WM/Wallpaper is a Word macro virus.
Beside replication, the virus activates its payload on every 31th day of each month. At this time, it attempts to replace the Windows desktop's wallpaper with a picture of a skull. This picture is saved to "c:\windows\temp\sk2.bmp".
Based on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the detected program or file, or ask you for a desired action.
Find the latest advice in our Community Knowledge Base.
See the manual for your F-Secure product on the Help Center.
Submit a file or URL for further analysis.
It also modifies the "c:\autoexec.bat" and "c:\windows\win.ini" to perform the changes to the user's desktop.
Based on the system time, it shows a message box with the same image and the following text:
The [PIRATE VIRUS] pillaged your computer!
The message box contains a single button labeled as:
GO BACK TO MS-WORD??