Virus.MSWord.Grass

Class Virus
Platform MSWord
Description

Technical Details


This is an encrypted German macro-virus, it contains six macros: DateiNeu,
ExtrasMakro, DateiBeenden, DateiSchliexen, ExtrasW÷rterZ hlen,
DateiSpeichernUnter. The virus replicates itself when any of these macros
is executed.


On March 10 the virus formats the C: drive and displays the MessageBox:


(c) Grasshopper Corp. / Germany 1997

On February 10 the virus displays the MessageBox:

Datei Schliexen
Datei wirklich Schliexen?

The virus then creates and executes the files CLICK.COM, LOSER.COM that
contain DOS viruses “Burger” and “Tequila”.


On May 10 the virus erases the files:


C:Io.sys
C:WindowsSystem.dat
C:WindowsSystemVmm32.vxd