Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Threats » O97M/Cybernet

Overview

Threat Risk LOW LOW
Destructivity LOW LOW
Payload
Detection files published 26 May 2000 03:00:00
Description created 26 May 2000 03:00:00
Description updated 08 Nov 2001 02:25:00
Malware type VIRUS
Alias
Spreading mechanism EMAIL
Summary None

O97M/Cybernet

Spreading

The first time O97M/Cybernet is interpreted it wil use MS Outlook to send itself to the 50 first entries in MS Outlook adress-book (not MS Outlook Express).It will only do this email routine once, as it sets a marker in the registry that it checks before trying to email.After this the virus will infect Word documents and Excel spreadsheets when they are opened. It spreads in Word document by infecting the normal.dot template, and infects Excel spreadsheets by dropping a file in Excel's startup-path (XLSTART).It turns off virusprotection settings in Office97 and Office2000.

Payload Details

The virus trigger its payload routine on 17 August and 25 December.

It will then insert random shapes and figures in active Word document and random notes in active Excel spreadsheets.

Then it will insert a text into the autoexec.bat file to write the following message:


#########################################################
# Vine…Vide...Vice...Moslem Power Never End... #
# I'm Really Sorry, This System Have Been Recycled By -= CyberNET =- Virus!!! #
# Brought To You From INDONESIA... #
##########################################################

Further it will write a "format c:" command to the autoexec.bat file and show a message box:


(Image not available)

When the the user push the "OK" button the virus will force a reboot.

Analysis

n/a

Removal

n/a


Last Updated: 12 Nov 2015 11:06:14