Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Safwan


Aliases:


Safwan

Malware

W32

Summary

For more information on macro viruses, see the description of WordMacro/Concept.

The Safwan virus consist of one encrypted AutoOpen macro. When the virus infects NORMAL.DOT, it splits to macros named FileOpen and System32.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

WordMacro/Safwan activates on the 10th of October. At this time it displays a dialog box with this text:

Happy Birthday
        Is it your birthday today?
        Yes  No

If the answer is yes the virus does not infect the opened document.

Otherwise the virus only spreads. The name of the virus comes from a text macro it created to check if it has already infected NORMAL.DOT.

Safwan was reported to be in the wild in summer 1997.





Description Created: Mikko Hypponen, F-Secure



Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.