macro.excel.ultras.freeze
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Macro.Excel.Ultras.Freezer
This virus infects Excel worksheets. It contains one module "Sheet?" where '?' is '3' or '5' depending on the virus version. The "Sheet?" module contains auto-functions Auto_Open and Auto_Close. The virus module also contains the functions:
Joke
The virus infects the system and files upon opening and closing. It also creates an infected file in the Excel Startup directory, the file name is PERSONAL.XLS or PERSONAL.XLM depending on the virus version.
The viruses delete the Tools/Macro menu (stealth) and anti-virus programs:
C:\Program Files\AntiViral Toolkit Pro\*.*
C:\Program Files\FindVirus\*.*
C:\f-macro\*.*
C:\Program Files\Command Software\F-PROT95\*.*
C:\Program Files\McAfee\VirusScan\*.*
C:\Program Files\Norton AntiVirus\*.*
The virus displays the following MessageBox on the 14th of any month:
ULTRAS
You Infected XM.Freezer by ULTRAS
and deletes by DELTREE command all files in the C:\PROGRA~1 directory. On the 28th of any month, it displays the MessageBox and deletes the files:
C:\WINDOWS\USER.DAT
C:\WINDOWS\USER.DA0
Copyright @2006 macro.excel.ultras.freeze