Virus Characteristics
This threat is detected as W97M/Generic. The virus contains one module - Kefko. It will disable the macro warning protection for Word and exports its code to c:\Kefko.sys. This file is not infected.
The virus will change the Username to
Dr.Virus. It will also add the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion RegisteredOwner = Dr.VirusThe following information will be added to File/Summary/Author = Dr.Virus, Comments = WM97.Kefko and Keywords = Všetko je OK.
The following AntiVirus files will be deleted:
- C:\PROGRAMME\MCAFEE\VIRUSSCAN\*.*
- C:\PROGRAMME\MCAFEE\VIRUSSCAN95\*.*
- C:\Programme\Dr Solomon's\Anti-Virus Toolkit\*.*
- C:\PROGRAMME\TBAV\TBAV.DAT
- C:\TBAV\TBAV.DAT
- C:\Programme\Norton Antivirus\V32scan.dll
- C:\Programme\Norton Antivirus\Virscan.dat
On the 19th of any month, the following message will be displayed:
Tools/Macro, Tools/Visual Basic Editor, Format/Style and File/Templates will display the following message: