|
VIRUSES- DESTROYER OF COMPUTERS (AVERT) W97M/Melissa.AO virus W97M/Melissa.AO This e-mail spreading Microsoft Word 97/2000 macro virus / worm uses the same infection routine as Melissa.A but has a different payload. When the infected document is opened, the virus disables four Word options - Tools\Macro command bar, Virus Protection, SaveNormalPrompt and ConfirmConversions. It will also set the registry key: HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\Level = 1 and disable the menu item called Macros/Security. Melissa.AO then checks the registry value: HKEY_LOCAL_MACHINE\Security\ActiveWorm and if it is not set to "Worm Empire", the virus assumes that the computer has not been infected and executes the infection payload. The infection payload uses the Microsoft Outlook address book to send a copy of the infected email to the first 50 individuals or groups listed in the address book. The email will have the subject line: "Extremely URGENT: To All E-Mail User - " and Date. The body will contain a copy of the infected document and the message: "This announcement is for all E-MAIL user. Please take note that our E-Mail Server will down and we recommended you to read the document which attached with this E-Mail." If the recipient opens the document they can be become infected with the Worm and it will attempt to spread to other users if they use Microsoft Outlook. The infected document only contains one macro which is Document_Open in the infected documents, and it will be Document_Close in infected Normal Templates. If this macro already exists, the virus will copy the code to a module named Worm_Empire and then overwrite DocumentOpen/Close with its own source code. During infection the worm will create the registry value HKEY_LOCAL_MACHINE\Security\ActiveWorm and set it to "Worm Empire". The virus payload triggers at 10 AM on the 10th day of any month. The file being worked on can be saved five times in the current directory with the filenames being the current Date & Month & Year & Second and the number from 1 - 5 eg. 103200011(1-5).doc. The virus then inserts the message "Worm! Let's We Enjoy!" into each of the documents. This virus has been seen in the field.
|
||||||||||||||||||||||||||||||||||||||
|