Threat Description

Cont

Details

Aliases:Cont, Blaster, Dream Blaster
Category:Malware
Type:Virus
Platform:W97M

Summary



W97M/Cont is a Word 97 class infector. It contains a destructive payload.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details




Variant:Cont.A

When an infected document is opened, W97M/Cont.A disables Word's built-in macro virus protection.

When the document is closed, it infects the global template. During infection the virus creates a temporary file, "c:\cont.dbl", and deletes it afterwards.

At random times the virus changes the document summary information as follows:

 Title: Macro Carrier
 Subject:  Dream Blaster
 Keywords: Minny

Every 17th day of each month, the virus checks for existence of "c:\minny.log" file. If the file does not exist, the virus appends several commands to the end of the "c:\autoexec.bat". These commands attempt to remove everything from "C:", "D:", "E:" and "F:" drives when the system is restarted.





Description Created: Analysis: Sami Rautiainen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More