Threat behavior
Virus:W97M/Thus.G is a Microsoft Word VBA Class module virus that infects Word documents and templates. This virus does not perform a payload other than to infect other files.
Installation
The virus infects the Normal Template and any opened documents by deleting other macros and inserting itself. Files are then infected when documents are opened, closed or new documents are created.
Payload
This macro virus, if allowed to run, disables macro security.
Additional Information
Infected documents contain the following string 'Anti-Virus' in the VBA code, which also serves as the infection marker for the virus. Early variants of the virus used a marker comment string 'Thus_001', a derivative of the virus family name.
Prevention