While infecting the system the virus receives the control in AutoClose
document, renames DMV macro to FileSaveAs, then renames AutoClose to DMV.
While infecting the files (FileSaveAs) the virus renames these macros back
DMV -> AutoClose, FileSaveAs -> DMV.
One of the strings in the virus body looks like follows:
|Find out the statistics of the threats spreading in your region|