Virus Protection > computer-virus-m-page1 > - macro.excel.ultras.cobra

macro.excel.ultras.cobra

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
Macro.Excel.Ultras.Cobra2

This virus infects Excel worksheets. It contains one module "Sheet?" where '?' is '3' or '5' depending on the virus version. The "Sheet?" module contains auto-functions Auto_Open and Auto_Close. The virus module also contains the functions:
TIMER, Trojan
The virus infects the system and files upon opening and closing. It also creates an infected file in the Excel Startup directory, the file name is PERSONAL.XLS or PERSONAL.XLM depending on the virus version.
The viruses delete the Tools/Macro menu (stealth) and anti-virus programs:
C:\Program Files\AntiViral Toolkit Pro\*.*
C:\Program Files\FindVirus\*.*
C:\f-macro\*.*
C:\Program Files\Command Software\F-PROT95\*.*
C:\Program Files\McAfee\VirusScan\*.*
C:\Program Files\Norton AntiVirus\*.*
On the 4th of any month, the virus writes the commands that format the hard drive to the AUTOEXEC.BAT file . On the 14th of any month, it deletes the C:\WINDOWS\REGEDIT.EXE file and displays the MessageBox:
ULTRAS
You Infected XM.Trojan.COBRA by ULTRAS
On the 26th of any month, it displays the same MessageBox and deletes the files:
C:\WINDOWS\SYSTEM.DAT, C:\WINDOWS\SYSTEM.DA0.
The virus, depending on the current day, appends the instruction that formats the hard drive to the C:\AUTOEXEC.BAT file.

Updated: 02/24/2006
Copyright @2006 macro.excel.ultras.cobra
Webroot Software Inc.