Virus.MSWord.Defender

Class Virus
Platform MSWord
Description

Technical Details


This macro virus contains six macros:


Documents: AutoOpen, Defend, Module1, Module2, Module3, Module4
NORMAL.DOT: FileSaveAs, ToolsMacro, FileOpen, Defender, Module1, Module2

It infects the global macros area on opening an infected document
(AutoOpen), and writes itself to documents that are saved with new name
(FileSaveAs). While entering the ToolsMacro menu the virus requests for a
password. The password is the same as the active document file name.


The virus disables several viruses or warns a user: while infecting a
document or NORMAL.DOT the virus checks it for “Concept” virus macros and
several other macros, then it deletes them. Depending on several conditions
the virus displays the MessageBoxes:


Defender
ALERT! Autorunning macro (possibly virus)
detected in document. Press OK to disable
Defender
WARNING: Active macro virus found. Defender will now exit Word.
You must then restart Word and try to load the document again

The virus contains the comments:

*****************************************************************
Macro : Defender
Created : August 29, 1995 (modified on October 1 1996)
Copyright (c) 1995 Microsoft Corp.
Description : On FileOpen, detect documents containing autorunning
macros and remove them
*****************************************************************