Threat Description

PayCheck

Details

Aliases: PayCheck, Bukit
Category: Malware
Type:
Platform: W32

Summary



For more information on Word macro viruses, see the description of WordMacro/Concept.

WordMacro/PayCheck is an encrypted macro virus. It contains seven macros: AutoExec, AutoOpen, FileSave, FileSaveAs, ToolsMacro, ShellOpen, FileOpen.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details



PayCheck actives on the 25th of any month. At this time it displays this dialog box:

 Selamat
   Sekarang adalah tanggal 25, sudahkah anda mengambil gaji?
   He..he..Selamat. Kalau bisa, lebih keras lagi kerjanya.
   Bravo Bukit Asam !!!

Opening the File/SaveAs menu might display this dialog box:

 Non Critical Error
   Internal error was occured in module UNIDRV.DLL
   Your application may not be work normally.
   Please contact Microsoft Product Support.

Opening the Tools/Macro menu might display this dialog box:

 Critical Error
   Internal error was occured in module UNIDRV.DLL
   Please contact Microsoft Product Support.

PayCheck was reported to be in the wild in fall 1997.





Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More