This is the second known macro virus infecting MS PowerPoint presentations.
It contains five macros in one module “ShapeShift”: actionhook, SlideIn,
WackShape, RandomWackSlide, WackPresentation.
To activate its code on a event the virus hooks MouseClick that pass
control to the virus “actionhook” macro. This macro runs the infection
routine: the virus affects all active presentations, then searches for
presentation files in the current directory and subdirectories and infects
Depending on the system random counter the virus changes the active slide
number. Also depending on the random counter the virus displays the
PPT.ShapeShift v0.1 /1nternal