Threat Description



Category: Malware
Platform: W32


XM/Robocop is a simple Excel and Excel 97 macro virus.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.

Technical Details


When an infected workbook is opened, the virus creates a new workbook, infects it and saves it to the Excel startup directory as "personal.xls".

After that the virus infects every workbook that is opened or created.

Beside replication, this virus contains a payload that activates on March 1st. At this time the virus modifies the formatting of the active worksheet and inserts the following text to it:

  ROBOCOP Nightmare Joker [SLAM]


This variant announces its presence every time when an infected workbook is opened or when Excel is started with a message box containing the following text:

(c)DRAT2000 Dual Macro Virus ver. 05b2 - by DRAT

It also contains a payload that is activated on October 25th. This payload shows a message box with the following text:

  Selamat Ulang Tahun Deddy Ratnanto!

Technical Details: Sami Rautiainen, F-Secure


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More