Virus.MSWord.Pendron

Class Virus
Platform MSWord
Description

Technical Details

This is a stealth macro virus. It contains 13 procedures in module “XBoss”:
Boss41, ToolsCustomize, ViewVBCode, FilePrintPreview,
FilePrintPreviewFullScreen, ToolsMacro, ToolsOptions, FileSaveAs,
AutoClose, AutoExec, AutoOpen, PlanetJangkit, TularComputer.

The virus infects global macros area on opening an infected document
(AutoOpen), and infects other documents on their opening and closing
(AutoOpen, AutoClose).

The virus turns off the Word virus protection (the VirusProtection option)
and all Word sounds. It also hides the “Templates and Add-Ins…” menu
(stealth).

On infecting the virus modifies MS Word properties:


UserName = “Pendron”
UserInitials = “Gunadarma”

On entering the “ToolsMacro” menu the virus asks for a password:


Pendron Security
Enter Your Password:

If entered text is not “princess” the virus displays the message:


Pendron GN’R Production
You Wrong My Friend !!!

If 11th day of month falls on Sunday the virus displays MS Word baloon:


Hallo Sobat Semua….
Salam Buat Anak-Anak Gunadarma From Pendron