Selected viruses, spyware, and other threats: sorted alphabetically
W97M/Thus.X |
W97M/Thus.X is a macro virus operating in the Microsoft Word 97 environment. It uses the "class" method of infection – it attacks the module "ThisDocument" which is present as a standard in each Word document or template. It attacks the global template normal.dot and Word documents. It is derived from W97M/Thus.A
When an infected document is opened W97M/Thus.X checks the level of Word security. If it is set on any value the virus disables item Tools/Macro/Security....of the Word menu. It also turns off the anti-virus protection and grammar check of the document.
In the system registry in the key HKEY_CURRENT_USER\Software\Microsoft\Office\ it creates the item Bethlem? with value ...by PPC. After that it attacks the global template and the active document. After infecting the template it attacks all documents while they are being opened and closed as well as new documents.
On March 3rd the virus displays the following window with the message:

After that it deletes files with extension .sys on the disk C:.
© 1992-2004 Eset s.r.o. All rights reserved. No part of this Encyclopedia may be reproduced, transmitted or used in any other way in any form or by any means without the prior permission.
