x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

Chack.BT

 
Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Chack.BT
Technical name:W97M/Chack.BT
Threat level:Low
Alias:W97M/Calivent.A
Type:Virus
Effects:  It infects Word documents and the global template, disables certain Word options, displays messages and modifies the text in documents.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

Detection updated on:Nov. 13, 2002
StatisticsNo
Family:VALENTIN

Brief Description 

    

Chack.BT is a macro virus virus that infects Word 97 documents and the global template that this application uses.

Chack.BT uses the normal means of infection used by macro viruses. First of all it infects the global template and then it infects all the documents opened, closed or saved on the affected computer.

Chack.BT also disables certain Word options, displays messages and modifies the text in Word documents.

Visible Symptoms 

    

Chack.BT is very easy to recognize, as it displays several messages on screen when certain conditions are met:

  • If the user selects Macros in the Macro option in the Tools menu, Chack.BT displays the following message:
    SOY EL ANGEL GABRIEL escribir a as_99@latinmail.com
  • On May 13, Chack.BT looks for the file ACCESO.EXE in the Windows directory. If it finds this file, it prints a page or displays a message on screen:
    Te fregaste loco, Ya no hay curra porgúuusto!
  • If the user selects one of the following options: Exit in the File menu, View-Code in the Visual Basic Editor or About Microsoft Word in the Help(?) menu, Chack.BT
    displays the following message:



    Then, the virus will display another two messages. The first contains the message Borrico and the OK button. When the user clicks on this button, another message is displayed:
    Text: Se ha detectado Virus W00/Rey en tu sistema. Deseas eliminarlo
    Buttons: Yes and No

    If the user clicks on Yes, the virus will delete all the documents in the My documents directory and display the following message:
    No se Puede Eliminar Rey Tu Maquina Está en Cuarentena.

    The virus will also insert the following text in the active Word document:
    Tienes Virus!!!!....Rey

    If the user clicks on the image or the No button, the virus will display the following message:
    Ingrese la contraseña de autoeliminación luego su maquina quedará limpia de virus.
    Y si quiere Virus o información yo te la daré
    as_99@latinmail.com

    In the unlikely event that the user entered the password: Edwing Gabriel Unimoq, the virus would display the text Eliminado and delete all the files in the Windows directory.