Virus Database


V3b.699

Description V3b.699

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of COM and EXE files that are executed. The virus contains the encrypted string:
7.11.V3b

Check other viruses! Be aware! Use Antiviral Software

Macro.Excel.Ultras.Cobra

Description Macro.Excel.Ultras.Cobra

This virus infects Excel worksheets. It contains one module "Sheet?" where '?' is '3' or '5' depending on the virus version. The "Sheet?" module contains auto-functions Auto_Open and Auto_Close. The virus module also contains the functions:
TIMER, Trojan
The virus infects the system and files upon opening and closing. It also creates an infected file in the Excel Startup directory, the file name is PERSONAL.XLS or PERSONAL.XLM depending on the virus version.
The viruses delete the Tools/Macro menu (stealth) and anti-virus programs:
C:Program FilesAntiViral Toolkit Pro*.*
C:Program FilesFindVirus*.*
C:f-macro*.*
C:Program FilesCommand SoftwareF-PROT95*.*
C:Program FilesMcAfeeVirusScan*.*
C:Program FilesNorton AntiVirus*.*
On the 4th of any month, the virus writes the commands that format the hard drive to the AUTOEXEC.BAT file . On the 14th of any month, it deletes the C:WINDOWSREGEDIT.EXE file and displays the MessageBox:
ULTRAS
You Infected XM.Trojan.COBRA by ULTRAS
On the 26th of any month, it displays the same MessageBox and deletes the files:
C:WINDOWSSYSTEM.DAT, C:WINDOWSSYSTEM.DA0.

Macro.Excel.Ultras.Cobra2

Description Macro.Excel.Ultras.Cobra2

This virus infects Excel worksheets. It contains one module "Sheet?" where '?' is '3' or '5' depending on the virus version. The "Sheet?" module contains auto-functions Auto_Open and Auto_Close. The virus module also contains the functions:
TIMER, Trojan
The virus infects the system and files upon opening and closing. It also creates an infected file in the Excel Startup directory, the file name is PERSONAL.XLS or PERSONAL.XLM depending on the virus version.
The viruses delete the Tools/Macro menu (stealth) and anti-virus programs:
C:Program FilesAntiViral Toolkit Pro*.*
C:Program FilesFindVirus*.*
C:f-macro*.*
C:Program FilesCommand SoftwareF-PROT95*.*
C:Program FilesMcAfeeVirusScan*.*
C:Program FilesNorton AntiVirus*.*
On the 4th of any month, the virus writes the commands that format the hard drive to the AUTOEXEC.BAT file . On the 14th of any month, it deletes the C:WINDOWSREGEDIT.EXE file and displays the MessageBox:
ULTRAS
You Infected XM.Trojan.COBRA by ULTRAS
On the 26th of any month, it displays the same MessageBox and deletes the files:
C:WINDOWSSYSTEM.DAT, C:WINDOWSSYSTEM.DA0.
The virus, depending on the current day, appends the instruction that formats the hard drive to the C:AUTOEXEC.BAT file.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Fenêtres De Toit
Install A Wordpress 3.0 Theme
Epidural Steroid Injection
Banki

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com