Search Solo Products, Services and others Overview of the Site Design and Build a Career Contact us for customer service and other feedback info SRN Micro Privacy Statement

 


A NEW MASS MAILER WITH DEADLY PAYLOAD REPORTED

Virus Name  : W97M/Resume

Alias             : Macro.Word97.Resume, W97M.Resume

Virus type    : Word Macro Virus

Threat level : Low

Virus details :

                     W97M/Resume is a word macro worm makes use of the MAPI functions in Microsoft Outlook to retrieve the current user profile and password for server logon. This worm grabs e-mail addresses from the address book of Microsoft Outlook and resends the mail. It is very similar to Melissa virus. It won't infect any document in the system but will delete files in the mapped drives.

                     The email will contain the subject line: "Resume - Janet Simons" and the message body will be

"To: Director of Sales/Marketing,

Attached is my resume with a list of references contained within.

Please feel free to call or email me if you have any further questions
regarding my experience. I am looking forward to hearing from you.

Sincerely,

Janet Simons."

                     When the the attachment "explorer.doc" is opened it will mail first. If Outlook is not installed or not configured, it will fail to mail. Then it will wait for close of document. When the document is closed it will copy to "C:\WINDOWS\Start Menu\Programs\StartUp\Explorer.doc" and "C:\Data\Normal.dot".Then it will delete the following files.

                     "C:\*.*"
                     "C:\My Documents\*.*"
                     "C:\WINDOWS\*.*"
                     "C:\WINDOWS\SYSTEM\*.*"
                     "C:\WINNT\*.*"
                     "C:\WINNT\SYSTEM32\*.*"
                     "A:\*.*"
                     "B:\*.*"
                     "D:\*.*"
                     "E:\*.*"
                     "F:\*.*"
                     ...........
                     ...........

                     "Y:\*.*"
                     "Z:\*.*"

Inside the virus code following text is there within comments

'----------------------------------------------------------'
' Better You Than Me Buddy... '
' ... Hope You Like My vIrUs '
' :) '
' :( '
'----------------------------------------------------------'

How can I protect my system?

                   Solo has incorporated W97M/Resume in its signature file to protect users from this virus attack. Solo antivirus registered users are already protected from this virus. Make sure that you have installed registered version of Solo Antivirus to protect your system from all virus threats.

How to remove W97M/Resume virus?

                   If you are already infected with this virus, you can remove it from your computer using Solo Antivirus software. Solo antivirus can detect and remove W97M/Resume virus safely. Use the following link to Download 30 day trial version of Solo antivirus to remove viruses from your computer.

                   Solo anti-virus not only scans for all viruses, it contains a unique System Integrity Checker to protect you from New Internet Worms, Backdoors and malicious VB, Java Scripts. It also effectively removes all existing Internet Worms, File viruses, malicious VB, Java scripts, Trojans, Backdoors, boot sector, partition table and macro viruses.

You can purchase Solo antivirus using the link