Virus Database


Macro.Word.Williamto

Description Macro.Word.Williamto

This is an encrypted Word macro virus. It contains 16 macros: Halim, FileNew, AutoOpen, FileOpen, FileSave, FileClose, FilePrint, HelpAbout, Williamto, FileSaveAs, ToolsMacro, FormatStyle, JustifyPara, ViewToolBars, FileTemplates, ToolsCustomize.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are opened, saved or saved with new name (FileOpen, FileSave, FileSaveAs).
This is the stealth virus: it draws its own dialog on entering Tools/Macro menu, on pressing any button the virus displays the MessageBox:
WordBasic Err = 7
Not enough memory

After opening a file the virus displays the message:
Williamto Virus
Williamto WordBasic Virus
Programmed by Williamto Halim
Virus Research Laboratory
Dedicated to Angelia Hadeli

On error while saving files the virus displays:
Attention!!!
Williamto Halim always lives in your computer

On closing files it displays:
File Close
Please close it later! Let's have fun!

On July 9 it displays:
Nice Day
Happy Birthday Amgelia Hadeli by Williamto Halim

The virus also replaces the "About Microsoft Word" with:
About Microsoft Word
Williamto WordBasic Virus
Programmed by Williamto Halim
Virus Research Laboratory
Dedicated to Angelia Hadeli

On printing documents the virus erases original text and prints its text:
Welcome to Williamto Word Macro Virus
I'm sorry about this but your computer has been infected by
Williamto Word Macro Virus
Please beware about this!!!
This Virus will destroy your data in your disk!!!
Copyright 1997 Virus Research Labs (Jakarta/Indonesia)

While printing the virus outputs to the status line the text:
[ Welcome to Williamto Word Macro Virus - Programmed & Written by
Williamto Halim the Hackers - Virus Research Laboratory ]

On November 11th the virus formats the hard drive and displays the MessageBox:
Attention!!!
I will format your hard disk now, ha-ha-ha!

Check other viruses! Be aware! Use Antiviral Software

Patras.1972

Description Patras.1972

This is a dangerous memory resident multipartite virus. While executing an infected EXE file the virus writes itself to the boot sector of the C: drive and then returns the control to the host file.
While loading from infected disk the virus hooks INT 8, waits for DOS loading procedure, allocates the DOS memory, copies itself to there, and hooks INT 21h. Then it writes itself to the end of EXE files that are executed. While infecting a file the virus also deletes the CHKLIST.MS file, if it exists.
After 60th infection the virus hooks INT 10h (Video) and manifests itself with sound and video effects: it displays the messages and launch "hearts" (03 ASCII) jumping on the screen. The messages are:
A lovely heart fell from the sky !!!
KARNAVALI OF PATRAS !!!
*** PATRAS H/Y ***

Patras.2346

Description Patras.2346

This is a dangerous memory resident multipartite virus. While executing an infected EXE file the virus writes itself to the MBR of the hard drive and then returns the control to the host file.
While loading from infected disk the virus hooks INT 8, waits for DOS loading procedure, allocates the DOS memory, copies itself to there, and hooks INT 21h. Then it writes itself to the end of EXE files that are executed. While infecting a file the virus also deletes the CHKLIST.MS file, if it exists.
After 60th infection the virus hooks INT 10h (Video) and manifests itself with sound and video effects: it displays the messages and launch "hearts" (03 ASCII) jumping on the screen. The messages are:
A lovely heart fell from the sky !!!
KARNAVALI OF PATRAS !!!
*** PATRAS H/Y ***

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Jeux De Naruto
BlÅ StjÄrnans Djursjukhus I Skara Ab
Salong Adam Och Eva
FÄrg Toppen
Leif Nyman Utvecklingskonsult

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com