W97M/Footer.A

description-logoAnalysis

  • Virus consists of one macro module within the class storage
  • Virus hooks Word event handlers which prevents the creating, opening or closing of infected documents
  • Virus adds a document property named "FootPrint1" to document during infection which is used to determine if a host file is infected already
  • Virus adjusts the footer property of an infected document to indicate the full path of the infected document, potentially over writing any footer property which may already exist

Telemetry logoTelemetry