SECURITY ALERT

Name:      W97M/Melissa.ao-mm
Aliases:   W97M/Melissa-ao-mm,Melissa.ao-mm
Variants:  
Platforms: Microsoft Word '97 (including all SRx versions)/MAPI (Outlook)
Status:    Not known to be in the wild
Threat:    Low

The following information was derived from information received from Network Associates and Sophos.

Virus Characteristics

This variant of Melissa is similar to other Melissa variants, but with a few minor changes. The subject of the e-mail containing the worm is: "Extremely URGENT: To All E-Mail User - (Date)" The body of the e-mail is:

This announcement is for all E-MAIL user. Please take note that
our E-Mail Server will down and we recommend you to read the
document which attached with this E-Mail.

Payload

The virus will attempt to e-mail itself to the first fifty entries it finds in the Outlook address book. On the 10th day of every month, and at some point within the 10th hour of that day, the virus will save the current document under five new file names, derived from the current date and time. It will also insert the following text string into the top of the document in large italic letters: "Worm! Let's We Enjoy."

Once it has e-mailed itself, it will modify the registry so that it will not re-deploy itself. The registry key is: HKEY_LOCAL_MACHINE\Security\ActiveWorm

Key: HKEY_LOCAL_MACHINE\Security\ActiveWorm
Value: Worm Empire

< - Virus Information Index - >



CONTACT US

SITEMAP
PRIVACY POLICY