| Description:
|
Details
Macro.Word97.Metamorph
It is a stealth macro virus. It contains five functions in documents in the one module "Metamorph": AutoOpen, FileTemplatesTemp, ToolsMacroTemp, ViewVBCodeTemp, AutoExecTemp. In the NORMAL.DOT the virus contains six functions in one random named module: FileSaveAs, AutoOpenTemp, FileTemplates, ToolsMacro, ViewVBCode, AutoExec. The name of this module is saved in the METAMORPH.INI file in section [Infected] in line Reponse.
The virus infects the global macros area on opening an infected document. Other documents get infection on saving with new name (FileSaveAs). The code of virus is different in documents and NORMAL.DOT - the virus modifies it while copying itself into the system. It creates new infection function FileSaveAs and stealth-functions ToolsMacro and ViewVBCode. While infecting documents the virus imports its original code from the C:METAPH.LOG which is created when the virus infects the system.
When Word starts the virus changes the names of menu items "File", "Edit", "View", "Format" with their french variants. Depending on the system date and time the virus displays the MessageBoxes:
Virus Metamorph
Attention, j'ai contaminé votre ordinateurall
Virus metamorph
Il est
L'heure de metamorph
Virus Metamorph
Au revoir...
Virus Metamorph
Poufffff!!!!!!
On displaying the last MessageBoxes the virus erases the files:
C:WindowsSystem*.*
C:WindowsCommand*.*
C:Windows*.Com
C:Dos*.* |