Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 16 May 2005 18:52:36 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for disinfecting macro viruses.
Please contact technical support.
More Information
WM97/Lebone-A is a macro virus for Microsoft Word that adds a viral macro to the active document when the document closed.
When an infected document is opened, WM97/Lebone-A displays the folllowing message " Virus alterou seu computador !!" with the title "Word texto informa!!"
WM97/Lebone-A copies itself to the root, Windows system, Program files and Command folders with the following corresponding filenames:
Lubir.sys, igon.sys, Lubi.sys and Nidun.sys.
WM97/Lebone-A also creates a Lubi.html file in the Arquivos de programas folder and sets the registry entries:
HKCU\Software\Microsoft\Office\9.0\Word\Security
Level
1&
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1
HKLM\Software\Microsoft\Windows\CurrentVersion
Lune
Virus ativado
HKLM\Software\Microsoft\Windows\CurrentVersion
RegisteredOrganization
Universal
HKLM\Software\Microsoft\Windows\CurrentVersion
RegisteredOwner
Astral
HKLM\Software\Microsoft\Windows\CurrentVersion
Version
13A31-Infected
HKLM\Software\Microsoft\Windows\CurrentVersion
VersionNumber
1313BA13 Astral
"HKLM\Software\Microsoft\Windows\CurrentVersion
ProductName
Electron
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Visual
Lube.html
When opened Lube.html displays a graphic message with the title "Macro virus!" and following running strings:
"Computador com problemas!"
"Word modificado com sucesso!"
"Word macro virus!"
WM97/Lebone-A attempts to stop processes associated with files that are located in the Windows, Windows system and Windows Command folders, and that have either EXE or COM extension.
Also on the 6th, 13th, 17th, 23rd and 28th WM97/Lebone-A displays the message " Virus modificou seus arquivos!!", "Word texto informa!!" and attempts to stop processes associated with files that are located in the root and Windows folders, and that have one of the following extensions:
COM, INI, TXT, GIF, XLS, PDF
WM97/Lebone-A modifies the active document by inserting the string:
"A vida pode ser feliz!!"
