Virus Database


VirTool.DOS.Instvcl.a

Description VirTool.DOS.Instvcl.a
The VCL (Virus Creation Laboratory) virus constructor was developed in 1992. It is a graphical environment to creating viruses and a range of Trojan programs for MS DOS environments. The user is able to choose infection method, the time at which various functions should be activated etc. Once allall

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Uhrjap family

Description Macro.Word.Uhrjap family

These macro viruses contain different number of macros:
"Uhrjap.a": one, DelNew, autoopen, autoclose, normclose
"Uhrjap.b": Eee, autoclose, ToolsMacro, FileTemplates, ToolsCustomize,
Oao, autoopen.

They infect the global macros area on opening an infected document. Other documents get infection on closing.
"Uhrjap.b" is the stealth virus: on entering the Tools/Macro, Tools/Customize or File/Templates menus the virus removes its macros from a document, and as a result its code is not visible in macro viewing menus.
The viruses have destructive payload. "Uhrjap.a" on each 20'th opening starts a procedure that every 10 minutes counts the characters in the document. If the count it the same (haven't changes during 10 minutes), the virus renames all files in the root directory and first level directories on the C:, D: and E: drives with the names "~TLPxxx.TMP", where "xxx" is ordinal number of file in a directory. The virus also runs this renaming procedure with probability 2% on any document opening.
The "Uhrjap.b" virus on document opening or closing with probability 1/30 saves document with new password "uhrjap-uhrjap", or prints document, or deletes from document all space characters and replaces all digits with the "#" character. It also with probability 1/50 activates its payload procedure that is similar with "Uhrjap.a" virus: it renames all files in the root directory and first level directories on the C:, D: and E: drives with the name "~037xxx.TMP" where "xxx" is ordinal number of file in a directory.

Macro.Word.Ultras.Goblin2

Description Macro.Word.Ultras.Goblin2

This virus infects the Word documents. The infection is run on documents opening or closing.
On Tuesday it creates the Zoo.383.b virus dropper on the C: drive, inserts into the C:AUTOEXEC.BAT file the command to execute it and displays the MessageBox:
ULTRASall
GoBLiN II by ULTRAS
Thank you Dirty Nazi [Stealth group WorldWide]
for such beautiful virus.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



FlyttstÄdning I Stockholm Aktiebolag
Haga Nya Trafikskola
Wedins Transport I Sundsvall Ab
Dervas StÄd Aktiebolag
Veteran Carparts I VÄxjÖ

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com