SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : Network Associates (NET) -- Ignore unavailable to you. Want to Upgrade?


To: AlienTech who wrote (4526)3/26/1999 9:19:00 PM
From: AlienTech  Respond to of 6021
 
Woopie another virus outbreak. So dont use outlook. If you get infected it invokes an open Outlook session to send a message to the first 50 address book entries in it.

Melissa is a Word 97 Class Module Macro virus that can also be upconverted to a Word 2000 Macro Virus.

Symptom

The virus can infect a system by being received from another infected user via Outlook. This appears to be the most common method of infection. Users will not know they have been infected, nor will the sender know the document has been sent. A user may become alerted to the infected document if the Macro Security settings are enabled. This warning will be displayed to the user when the document is opened.

Pathology

When the infected document is opened, the virus checks for a setting in the registry to test if the system has already been infected.

If the system hasn't been infected, the virus creates an entry in the registry: HKEY_CURRENT_USER\Software\Microsoft\Office\"Melissa?" = "... by Kwyjibo"

(If this key exists the email process will not execute, the virus will still infect. AVERT advises that it not be removed.)

This virus also creates an Outlook object using Visual Basic instructions and reads the list of members from Outlook Global Address Book. An email message is created and sent to the first 50 recipients in the Global Address Book, one at a time. The message is created with the subject

"Important Message From – <User Name>"

The message body of text reads

"Here is that document you asked for ... don't show anyone else ;-)".

The active infected document is attached and the email is sent. The most prevalent document being seen is one called List.DOC, however this is NOT the only document that can be sent or received. Once the system is infected all documents that are opened are infected. As any document can be sent, a user that receives the infected document, who hasn't been infected, can become infected with this document, and the process will continue.

The virus does have a payload. If the day equals the minute value, and the infected document is opened this text is inserted at the current cursor position:

" Twenty-two points, plus triple-word-score, plus fifty points for using all my letters. Game's over. I'm outta here."

This virus checks for low security in Office2000 by checking the value from the registry; if the value HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\"Level" is not null,

the virus will disable the "MACRO/SECURITY" menu option. Otherwise Word97 menu option "TOOLS/MACRO" is disabled.

avertlabs.com