Threat Encyclopaedia | Vytlačiť stránkuPoslať |
On the 31st day in a month it displays the following window with message:
The virus exports its code into the file c:class.sys; upon attacking documents and global template it imports its code from that file. The virus code in the infected file cannot be seen in the Word list of macros by means of the menu item Tools/Macro because W97M/Class.A stores its module into the area "class".
Polymorphic mechanism of the virus is ingeniously simple. The W97M/Class.A inserts a line with a note between each line of the code and a line of its code. Text of the note is formed by name of the Word user, current time and date, name of the active printer and again the current time and date. The inserted line could look as follows:
'replicator7/7/98 8:17:40 PM//KILLER/HP7/7/98 8:17:40 PM