Content
W97M/Dariem
- Type
- Virus
- SubType
- Macro
- Discovery Date
- 05/24/2000
- Length
- Minimum DAT
- 4080 (05/31/2000)
- Updated DAT
- 4080 (05/31/2000)
- Minimum Engine
- 5.1.00
- Description Added
- 08/02/2001
- Description Modified
- 09/18/2002 10:22 AM (PT)
Tab Navigation
Characteristics
This virus infects Word 97 documents and executes when a Word document is opened, closed, or created.
This virus changes the author, title, subject, keywords, and the comment property of the ActiveDocument.
When a document is closed, the virus checks to see if the date is February 3 or 26. This virus creates a password "Dariem" which is needed to open the ActiveDocument. This virus stores the code from the ActiveDocument to a variable. If the variable is empty, the virus assigns the source code from the GlobalTemplate to a variable, deleting the code from the ActiveDocument, and inserting its viral code from the variable into the ActiveDocument.
If the variable does not contain an infection marker, the virus deletes the code of the ActiveDocument and inserts the exact same code from the variable to the ActiveDocument.
When a Word document is created, this virus disables the VirusProtection, SaveNormalPrompt & ConfirmConversions properties. This virus changes the author, title, subject, keywords, and the comment property of the ActiveDocument. This virus assigns the source code from the GlobalTemplate to a variable, deletes the code from the active document, and copies the code into the ActiveDocument from the variable.
If the date is February 3 or 26, this virus changes the footer text to "MENSAJE", and disables the DocumentMap and the Header and Footer menu items under the View menu. On any other day this virus sets the footer text to an empty string. This virus disables the ALT-F11 hotkey (Visual Basic Editor) and the ToolsMacro menu item.
When a Word document is opened, this virus stores the code from the GlobalTemplate to a variable. If the variable is empty, this virus assigns the source code from the GlobalTemplate to a variable, deleting the code from the ActiveDocument, and inserting its viral code from the variable into the ActiveDocument.
If the variable does not contain an infection marker, this virus deletes the code of the GlobalTemplate and inserts the exact same code from the variable to the GlobalTemplate.
Symptoms
Method of Infection
Removal
Use current engine and DAT files for detection and removal.
It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.
AVERT Recommended Updates:
* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch)
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- W97M/Dariem.A
Characteristics
Characteristics -
This virus infects Word 97 documents and executes when a Word document is opened, closed, or created.
This virus changes the author, title, subject, keywords, and the comment property of the ActiveDocument.
When a document is closed, the virus checks to see if the date is February 3 or 26. This virus creates a password "Dariem" which is needed to open the ActiveDocument. This virus stores the code from the ActiveDocument to a variable. If the variable is empty, the virus assigns the source code from the GlobalTemplate to a variable, deleting the code from the ActiveDocument, and inserting its viral code from the variable into the ActiveDocument.
If the variable does not contain an infection marker, the virus deletes the code of the ActiveDocument and inserts the exact same code from the variable to the ActiveDocument.
When a Word document is created, this virus disables the VirusProtection, SaveNormalPrompt & ConfirmConversions properties. This virus changes the author, title, subject, keywords, and the comment property of the ActiveDocument. This virus assigns the source code from the GlobalTemplate to a variable, deletes the code from the active document, and copies the code into the ActiveDocument from the variable.
If the date is February 3 or 26, this virus changes the footer text to "MENSAJE", and disables the DocumentMap and the Header and Footer menu items under the View menu. On any other day this virus sets the footer text to an empty string. This virus disables the ALT-F11 hotkey (Visual Basic Editor) and the ToolsMacro menu item.
When a Word document is opened, this virus stores the code from the GlobalTemplate to a variable. If the variable is empty, this virus assigns the source code from the GlobalTemplate to a variable, deleting the code from the ActiveDocument, and inserting its viral code from the variable into the ActiveDocument.
If the variable does not contain an infection marker, this virus deletes the code of the GlobalTemplate and inserts the exact same code from the variable to the GlobalTemplate.
Symptoms
Symptoms -
Method of Infection
Method of Infection -
Removal -
Removal -
Use current engine and DAT files for detection and removal.
It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.
AVERT Recommended Updates:
* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch)
Variants
Variants -
N/A