Virus Profile: W97M/Azrael

Threat Search
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 10/1/1999
Date Added: 12/10/2002
Origin: Unknown
Length: N/A
Type: Virus
Subtype: Macro
DAT Required: 4032
Removal Instructions


This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Indication of Infection

The above message displayed on 23rd day of any month.

Methods of Infection

Overwrites up to four documents on the recent files list and all *.doc files on drive C: with a copy of the active infected document.

Virus Characteristics

This threat is detected as W97M/Azrael. W97M/Azrael is a small macro virus consisting of one macro - autoopen. If day is 23rd of any month, the virus will delete all .dll files from the hardcoded path c:\windows\system\. It will also display the following message:

Azrael cleaned your system directory !!!

Use current engine and DAT files for detection and removal.

It is very common for macro viruses to disable options within Office applications for example in Word, the macro protection warning commonly is disabled. After cleaning macro viruses, ensure that your previously set options are again enabled.

AVERT Recommended Updates:

* Office 2000 updates

* Malformed Word Document Could Enable Macro to Run Automatically (Information/Patch)


PC Infected? Get Expert Help

Virus Removal Service

Connect to one of our Security Experts by phone. Have your PC fixed remotely - while you watch!