltd.v1.21spc.zip (54672 bytes)

namesizecompressed
HMVS.EXE 37322 37235
PC.NFO 8599 2741
FILE_ID.DIZ 369 223
WHATSNEW.TXT 2607 925
REGFORM.TXT 2724 878
HMVS.TXT 13441 4446
HMVS.SIG 7498 6929
README.1ST 827 517

PC.NFO

                          ▄▄██▓▄▄                   ░
                       ▄▓▓▀▀   ▀▀▓▓▄▄   ■ ▀   ▄     ▒     ▄▄▓▓▄
             ▄       ▄▀ ▄▄▄████▄▄▄ ▀█▓▄          ▀ ▄▓  ■▀▀▀▀▀██▓▓▄
        ▄▀     ▀ ▄ ▀  ▄██▓▓████████▄ ▀██   ░ ░ ░░▒▒▓▓▓█████▄▄▄ ▀▀██▄
       ▐▌           ▄██▀▀     ▀███▓██ ▐██▄ ▄      ▄████▓████████▄ ▀▓▓▀
        ▀▄        ▄▀▀    ▄ ░░  ▐█▓▓▓█▌ █▀        ▐███▀▀█████████▓█
            ▀   ▀   ▄▄▄██      ███▓███ ▀    ▄   ▄███▌  ▐▓█████▓▓▓▓▒▒░░ ░  ░
        ■   ▄▄▄▄█████▓▓█▌  █▄▄███████▌ ▀      ▀█▓███    ▀▓████▀▀▓▀  ▄▄
         ▀▄  ▀▓▓███▓▓▓▓█▌ █▓▓██████▓█  ▄ ░ ░░ ▄ ▀▓▓█      ▀▀ ▄▄ ▒ ▄▓▓▀
          ▐▓▄  ██████▓▓▓▌██▓███████▀  ░   ░ ░ ██▄ ▀▓▌    ▄▓█▓▀  ░ ▐▀
          ▓███▌▐██████▓▓▌ ▀███▓▓▀▀           ▐▓███  ▀   ▀▓▀
 ░  ░ ░░▒▒▓▓▓██ ██████▓▓█                    ▓▓▓██▌
         ▒▓▓███ █▓█████▓▓▌ ░░░░░ ░      ░     ▀▓▓▀  ▄       ▄█▓▄
          ▒ ▓▀  █▓██████▓█  ░░░ ░   ░     ▀ ▄ ▒   ▄▓   ▄   ░ ▀███▓▄     ░
          ░    ▐▓▓███████▓█▄ ░    ░         ▐█▓▄▄█▓▌  ▀▓▀░░░░ ▐█▓▓▓▀ ▀ ░░░░ ░
              ▄▓▓█████▀▀▀▀▀▀▀         ░ ░░░▒▒▓▓▓███▌       ░ ▄██▓▓█▄▄   ░
          ▄▄█▓█▀▀▀        ▄▓█▄▄               ▒ ▀███▄      ▄▓▀▀    ▀▀▀▓▄▄
       ▄■▀▀               ▀█▓▓██▄             ░    ▀▓██▄▄▀▀     ▄■ ▀      ▀ ▄
     ▄                ▄ ■ ▄  ▀▀▓██▄                 ▐▓▓▀    ░  ▐▌ ░░        ▐▌
    ▐▌              ▀      ▄ ▀    ▀▀▄         ░    ▄▀    ░ ░░░  ▀▄          █
     ▀▄           ▀        ▐█▄  [cH]▐█ ▀    ▄   ▀           ░      ▀    ▄  ▀
┌───────■──▄── ■▀─── ── ─ ▄▓▀ ▀▀─▄ ■▀          ─  ── ────── ─────── ────────┐
|                        ■▀                                                 |
|    dATE : [ 01/28/97 ]                                                    |
:  rEG bY : [ eMX! ]                                                        :
:   tITLE : [ ESET LtD`s "HeuristicMacroVirsuScanner v1.21 ]                :
|   wHERE : [ ftp:/ftp.elf.stuba.sk/pub/pc/avir/ ... ]                      |
├───────── ────── ───── ── ──  ─  ─             ─ ─  ──  ──── ─── ──────────┤
|              pATCH ( )    sERIAL# ( )    kEYGEN ( )     hACKED (*)        |
├───────── ────── ───── ── ──  ─  ─             ─ ─  ──  ──── ─── ──────────┤
| dESC:   Run HMVS.EXE .. ( hacK LiCENSED vERSiON! )                        |
│                                                                      eMX! │
└────── ───── ── ── ─ ── ──    ─                 ─ ─ ── ─── ──── ─── ────sk─┘

                         >>> PC97 MeMBeRs ─-───▄
                      ▀   ▀ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

fOUNDER: [ The Keyboard Caper......................... [email protected] ]

   pREZ: [ tHATDUDE........................ [email protected] ]
   vICE: [ Archimede................................ [email protected] ]

aDVISOR: [ [email protected] ]
         [ n00dles.......................... [email protected] ]
         [ THe BoMB......................... [email protected] ]
         [ MegaByte........................ [email protected] ]

cRACKER: [ Acp.................................. [email protected] ]
         [ aquad00d................................... [email protected] ]
         [ Byte Ripper.......................... [email protected] ]
         [ G-RoM................................. [email protected] ]
         [ Jestrz..................................... [email protected] ]
         [ Kristina.............................. [email protected] ]
         [ madmax!........................... [email protected] ]
         [ NuZ............................................ [email protected] ]
         [ Pr0m......................................... [email protected] ]
         [ Reformed........................... [email protected] ]
         [ Saltine.......................... [email protected] ]
         [ surva.............................. [email protected] ]
         [ Sync............................. [email protected] ]
         [ XLogic............................ [email protected] ]
         [ zircon......................................... [email protected] ]
     >   [ eMX!..................................... [email protected] ]

cOURIER: [ alfi5.................................. [email protected] ]
         [ Baloosh................................. [email protected] ]
         [ CyberJack.............................. [email protected] ]
         [ Saken.............................. [email protected] ]
         [ The Usurper.............................. [email protected] ]
         [ Whipe.................................... [email protected] ]
         [ z0ned...................................... [email protected] ]

gRAPHIX: [ Antha...................................... [email protected] ]
gRAPHIX: [ Cheesi...................................... [email protected] ]
gRAPHIX: [ Creature of Hell.................. [email protected] ]
gRAPHIX: [ Mystic12....................................... [email protected] ]
wEBDUDE: [ b0neZ................................... [email protected] ]
wEBDUDE: [ daze97........................................................ ]
  mUSIC: [ ^Cyber............................. [email protected] ]
d0XDUDE: [ FXer...................................... [email protected] ]
b0TDUDE: [ [bOnEz].................................... [email protected] ]

  tRIAL: [ Smurfer....................................... [email protected] ]
         [ BLiTZ...................................... [email protected] ]


                           - crEw bOards -─-───▄
                      ▀   ▀ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

    wHQ: [ Wolfenstein        +012  TKC            28.8     PTA           ]
         [ Extacy (21h)       +012  Jakez/Ace      28.8 x2  PTA           ]
         [ Music Club         +012  Dr. Death      28.8     PTA           ]
         [ Gravestone          +76  XLogic         28.8     Australia     ]
         [ Star Trek TNG       +32  Psychotron     28.8     Belgium       ]
         [ PhantOm            +021  DaRKNiGHT      28.8     CT            ]
         [ Impulse             +49  MEPHiST0       28.8     Germany       ]
         [ PhreakOut (21h)     +11  PhreakMan      28.8     South Africa  ]
         [ Logics              +44  Fingers        28.8     United Kdm.   ]
         [ Morbid Vision       +49  cYcl0ne        ISDN x2  Germany       ]
         [ tHE uNKNoWN         +44  BLaCK SaBBATH  ISDN     United Kdm.   ]

 cANADA: [ neurosis            204  shadOw killer  33.6     Winnipeg, MB  ]

    uSA: [ Abuse (telnet/bbs)  305  Jock Itch      28.8     Keywest, FL   ]
         [ Evil Empire         209  Whipe          28.8     Fresno, CA    ]
         [ Hellfire            713  Fryguy         28.8     Houston, TX   ]
         [ HDC (615-395-9228)  615  Burning Angel  28.8     Nashville, TN ]

    fTP: [ xxx.xxx.xx.xx       713  Fryguy         T1       Houston, TX   ]
         [ xxx.xx.xx.xx        916  Archimede      ISDN     Sacramento,CA ]
         [ xxx.xx.xxx.xxx       -   Cool-Hand      T1       YourHouse, XX ]
         [ xx.x.xxx.xxx.x       -   n00dles        T1       BiiaaTCH, CA  ]

pUB fTP: [ alpha.pulsar.net     -   Stumble        T1       Port: 1997    ]

    iRC: [                    #PC97 or #Cracking (EfNet)                  ]
    wEB: [ Primary  :            -= Soon to come =-                       ]
         [ Secondary:     http://www.geocities.com/Paris/5842/            ]
         [ Secondary:      http://www.nca.pt/individual/pcrew/            ]
         [ Secondary:            -= Soon to come =-                       ]

   mY
PeRSOnaL
 gREETS: [              h! mY fRieNDs in TuRkiSH PC sCENE!                ]
         [                             :)                                 ]
         [                                                                ]

   nEWS: [ PhRoZeN CReW is looking for high-quality crackers, asm coders, ]
         [ dupe checkers, couriers and distribution sites (28.8x5+).  If  ]
         [ you're interested, contact tHATDUDE or Archimede by E-Mail or  ]
         [ on IRC.  Enjoy and have fun!                                   ]



                          We ALWAYS get what we want!  -───▄
                      ▀   ▀ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

[Logo design by cH. NFO created by shadow killer ([email protected])] [01/11/97]



FILE_ID.DIZ

tHE      ▄▄▄█▀█▄       ▄██▄
      ▀███▀   ▄█     ▄██▀  ▀
        ██▄▄▄█▀     ▄██
         ██▄ hRoZeN ██▄ ReW ▄
          ██▄        ▀██▄▄▄█▀
           █▀▀         ▀▀▀  '97
┌[pRESENTS]────────────────────────┐
│ ESET LTd. v1.21   *hACK-liCENSE* │
│  hEURiSTiC MaCRO viRUS sCANNER!  │
│        >>> hACKeD bY: eMX!       │
└[dOS/tOOL]──────────────[01-28-97]┘



WHATSNEW.TXT

If you have any ideas or suggestion, don't hesitate please to contact
authors.

If you have any macro virus on your PC which HMVS can't detect by its name,
send it us please. Its recognition will be added into program in few
minutes after its receiving.

1.21      13-jan-96
──────────────────────────────────────────────────────────────────────────
- added detection of new macro viruses

1.20      6-jan-96
──────────────────────────────────────────────────────────────────────────
- more precise detection of viral macros with using CRC16
- less false positive alarm caused by heuristics
- recognition of MS Word / Office'97 documents (without scanning and
  analysing)
- added detection of new macro viruses
- added /FLG cmd line switch for displaying heur. flags

1.10      1-dec-96
──────────────────────────────────────────────────────────────────────────
- new OLE 2 parser
- added detection of streams containing macros in MS EXCEL files
- added few new virus signatures
- fixed all known bugs

1.06      13-oct-96
──────────────────────────────────────────────────────────────────────────
Added detection of new macro viruses.

1.05      1-oct-96
──────────────────────────────────────────────────────────────────────────
/EXT option can now decrypt macros with unlimited size.
HMVS is from now distributed via SimTel too.

1.04      24-sep-96
──────────────────────────────────────────────────────────────────────────
Heuristics was slightly improved. Added new three heuristic flags.
Corrected recognition of asian type of strings (fixed in emul8r).
For selected flags is number of their occurences displayed too.
Added /EXT option for registered user.

1.03      8-sep-96
──────────────────────────────────────────────────────────────────────────
Added some new viruses. Fixed subdirectories scanning bug. Fixed bug
with detecting asian versions of MS Word document.

Warning: This version doesn't scan Excel files, however it always display
         OK after *.XLS filenames, because scan routine isn't yet finished.

1.02      4-sep-96
──────────────────────────────────────────────────────────────────────────
Some hidden bugs were corrected. Added short user manual.

1.01      1-sep-96
──────────────────────────────────────────────────────────────────────────
Detection of 13 new macro viruses has been added.

1.00      25-aug-96
──────────────────────────────────────────────────────────────────────────
First official release. Can recognize directly 28 MS Word macro viruses
+ powerfull & intelligent heuristic scanner.




REGFORM.TXT

       HMVS Registration Form For The Registration Site In Slovakia
---------------------------------------------------------------------------

              Name: __________________________________

Company (optional): __________________________________

           Address: __________________________________

              City: __________________________________

   State, ZIP Code: __________________________________

           Country: __________________________________

           Phone #: __________________________________

             FAX #: __________________________________

            e-mail: __________________________________


type of licence: Single user licence      [ ]
                 Multiple users licence   [ ]  for [   ] users
                 Unlimited users licence  [ ]

Text for registration key (only your true name or name of your
company is allowed) must be from 5 up to 50 characters long !

Registration Text: "--------------------------------------------------"
                    12345678901234567890123456789012345678901234567890

Total payment in equivalent of USD: ___________



------------------------------ cut here ------------------------------


                              Prices:

Single user licence (for 1 user) ....  10 USD (or equivalent)
-----------------------------------------------------------------------

Multiple users licence (for one company or firm)
-----------------------------------------------------------------------
  2nd  - 10th  user .............. 7 USD per user
  11th - 20th  user .............. 5 USD per user
  21st - 50th  user .............. 3 USD per user
  51st - 100th user .............. 2 USD per user
  101st and each next user .....   1 USD per user

Example of payment calculation for 53 users:

   1*10USD + 9*7USD + 10*5USD + 30*3USD + 3*2USD = 219 USD

Unlimited users licence ............. 1000 USD (fixed price)
-----------------------------------------------------------------------
This type of licence is valid for one firm or company with unlimited
number of users !!!

Mail registration form to:  [email protected],
or fax it to fax number:    +42-7-5438230

For invoice please send order to:
                  ESET Ltd.
                  Ondavska 3
           826 47 Bratislava
                  Slovakia

Bank connection:
                  Ludova Banka Bratislava, a.s. (VOLKSBANK)
                  Nam. SNP 15
           810 00 Bratislava
                  Slovakia
account number:   4000533008/3100

You will receive by E-mail your registration key, which will be valid
for all future version of HMVS (no time or version limitations !)




HMVS.TXT

        ┌──────────────────────────────────────────────────────────┐
        │          Heuristic Macro Virus Scanner/cleaner           │
        │                      (user's manual)                     │
        │                                                          │
        │           (c) Jan Valky & Lubos Vrtik, Slovakia          │
        └──────────────────────────────────────────────────────────┘

                           Last update: 6-jan-97

Sorry, this is only short version of DOX, because we're lazzy to
write full DOX :)

Excuse us our english plz, it is not our natural language ;(

IF YOU WANT HELP US TO IMPROVE HMVS, PLZ SEND US ANY COMMENTS OR IDEAS.
NEW MACRO VIRUSES ARE WELCOMED. SEND US PLZ ALL MACRO VIRUSES HMVS CAN'T
DETECT BY NAME.

══════════════════════════════════════════════════════════════════════════
                               CONTENTS

1.   HOW TO USE HMVS
2.   METHODS USED IN HMVS
2.1  Available options, when virus was found
3.   WHAT IS MACRO VIRUS :)
4.   HEURISTIC FLAGS DISPLAYED BY HMVS
══════════════════════════════════════════════════════════════════════════

1.   HOW TO USE HMVS
──────────────────────────────────────────────────────────────────────────

Without paramaters will HMVS scan only *.DOC and *.DOT files in
current directory and all its subdirectories.

Usage: HMVS drive:[\\path] switches
switches:
/H,/?        - this help
/ALL         - scan all files (*.*)
/REP         - output to log file HMVS.LOG
/REP=file    - output to specified log file
/NOH         - disable heuristics, only scanning
/NOS         - disable scanning, only heuristics
/MAC         - prompt if file contains macros
/IA          - nonstop scanning without prompt
/CA          - automatically clean all infected files
/RA          - automatically rename all infected files
/NOB         - disable user break with ESC key
/EXT         - decrypt execute only macros (reg. version only)
/FLG         - enable displaying heur. flags

Short description of command line parameters:

/H
/?           Displays help about HMVS using
/ALL         All files will be scanned (*.*)
             Without this parameter only files *.DOC and *.DOT
             will be scanned.

/REP         Report will be logged to file HMVS.LOG

/REP=file    Report will be logged to user specified file

/NOH         Disables heuristic analysis. Only standard scanning
             method will be used.

/NOS         Disables standard scanning method. Only heuristics
             will be used.
             You can use both switch (/NOS /NOH) together :)
             This combination can save your time, if you want get
             informations about macros in file (use also /MAC
             or /REP switch)

/MAC         If this switch was entered program will stop at each
             file, that contains one or more macros. Otherwise program
             will stop only when file is infected by known virus,
             when file is probably infected or suspected.

/IA          With this option program won't stop on any file.
             You will use probably this option together with /REP
             switch.

/CA          If you want to automatically clean any infected
             or probably infected files, use this switch.
             Files will be cleaned only if creating of backup copy
             was succesfull.

             WARNING: ALL MACROS WILL BE REMOVED FROM INFECTED FILE

             After cleaning you should check if cleaned file is OK.
             If something went wrong, you can restore original
             file from backup copy. If HMVS fails plz send us file, that
             couldn't be cleaned.

/RA          With this switch HMVS'll automatically rename any infected
             or probably infected files.

/NOB         With this option HMVS can't be stopped with ESC key.
             Otherwise you can break program in any time with pressing
             the ESC key.

/EXT         This option allow you to decrypt execute only macros.
             (Available only for registered users).
             With this option you will be prompted at each file
             containing execute-only macro(s), if you want to
             decrypt it. If yes, program will first create a backup
             copy of file (*.VI?) and them decrypt all execute-only
             macros.
             This is nice option for AV researcher or experienced
             users.

             WARNING: If you use this option, scanning is disabled !

/FLG         Enable displaying heur. flags (disabled default)


2.   METHODS USED IN HMVS
──────────────────────────────────────────────────────────────────────────

When MS Word documents or templates are scanned, HMVS do the following:
- searches for macros in document or template
- decrypts each macro (if encrypted)
- uses standard scan method (only macros are scanned, not whole file !)
  Some antiviral product have problem to detect how and where macros
  are placed, so they must scan whole file :)
- uses heuristics
  Each macro is analysed and checked for some operations. If heuristics
  found some checked operation, it set flag for it.

After these operations HMVS displays results of scanning and heuristic
analysis.

HSMV uses two methods to detect macro viruses:

■ Standard method based on 'identifications strings'
  This is well know method frequently used in most virus scanners.
  Search string method is fast and reliable, but can search only for
  known viruses.

  CRC16 method
  This is good method for exact identification of static viral macros.
  However, this method is usable only for old generation of macro viruses

■ Heuristic analysis
  HMVS uses unique heuristic technology. HMVS uses special semi-emulator
  of word macro commands (something like length disassembler, if you
  know, what is it ...). It trace trough each command in macro,
  step by step, and try to understand it.

All methods are good. Standard method can detect macro virus exact by
its name, heuristics can detect known and unknown viruses.

Good antivirus products can use both methods. With large virus databases
they can reach top hit-rate and they can detect unknown viruses too.

Heuristics may produce false positive alarms in same cases. We'we checked
HMVS with some files containing antimacros (for example DOCGUARD.DOC).
Because this file contains macros is doing some operations typical for
viruses, this file for HMVS seems to be infected by a macro virus.

There is an example of false alarm (file DOCGUARD.DOC)

C:\MACRO\WINWORD\DOCGUARD.DOC
Stream: WordDocument (MS Word)
* document contains 7 macros with total length 15065 bytes
{AutoOpen} {Remove} {Install} {AutoClose} {NormalAutoExec} {NormalAutoOpen}
{NormalFileOpen}
! Copies macros into the template ('MacroCopy') [3 x]
+ Contains execute-only (encrypted) macros
+ Detects if macro is execute-only ('IsExecuteOnly()')
+ Uses the 'FileSaveAs' macro command
+ Enables auto macro processing ('DisableAutoMacro')
+ Detects number of macros in template or document ('CountMacros()')
+ Detects macros names in template or document ('MacroName$()')
! Deletes other files ! ('Kill') [2 x]
+ Contains macros but is named *.DOC
! Creates or edits macro ('ToolsMacro .Edit')
Result of heuristics: POLY.CRYPT.COMPANION.MACRO virus

PROBABLY INFECTED WITH A MACRO VIRUS !!!

2.1  Available options, when virus was found
──────────────────────────────────────────────────────────────────────────

If HMVS detect that file is infected, it displays something like
the following example:

Note: Macros enclosed in [] are unencrypted, macros enclosed in {} are
      encrypted.

      Flags used for result of heuristics:

      POLY        - might be polymorph or self modifying or antiheuristic
                    virus
      CRYPT       - encrypted virus
      STEALTH     - uses 'stealth' method
      COMPANION   - companion macro virus (links template with document)
      MACRO       - macro virus

C:\MACRO\WINWORD\XENIXOS\XENIXOS.DOC
Stream: WordDocument (MS Word)
* document contains 11 macros with total length 31342 bytes
{Drop} {Dummy} {AutoExec} {AutoOpen} {Datei╓ffnen} {ExtrasMakro}
{DateiBeenden} {DateiDrucken} {DateiSpeichern} {DateiSpeichernUnter}
{DateiDruckenStandard} 
! Copies macros into the template ('MacroCopy') [60 x]
+ Contains execute-only (encrypted) macros
+ Uses the 'FileSaveAs' macro command
+ Disables global template write access warnings
+ Enables auto macro processing ('DisableAutoMacro')
- Might prevent the ESC key from interrupting a macro ('DisableInput')
+ Detects number of macros in template or document ('CountMacros()')
+ Detects macros names in template or document ('MacroName$()')
- Gets parameters from WIN.INI or WINWORD6.INI ('GetProfileString$()')
! Executes other DOS or Windows programs ! ('Shell') [1 x]
! Writes directly to a sequential file ! ('Print #') [381 x]
+ Changes DOS attributes of other files ('SetAttr')
- Changes current directories ('ChDir')
- Opens a sequential file for input or output of text ('Open #')
- Closes an open sequential file ('Close #')
+ Contains macros but is named *.DOC
Contains virus pattern:  
Result of heuristics: CRYPT.MACRO virus

INFECTED WITH A MACRO VIRUS !!!

1-Skip  2-Remove all macros  3-Rename file  4-Ignore all
5-Automatically remove all macros  6-Automatically rename all files  :

Now program waits for user input ...

Available actions:

1-Skip
  Program will do nothing. It skips this file and will continue searching
  for the next files
2-Remove all macros
  At first backup copy will be created. Then ALL macros from file
  will be removed (each macro will be overwritten with nice text :)
3-Rename file
  Renames file to *.VI?
4-Ignore all
  Do nothing with all files. Like 1, but for any next file
5-Automatically remove all macros
  Like 2, but for any next file
6-Automatically rename all files
  Like 3, but for any next file

3.   WHAT ARE MACRO VIRUSES :)
──────────────────────────────────────────────────────────────────────────

If you don't know what are macro viruses, you have big chance to be
a potential victim of macro viruses :)
Don't worry, HMVS is here to solve your problems (we hope ...)

4.   HEURISTIC FLAGS DISPLAYED BY HMVS
──────────────────────────────────────────────────────────────────────────

Current version of HMVS can detect the following flags:
(Currently we do not plan to add new flags in next version)

! Copies macros into the template ('MacroCopy')
+ Might copy macros to template with using 'Organizer .Copy'
! Copies macros to template with using 'Organizer .Copy'
! Adds a template or WLL to the list of global templates ('AddAddIn')
+ Contains execute-only (encrypted) macros
+ Detects if macro is execute-only ('IsExecuteOnly()')
+ Uses the 'FileSaveAs' macro command
+ Disables global template write access warnings
+ Enables the fast save option 'FastSaves'
- Might enable auto macro processing ('DisableAutoMacro')
+ Enables auto macro processing ('DisableAutoMacro')
- Might prevent the ESC key from interrupting a macro ('DisableInput')
+ Prevents the ESC key from interrupting a macro ('DisableInput')
+ Detects number of macros in template or document ('CountMacros()')
+ Detects macros names in template or document ('MacroName$()')
- Sets up a background timer that runs a macro at the specified time ('OnTime')
- Gets parameters from WIN.INI or WINWORD6.INI ('GetProfileString$()')
- Sets parameters in WIN.INI or WINWORD6.INI ('SetProfileString$()')
- Gets parameters from initiating file ('GetPrivateProfileString$()')
- Sets parameters in initiating file ('SetPrivateProfileString$()')
+ Removes document protection ('LockDocument')
- Manipulates with protection for form fields
- Removes protection for form fields
- Renames menu items ('RenameMenu')
! Executes other DOS or Windows programs ! ('Shell')
! Deletes other files ! ('Kill')
! Writes directly to a sequential file ! ('Write')
! Writes directly to a sequential file ! ('Print #')
+ Removes directory ('RmDir')
+ Changes DOS attributes of other files ('SetAttr')
- Detects number of subdirectories ('CountDirectories')
- Changes current directories ('ChDir')
- Opens a sequential file for input or output of text ('Open #')
- Closes an open sequential file ('Close #')
+ Makes available a routine stored in DLL or WLL 4 use in a macro ('Declare')
- Detects environment variable ('Environ$')
+ Contains macros but is named *.DOC
- Detect whether the active document was changed ('IsDocumentDirty()')
+ Converts document to the template ('FileSaveAs .Format = 1')
+ Sets a password for opening the document ('FileSaveAs .Password = ')
! Creates or edits macro ('ToolsMacro .Edit')

!   means dangerous operation
+   means warning (suspect)
-   only for your information

Sorry, we haven't time to explain these messages. We thinking for AV
researchers and experienced users it is sufficient.

We can add detailed descriptions in next release, if we'll get lot of
requests and questions.

     ───────────────────────   that's all    ───────────────────────────

BTW, We don't like user's manual writting ...



# 0 1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z