Virus.MSWord.Friends

Class Virus
Platform MSWord
Description

Technical Details


This is encrypted virus containing 20 macros:


AutoOpen, AutoExec, DateiÖffnen, DateiNeu, DateiSchlie�en, DateiBeenden,
Talk, Fast, Abbrechen, Infizieren, DateiSpeichern, DateiSpeichernUnter,
FileOpen, FileNew, FileExit, Cancel, FileSave, FileSaveAs, ExtrasMakro,
ExtrasMacro

It infects the files that are accessed in several ways – creating, opening
and closing. The virus creates [Friends] section in WIN.INI file and writes
the string to there:

Author=Nightmare Joker

The virus in some cases also calls “Fast” and “Talk” macros.


Macro “Fast” depending on the system timer creates the FAST.COM file
infected by DOS virus “LittleBrother.395”. To do that the virus writes the
virus hexadecimal dump to disk file C:DOSFAST.SCR, creates and writes the
commands


@echo off”
debug < fast.scr > nul
@echo off”
fast.com”

to C:DOSSTART.BAT file and runs this BAT file. Being executed, START.BAT
runs DEBUG.EXE and created infected FAST.COM file (DOS virus dropper). The
virus then deletes the files START.BAT and FAST.SCR, and overwrites the
C:AUTOEXEC.BAT with the commands that run virus dropper on DOS loading:

@echo off
c:dosfast.com

Macro “Talk” depending on “sCurrency” MS Word variable displays the message
boxes in English or German and gets the text string (“My name is:” input):

Hallo mein Freund!
Ich bin der << Friends >> Virus und wie hei�t du? Gib doch bitte
anschlie�end unten deinen Namen ein:
Hello my Friend!”
I’m the << Friends >> Virus and how are you? Can you give me your name,
please:
Mein Name ist:
My name is:
Also [name] ich habe eine gute und eine schlechte Nachricht für
dich! Die schlechte Nachricht ist, da� ich mich auf deiner Platte
eingenistet habe und die gute ist, da� ich aber ein freundlicher und auch
nützlicher Virus bin. Drücke bitte OK f�r Weiter!
Wenn du mich nicht killst, dann füge ich ein Programm in deine
Autoexec.bat ein, da� deine lame Tastatur etwas auf Touren bringt. Also
[name], gib dir einen Ruck und kill mich nicht. Goodbye!
Hello [name] I have a good and a bad message for you! The bad message is
that you have now a Virus on your Harddisk and the good message is that
I’m harmless and useful. Press OK!
If you don’t kill me, I will insert a programme in your AutoExec.bat thats
your Keyboard accelerated. Please [name] don’t kill me. Goodbye!

where [name] is the string entered in “My name is:/Mein Name ist:”.


When extracting macros menu items are run (macros “ExtrasMacro” or
“ExtrasMakro”) the virus displays the message boxes:


Hello my friend! << Friends >> Virus
You can’t do that! I’m very anxious!
Hallo mein Freund! << Friends >> Virus
Du kannst das nicht tun! Ich bin sehr ängstlich!