Threat Description

Razer

Details

Aliases:Razer
Category: Malware
Type:
Platform: W32

Summary



This is a simple Word macro virus.

It creates the following macros to NORMAL.DOT: AutoOpen, WordSystem, WinUpdate, FileSave and FileSaveAs - unless the user is running Portuguese version of Word. In that case, the last two macros are replaced by FicheiroGuardar and FicheiroGuardarComo.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



When the virus infects a machine for the first time, it attempts to display a dialog box with these texts:

MoRTaLs aRe UnaBLe To HanDLe THe PoWeR ! ! !
  GOD LIVES IN HELL...

When 100 files have been opened after infection, the virus tries to delete the current command interpreter. This would prevent the machine from booting.

WM/Razer.A was reported to be in the wild in UK in early 1998.

[MHH//DF]






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More