Description
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Indication of Infection
Macro warning when opening infected document on non-infected system, and macro warning is enabled before hand. Files are deleted from the STARTUP folder in Office97/2000.
If the current day is March 5, August 8 or December 22, and MS Office Assistant (MSA) is installed, this message will be displayed using the MSA:
"ReYoKh Team Labs mengucapkan"
"Selamat Ulang Tahun !!!"
"untuk [Name] bahagia selalu"
In the above message, [Name] can be one of three words: "REZA", "YOMBI" or "NELIS".
Methods of Infection
This virus hooks Word event handlers in an effort to maximize the chance of running its code. The following methods can invoke the macro routines:
opening, closing, saving or creating a document.
If the code is allowed to run, this virus first writes a temporary file in the STARTUP folder for Office named "EcHa". This temp file is then used to transfer code between infected file and new host document. The temp file is deleted along with any files which may be stored in the STARTUP folder.
Aliases
WM97/Touchme-A