Main Menu
Home
Bookmark
Contact Us



 
Macro.Word.Tungusk Viruses Information

Name: Macro.Word.Tungusk
Category: Viruses
Description: Details
Macro.Word.Tunguska

This is an encrypted Italian macro virus. It contains eight macros: AutoExec, AutoOpen, FileApri, AutoClose, FileSalva, GuidaSupporto, FileSalvaConNome, GuidaInformazioni.
The virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to documents on saving and saving with new name (FileSalva, FileSalvaConNome).
The virus creates two strings in the WINWORD6.INI file in [Microsoft Word] section:
DictionaryHelp=1
DOC-PATH=

The virus also tries to read from this section two variables: "CheckCRC" and "Debug". If CheckCRC=1, the virus disables its infection routine. If Debug=1, the virus displays many debug MessageBoxes.
The virus contains the comments:
------------------------------------------------------------------------
Virus: TUNGUSKA
------------------------------------------------------------------------
Variabile in Winword6.ini:
CheckCRC$ : se = 1, il virus NON infetta il MIO computer
Debug$ : se = 1, visualizzo i messaggi di Debug
DictionaryHelp$ : se = 1, scattata una certa data
------------------------------------------------------------------------
MACRO Italiane MACRO Inglesi COMMENTO
------------------------------------------------------------------------
AutoClose AutoClose intercetta doppio-click
AutoExec AutoExec intercetta avvio Word
AutoOpen AutoOpen intercetta apertura file
FileApri FileOpen intercetta Dialogo Apri
* FileChiudiOChiudiT. FileClose intercetta chiusura file
FileSalva FileSave intercetta salva file
FileSalvaConNome FileSaveAs intercetta Dialogo SalvaConNome
* FileModelli Templates intercetta Dialogo Modelli
GuidaInformazioni GuidaInformazioni virus
GuidaSupporto GuidaSupporto per controllo presenza virus
------------------------------------------------------------------------



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Deadman.57
Radyum.44
BAT.Winstart.29
Per
Jel.84
1stVir.317
Theta famil
TrojanSpy.Linux.Logft
Mr_Twiste
Linux.Winte


 


© 2006-2008 spyware32.com - Privacy Policy