V.6000
Description V.6000
It is a dangerous memory resident polymorphic stealth multipartite virus. While executing an infected file or loading from infected floppy disk that virus writes itself to the MBR of the hard drive. The virus stays memory resident on loading from infected MBR only, it hooks INT 8, 13h, 17h, 1Ch, 20h, 21h, 25h, 26h, 27h and writes itself to the end of COM and EXE files that are accessed, or on the program termination. Depending on its internal counter the virus searches for the files and infects them. The virus checks the file names and does not infect the files: COMMAND.COM, GDI.EXE, DOSX.EXE, WIN386.EXE, KRNL286.EXE, KRNL386.EXE, USER.EXE, WSWAP.EXE, CHKDSK.EXE
On accessing to a floppy disk the virus writes itself to the boot sector. Depending on its internal counters and under debuggers the virus erases the CMOS and the hard drive sectors. The virus uses a complex algorithm allowing the virus to stay memory resident after cold reboot and loading from a clean DOS floppy disk. On installation the virus stores the CMOS memory that keeps the information about floppy drives and sets that info to zero (i.e. the virus emulates situation when no floppy drives are installed). On accessing to disks the virus temporary restores the CMOS and then erases these fields again. On any (cold or warm) reboot the system checks the CMOS, does not detect the floppy disks and passes the control to the MBR of hard drive. As a result the virus in the MBR receives the control, installs itself into the memory and then passes the control to the floppy disk loader. As a result the virus stays memory resident after loading from a clean write-protected disk.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Williamto
Description Macro.Word.Williamto
This is an encrypted Word macro virus. It contains 16 macros: Halim, FileNew, AutoOpen, FileOpen, FileSave, FileClose, FilePrint, HelpAbout, Williamto, FileSaveAs, ToolsMacro, FormatStyle, JustifyPara, ViewToolBars, FileTemplates, ToolsCustomize. The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are opened, saved or saved with new name (FileOpen, FileSave, FileSaveAs). This is the stealth virus: it draws its own dialog on entering Tools/Macro menu, on pressing any button the virus displays the MessageBox: WordBasic Err = 7 Not enough memory
After opening a file the virus displays the message: Williamto Virus Williamto WordBasic Virus Programmed by Williamto Halim Virus Research Laboratory Dedicated to Angelia Hadeli
On error while saving files the virus displays: Attention!!! Williamto Halim always lives in your computer
On closing files it displays: File Close Please close it later! Let's have fun!
On July 9 it displays: Nice Day Happy Birthday Amgelia Hadeli by Williamto Halim
The virus also replaces the "About Microsoft Word" with: About Microsoft Word Williamto WordBasic Virus Programmed by Williamto Halim Virus Research Laboratory Dedicated to Angelia Hadeli
On printing documents the virus erases original text and prints its text: Welcome to Williamto Word Macro Virus I'm sorry about this but your computer has been infected by Williamto Word Macro Virus Please beware about this!!! This Virus will destroy your data in your disk!!! Copyright 1997 Virus Research Labs (Jakarta/Indonesia)
While printing the virus outputs to the status line the text: [ Welcome to Williamto Word Macro Virus - Programmed & Written by Williamto Halim the Hackers - Virus Research Laboratory ]
On November 11th the virus formats the hard drive and displays the MessageBox: Attention!!! I will format your hard disk now, ha-ha-ha!
Macro.Word.Wmvh
Description Macro.Word.Wmvh
This virus contains two macros in documents (AutoOpen, BieDEMO) and five macros in NORMAL.DOT (AutoNew, AutoOpen, AutoExec, AutoClose, BieDEMO). It infects the global macros area on opening an infected document (AutoOpen). The documents get infection on AutoNew, AutoOpen, AutoClose. On October 10th the virus displays the MessageBox: BieDEMO Macro Virus by WMVH This is a Demo of Bie's WMVH
The virus contains the comments: REM Bie's Word Macro Virus Hamburger Ver.beta REM This Macro Virus Made from Bie's WMVH REM Bie's E-Mail: bie111@hotmail.com REM 2/09/1997
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Bra Grafikkort Cash Advance Loan Computer Accessories Techno Mp3 Anton Och Affe
|