Additional Details
This variant contains a destructive payload.
First the virus disables the build-in macro virus protection and
drop its code in a file C:\Surround.key. The virus uses this file
later to replicate.
If the day is 21nd and Surround.A infects Word for a first time,
it will produse a beep sound.
If the date is December 29 Surround.A will try to delete Win.com
file from Windows directory. The payload won't be executed if
Windows directory name and path is not C:\Win*. This will cause
Visual Basic error, that makes the virus obvious.
If Surround.A is able to execute its destructive payload, then it
will show the following message box:
"You are now Surrounded!!"
[Analysis: Katrin Tocheva, F-Secure]