Prevent Online Threats

Macro.Word.Candyman

Details
Macro.Word.Candyman.a

The macro viruses of this family contain three macros:
“Candyman.a”: Autoopen, Candyman, AutoClose
“Candyman.b”: Autoopen, Dyatrima, AutoClose

They infects the global macros area on opening an infected document (AutoOpen), and infect other documents on their closing (AutoClose).
On 25th of any month the “Candyman.a” virus deletes all files in folders C:\WINDOWS and C:\DOS. Then it displays the message:
No se olviden de CABEZAS -Pierri y Duahlde
PUTOS-Cabezas Virus by CANDYMAN Bs. As. Argentina

The “Candyman.b” virus drops and executes the DYA.COM file infected by the DOS overwriting virus “HLLO.Candym”.

Related Posts

  • Candy.99
  • Macro.Word.Minima
  • Macro.Word.EM
  • Macro.Word.Misspelle
  • Macro.Word.Haggi
  • Leave a Reply


    Spyware Removal Spyware Protection Tools