W97M/Groov.A
Analysis
- Virus consists of one macro module named either
"groovie" or "orbit"
- Virus hooks Word event handlers which prevents
the printing, opening, closing and saving of infected
documents, or exiting Word
- In a one in five chance, virus will attempt to save host IP information as "c:\ip.txt", then send this file using FTP to "complex.is" to the "incoming" directory