Skip to main content

Class

Classification

Category:

Malware

Type:

Virus

Aliases:

  • Class

Summary

This Word macro virus (also known as "MS Word 97 Macro Class Virus") infects Word 97 documents.

Removal

Technical Details

W97M/Class changes it's own code constantly by inserting comments that contain the current user name, date and time and information about the active printer.

The virus uses an effective way to hide its code. The virus installs its module to Word classes by using special WordBasic operators. The virus code is appended as a native Word component. As a result the virus is not visible in the Tools/Macro menu.

The virus creates a file "c:\class.sys" to replicate. This file can be safely deleted after the system has been disinfected.

W97M/Class activates on the 31st of every month. On this date it displays this message:

This Is Class o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o oVicodinES /CB /TNNo o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o

Variant:Class.B

This is almost identical to Class.D except the displayed message is slightly different and the name of the registered user is not changed.

Variant:Class.D

W97M/Class.D activates on the 14th of the month from June to December. At this time it displays a message:

I Think (Name of the current user) is a big stupid jerk! VicodinES Loves You / Class.Poppy

Sometimes the virus also changes the registered company name to "Dr. Diet Mountain Dew".

Variant:Class.Q

This variant is functionally identical with Class.B.

Variant:Class.BV

W97M/Class.BV is a variant that does not contain any payload. Furthermore, it does not create a temporary file to replicate.

Variant:Class.CN (Mad Cow)

This variant of Class is also known as Mad Cow. It is related to the famous Melissa virus as well.

Class.CN spreads in Word documents and transfers itself via email, using Microsoft Outlook. It sends email to the first 20 aliases listed in Outlook Address Book.

The messages look like this:

From: (name of infected user) Subject: Mad Cow Joke To: (20 names from alias list) Beware of the spread of the Madcow Disease Attachment: (random document infected with Syndicate)

Do notice that Class.CN can arrive in any document, not necessarily just in MADCOW.DOC in which it was initially distributed.

Another noticeable and a major difference that makes it different from Melissa and Syndicate: Class.CN re-sends the messages only when an infected document is opened or closed in an infected system.

W97M/Class.CN is a polymorphic virus which means that it changes it's own code every time it replicates. It uses a file called C:\V.SYS while spreading.

The virus contains these comments that are never shown to the user:

'WORD/VERONICA // thanks to WORD/MELLISA & WORD/CLASS

Variant:Class.EB

W97M/Class.EB is a non-polymorphic variant of W97M/Class. The file name that it uses to replicate has been changed to "c:\normal.do".

This virus activates its payload on the 11th day of each month when it displays a message box with the following text:

Internal Error! Restart Word.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.