Virus.MSWord.Gest

Class Virus
Platform MSWord
Description

Technical Details


This is an encrypted macro virus. It contains two macros: AutoOpen and
AutoClose. The virus infects the global macros area on opening an infected
document and infects documents when they are opened or closed.


The virus creates the [Gest] section in the WIN.INI file and writes the
“date” string to there. This string contains the date of infection. In 40
days the virus writes to the AUTOEXEC.BAT file the command that erases all
files on the C: drive:


@deltree c:*>nul