Classification

Category :

Malware

Type :

Virus

Platform :

W97M

Aliases :

Titasic, Astia.A

Summary

W97M/Astia is a Word 97 macro virus that activates when an infected document is opened. At this point it infects the global template and every document thereafter.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

When the Word is closed, the virus creates two infected template files to the Word's startup directory: "SNrml.src" and "SNrml.dot".

The virus replaces the "Tools/Macros/Visual Basic Editor" and "Tools/Macros/Macro" menu selections with its own dialog box containing the following text:

Maaf..



 Anda jangan coba-coba mengedit, merubah, ataupun menghapus



 makro Titasic..!!



 Anda hanya bisa merekam makro, menyimpan, menggunakan



 serta menghapus makro buatan Anda



 Apakah Anda ingin merekam makro..?

If user selects "Yes" from the dialog box, the virus attempts to start the macro recorder.

Since October 10th, 1998 the virus activates its payload when Word has been running for 45 minutes. At this point it will create a new document with a form. This form will contain some graphics as well as the following texts one at the time:

Mungkin kehadiran TITASIC mengganggu kesibukan Anda, untuk itu



 maafkanlah kelancangan Titasic ..



 Ingat...!! Radiasi komputer berbahaya bagi Anda! So..



 istirahatlah sejenak biar enggak stres, pusing, uring-uringan,



 dsb..!



 Buat Cewek 'SINGLE' yang merasa dirinya Cakeup & Manis..,



 Salam dari Astia..!



 Mangga bilih bade didamel deui.!

Variant:Astia.B

W97M/Astia.B activates its payload since October 15th, 1998 when Word has been running for 45 minutes. Otherwise it is the same as W97M/Astia.A.

Variant:Astia.C

W97M/Astia.C is like W97M/Astia.A but the text that the virus shows when its payload activates is slightly modified.

Variant:Astia.L

ALIAS:Mamm

W97M/Astia.L uses different file names in the Word's startup directory, "MAMM.dot" and "MAMM.src", and it contains no payload.

Variant:Astia.O

This variant is like W97M/Astia.A but the Titasic macro has been removed and there is no payload.

Variant:Astia.Y

ALIAS:BMH

W97M/Astia.Y is a modified variant of W97M/Astia.A.

After August, 7th 1998 when the Word has been running for 15 minutes, the virus activates its payload. The payload changes the title text of Word to "Boo" and creates a new document with a form that contains the following texts:

Infected Boomv1.01

 Me, No longer to stay in your computer!

 Beware of the Boomv1.01!

 BmH guess who(m) am I

 thanks to (UserName)

where "(UserName)" is replaced with the current user name.

The virus also replaces "Tools\Macros\Visual Basic Editor" and "Tools\Macros\Macro" with a dialog box with the following text:

Are you sure want to create a new macro ?

If the user selects "Yes" button, the virus attempts to start the macro recorder.