W97M/Thus.a
 
Profile

Name
W97M/Thus.a

Aliases
Thus.a, W97M/Thursday

Variants
None

Date Added
8/27/99

Information
 Discovery Date:8/26/99
 Type:Virus
 SubType:Macro
 Risk Assessment:High
 Risk Justification:

Characteristics
This is a virus that infects Word 97 documents. The virus consists of a module called ThisDocument. It will infect Word's normal.dot file. When it infects it turns the Word 97 Macro Warning feature off.

Prior to infecting a document, the virus will look to see if it has already infected the document by checking for a comment - thus.000 - if this comment is found the virus will not reinfect.

On the 13th of December when an infected document is opened the virus will attempt to delete ALL files on drive C: (including subdirectories).

This virus has been reported to AVERT by various banks and financial organizations in Europe and the United States.

Symptoms
There are no specific indications that a document has been infected.

Method Of Infection/Installation
At this time it appears the documents have been passed from one organization to another.

This virus DOES NOT use email to spread itself, however as in many cases it can get from one place to the next as an attachment in an email message.

Removal
For VirusScan 4x users, update your DATS from here.
For VirusScan 3x users, update your DATS from here.
For Dr Solomon's 7.95 and above users, an EXTRA.DRV is here.

Removal Instructions
Not Available...