Virus Database


Win32.Ultratt

Description Win32.Ultratt

This is a non-memory resident parasitic Win32 virus with IRC spreading abilities. The virus searches for EXE, SCR, CPL, and OCX Windows executable files, and writes itself to the end of the file. There is only one virus version known, which is a "debug" version, and it infects these files only in when their names begin with the "1" character (for example, "1.EXE"). The virus looks for files in current, Windows, and Windows system directories.
To spread via IRC channels, the virus creates an infected C:MUTT.EXE file and overwrites SCRIPT.INI and EVENTS.INI files (mIRC and PIRCH control files) with commands that send a virus copy (MUTT.EXE file) to anyone entering the affected chat channel.
The virus uses anti-debugging tricks, and halts the system if its code is under debugger.
On the 15th of any month, the virus, by modifying the system registry, makes A: and B: drives invisible in Explorer. Then it displays the following message box:
[Win32.Mutt v1.00]
Mutt by ULTRAS[MATRiX] (c) 2000
Thanx: [MATRiX] VX TeAm: mort, NBK, anaktos, Del_Armg0, Lord Darkall
Greetz: all VX scene
The virus deletes the following anti-virus data files:
AVP.CRC, ANTI-VIR.DAT, CHKLIST.MS, IVB.NTZ, NOD32.000, TBSCAN.SIG, AP.VIR
The virus also contains a routine that terminates anti-virus scanners and resident monitors, but this routine never receives control. The list of anti-virus programs appears as follows:
AVP Monitor
Amon Antivirus Monitor
AVG Control Center
Avast32 -- RezidentnĪ podpora
AntivĪrusovä monitor Amon
Norton AntiVirus

Check other viruses! Be aware! Use Antiviral Software

Geliyor.1356

Description Geliyor.1356

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are executed. Depending on the system date it patches its infection code and starts to disinfect the files instead of infection. It contains the internal text strings, several of them are encrypted:
geliyor. . .
Heey! O askerden geliyor..O'nu arìyorum gören varmì?
Hani O nerede göremedim ? Gelecek ay O geliyor. . .
Her canlì doºar büyür ölürD.T nisan 94 Ö.T mayìs 95

Gena

Description Gena

It's a very dangerous memory resident virus. It contains a lot of errors. This virus hooks INT 13h and overwrites the hard drive MBR and the floppy Boot-sectors. On an error it types the 'trash'. It also contains the text:
by Gena 1992 . Drink "TAMARISI" !!! is a best of hilins !!!
Help me AIDSTEST.EXE !!!
Oh my got !!!
Ik Ik Ik Ik , man !
locked vector !!!
SIGNATURA PROLETARIATA. PARANOjA. AZOV !!!

Home

Viruses from A to Z
0-9 A B Ņ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



DLS BYGG HANDELSBOLAG
Klinik Smide Ab
MotortjÄnst I Lennheden
LuleÅ Bil & BÅtkarosseri Aktiebolag
Chr. Andersson Bil & PlÅt

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com