Virus Database


Macro.Word.Uhrjap family

Description Macro.Word.Uhrjap family

These macro viruses contain different number of macros:
"Uhrjap.a": one, DelNew, autoopen, autoclose, normclose
"Uhrjap.b": Eee, autoclose, ToolsMacro, FileTemplates, ToolsCustomize,
Oao, autoopen.

They infect the global macros area on opening an infected document. Other documents get infection on closing.
"Uhrjap.b" is the stealth virus: on entering the Tools/Macro, Tools/Customize or File/Templates menus the virus removes its macros from a document, and as a result its code is not visible in macro viewing menus.
The viruses have destructive payload. "Uhrjap.a" on each 20'th opening starts a procedure that every 10 minutes counts the characters in the document. If the count it the same (haven't changes during 10 minutes), the virus renames all files in the root directory and first level directories on the C:, D: and E: drives with the names "~TLPxxx.TMP", where "xxx" is ordinal number of file in a directory. The virus also runs this renaming procedure with probability 2% on any document opening.
The "Uhrjap.b" virus on document opening or closing with probability 1/30 saves document with new password "uhrjap-uhrjap", or prints document, or deletes from document all space characters and replaces all digits with the "#" character. It also with probability 1/50 activates its payload procedure that is similar with "Uhrjap.a" virus: it renames all files in the root directory and first level directories on the C:, D: and E: drives with the name "~037xxx.TMP" where "xxx" is ordinal number of file in a directory.

Check other viruses! Be aware! Use Antiviral Software

Slam.565

Description Slam.565

Slam.565
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed or opened. The virus does not manifest itself in any way, it contains the text:
SKANK (C) Dark Chakal [SLAM]

Slam.Damned
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus deletes the anti-virus files: ANTI-VIR.DAT, CHKLIST.CPS, CHKLIST.MS, AVP.SET, FINDVIRU.DRV, AVP.OVL, SCAN.DAT, SIGN.DEF.
The virus also contains the text:
DaMNeD Virus (c) 1997, Dark Chakal [SLAM]

SlamTilt.703

Description SlamTilt.703

It is not a dangerous nonmemory resident parasitic partly encrypted virus. It searches for .COM files and writes itself to the end of the file. In some cases it displays the message:
<<< SLAM TILT >>>

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com