Rash
Rash
Type Word macro virus
Creator
Date Discovered 2001.17.17
Place of Origin
Source Language
Platform MS Word
File Type(s) .doc, .sys
Infection Length 1,105 bytes
Reported Costs

Rash also known as Rashkiller and Asder (some variants) is a macro virus from 2001. Some later variants of the virus drop the Onehalf virus.

When an infected document is opened, Rash intercepts the Document_Close macro and copies itself to the ThisDocument module. The virus disables the virus protection option and the prompt to save the document upon closing. Rash then infects the Normal template and all active documents.

The virus drops a file named AA*.SYS at the root of the C: drive. This contains code that changes the virus's attributes.

Variants

This variant is known to some antivirus products as Asder. It drops a copy of the Onehalf virus in a file named COMMàND.COM and modifies the AUTOEXEC.BAT file so this file is executed at next startup. It infects the global template when an infected document is closed.

Sources

Trend Micro, W97M_RASH.A. 2002.01.11

-, W97M_ASDER.A. 2000.10.26

Unless otherwise stated, the content of this page is licensed under Creative Commons Attribution-NonCommercial-ShareAlike 3.0 License