Sophos

WM97/Lebone-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Infected files
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 16 May 2005 18:52:36 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

WM97/Lebone-A is a macro virus for Microsoft Word that adds a viral macro to the active document when the document closed.

When an infected document is opened, WM97/Lebone-A displays the folllowing message " Virus alterou seu computador !!" with the title "Word texto informa!!"

WM97/Lebone-A copies itself to the root, Windows system, Program files and Command folders with the following corresponding filenames:
Lubir.sys, igon.sys, Lubi.sys and Nidun.sys.

WM97/Lebone-A also creates a Lubi.html file in the Arquivos de programas folder and sets the registry entries:

HKCU\Software\Microsoft\Office\9.0\Word\Security
Level
1&

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

HKLM\Software\Microsoft\Windows\CurrentVersion
Lune
Virus ativado

HKLM\Software\Microsoft\Windows\CurrentVersion
RegisteredOrganization
Universal

HKLM\Software\Microsoft\Windows\CurrentVersion
RegisteredOwner
Astral

HKLM\Software\Microsoft\Windows\CurrentVersion
Version
13A31-Infected

HKLM\Software\Microsoft\Windows\CurrentVersion
VersionNumber
1313BA13 Astral

"HKLM\Software\Microsoft\Windows\CurrentVersion
ProductName
Electron

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Visual
Lube.html

When opened Lube.html displays a graphic message with the title "Macro virus!" and following running strings:
"Computador com problemas!"
"Word modificado com sucesso!"
"Word macro virus!"

WM97/Lebone-A attempts to stop processes associated with files that are located in the Windows, Windows system and Windows Command folders, and that have either EXE or COM extension.

Also on the 6th, 13th, 17th, 23rd and 28th WM97/Lebone-A displays the message " Virus modificou seus arquivos!!", "Word texto informa!!" and attempts to stop processes associated with files that are located in the root and Windows folders, and that have one of the following extensions:

COM, INI, TXT, GIF, XLS, PDF

WM97/Lebone-A modifies the active document by inserting the string:
"A vida pode ser feliz!!"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer