Virus Database


Ultimate.487

Description Ultimate.487

This is a harmless non memory-resident encrypted parasitic virus. It searches for COM files, then writes itself to the end of the file. The virus decryption loop is placed at the file beginning.
The virus contains the text string:
[Ultimate Evil II] by Vecna.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Calendar

Description Macro.Word97.Calendar

This virus contains seven macros: AutoOpen, AutoClose, ToolsMacro, FileSaveAs, FileTemplates, Calendar, and ViewVBCode.
It infects documents that are opened, closed or saved with a new name (AutoOpen, FileClose, FileSaveAs). Upon opening a file, the virus also turns the VirusProtection option off.
Upon entering the Tools/Macro menu, the virus displays the MessageBox:
Microsoft Word
You do not have permission to do this

On the following dates, the virus displays the MessageBoxes:
January 1 "New Year's Day",
January 20 "Martin Luther King Jr. Day",
February 12 "President Lincoln's Birthday and Ash Wednesday",
February 14 "Valentine's Day",
February 17 "Presidents Day",
February 22 "President Washington's Birthday",
March 17 "St. Patrick's Day",
March 23 "Palm Sunday",
March 28 "Good Friday",
March 30 "Easter",
April 22 "Passover",
May 9 "Calendar, coded by DarkChasm [SLAM]",
May 11 "Mother's Day",
May 17 "Armed Forces Day",
May 19 "Victoria Day",
May 26 "Memorial Day Observed",
May 30 "Traditional Memorial Day",
June 15 "Father's Day",
July 1 "Canada Day",
July 4 "Independence Day",
October 2 "Rosh Hashonah",
October 11 "Yom Kippur",
October 12 "Columbus Day",
October 13 "Columbus Day Observed",
October 16 "Happy Birthday DarkChasm",
October 24 "United Nations Day",
October 31 "Halloween",
November 4 "Election Day",
November 11 "Veteran's Day",
November 27 "ThanksGiving Day",
December 21 "Happy Birthday Christy",
December 24 "Christmas Eve and Hanukkah",
December 25 "Christmas",
December 31 "New Year's Eve".

Macro.Word97.Carrier

Description Macro.Word97.Carrier

This virus contains three macros in one class "ThisDocument": Document_Close, Document_New, Document_Open, and two in module "Agent": AutoOpen, FileSaveAs.
The virus replicates on documents opening, closing or creating. The replication routine used Import/Export functions via the C:NORMAL.BAS in case of NORMAL.DOT and C:DOCUMENT.BAS file in case of documents.
The virus has the comment which is used to detect already infected files:
REM WRITTEN BY LORD ARZ

The virus sets the caption for all windows:
Infected by the Carrier virus (a trooper has already landed)

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com