Virus.MSWord.Tunguska

Class Virus
Platform MSWord
Description

Technical Details


This is an encrypted Italian macro virus. It contains eight macros:
AutoExec, AutoOpen, FileApri, AutoClose, FileSalva, GuidaSupporto,
FileSalvaConNome, GuidaInformazioni.


The virus infects the global macros area on opening an infected document
(AutoOpen) and writes itself to documents on saving and saving with new
name (FileSalva, FileSalvaConNome).


The virus creates two strings in the WINWORD6.INI file in [Microsoft Word]
section:


DictionaryHelp=1
DOC-PATH=

The virus also tries to read from this section two variables: “CheckCRC”
and “Debug”. If CheckCRC=1, the virus disables its infection routine. If
Debug=1, the virus displays many debug MessageBoxes.


The virus contains the comments:


————————————————————————
Virus: TUNGUSKA
————————————————————————
Variabile in Winword6.ini:
CheckCRC$ : se = 1, il virus NON infetta il MIO computer
Debug$ : se = 1, visualizzo i messaggi di Debug
DictionaryHelp$ : se = 1, scattata una certa data
————————————————————————
MACRO Italiane MACRO Inglesi COMMENTO
————————————————————————
AutoClose AutoClose intercetta doppio-click
AutoExec AutoExec intercetta avvio Word
AutoOpen AutoOpen intercetta apertura file
FileApri FileOpen intercetta Dialogo Apri
* FileChiudiOChiudiT. FileClose intercetta chiusura file
FileSalva FileSave intercetta salva file
FileSalvaConNome FileSaveAs intercetta Dialogo SalvaConNome
* FileModelli Templates intercetta Dialogo Modelli
GuidaInformazioni GuidaInformazioni virus
GuidaSupporto GuidaSupporto per controllo presenza virus
————————————————————————