Classification

Category :

Malware

Type :

-

Aliases :

Strezz

Summary

For more information on Word macro viruses, see WordMacro/Concept.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

The WordMacro/Strezz virus consist of three encrypted macros: AutoOpen, FilePrint and FileSaveAs. Each of them contains the following comments:

Virus
: STREZZ.WinWord
 Author : Dark Love & Lady Love

When the virus infects the global template, it removes the following menus from Word, making it impossible to view the macros of the virus:

File/Templates
 File/---------
 File/Macro
 View/Toolbars
 Tools/Macro
 Tools/Customize
 Format/Style

Strezz activates when files are printed. At this time it removes the Edit/Undo menu and prints the following text before the original document:

STRESS '97
 Special for my love by
 The Free Hackers
 Viroright (C) 1997 Internation Virus Research
 If you have bugs, please call me and don't stress for it!
 I will back laler!

The above extra lines can easily go undetected by the user if he's using a fax driver to fax the document directly from Word.However, after the printing (or faxing) has finished, the virus displays the following text:

You are STREZZ now, I'm sorry for it!
 [IVR] - Internation Virus Research