Virus Database


V.6000

Description V.6000

It is a dangerous memory resident polymorphic stealth multipartite virus. While executing an infected file or loading from infected floppy disk that virus writes itself to the MBR of the hard drive. The virus stays memory resident on loading from infected MBR only, it hooks INT 8, 13h, 17h, 1Ch, 20h, 21h, 25h, 26h, 27h and writes itself to the end of COM and EXE files that are accessed, or on the program termination. Depending on its internal counter the virus searches for the files and infects them. The virus checks the file names and does not infect the files:
COMMAND.COM, GDI.EXE, DOSX.EXE, WIN386.EXE, KRNL286.EXE, KRNL386.EXE,
USER.EXE, WSWAP.EXE, CHKDSK.EXE

On accessing to a floppy disk the virus writes itself to the boot sector. Depending on its internal counters and under debuggers the virus erases the CMOS and the hard drive sectors.
The virus uses a complex algorithm allowing the virus to stay memory resident after cold reboot and loading from a clean DOS floppy disk. On installation the virus stores the CMOS memory that keeps the information about floppy drives and sets that info to zero (i.e. the virus emulates situation when no floppy drives are installed). On accessing to disks the virus temporary restores the CMOS and then erases these fields again. On any (cold or warm) reboot the system checks the CMOS, does not detect the floppy disks and passes the control to the MBR of hard drive. As a result the virus in the MBR receives the control, installs itself into the memory and then passes the control to the floppy disk loader. As a result the virus stays memory resident after loading from a clean write-protected disk.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Williamto

Description Macro.Word.Williamto

This is an encrypted Word macro virus. It contains 16 macros: Halim, FileNew, AutoOpen, FileOpen, FileSave, FileClose, FilePrint, HelpAbout, Williamto, FileSaveAs, ToolsMacro, FormatStyle, JustifyPara, ViewToolBars, FileTemplates, ToolsCustomize.
The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are opened, saved or saved with new name (FileOpen, FileSave, FileSaveAs).
This is the stealth virus: it draws its own dialog on entering Tools/Macro menu, on pressing any button the virus displays the MessageBox:
WordBasic Err = 7
Not enough memory

After opening a file the virus displays the message:
Williamto Virus
Williamto WordBasic Virus
Programmed by Williamto Halim
Virus Research Laboratory
Dedicated to Angelia Hadeli

On error while saving files the virus displays:
Attention!!!
Williamto Halim always lives in your computer

On closing files it displays:
File Close
Please close it later! Let's have fun!

On July 9 it displays:
Nice Day
Happy Birthday Amgelia Hadeli by Williamto Halim

The virus also replaces the "About Microsoft Word" with:
About Microsoft Word
Williamto WordBasic Virus
Programmed by Williamto Halim
Virus Research Laboratory
Dedicated to Angelia Hadeli

On printing documents the virus erases original text and prints its text:
Welcome to Williamto Word Macro Virus
I'm sorry about this but your computer has been infected by
Williamto Word Macro Virus
Please beware about this!!!
This Virus will destroy your data in your disk!!!
Copyright 1997 Virus Research Labs (Jakarta/Indonesia)

While printing the virus outputs to the status line the text:
[ Welcome to Williamto Word Macro Virus - Programmed & Written by
Williamto Halim the Hackers - Virus Research Laboratory ]

On November 11th the virus formats the hard drive and displays the MessageBox:
Attention!!!
I will format your hard disk now, ha-ha-ha!

Macro.Word.Wmvh

Description Macro.Word.Wmvh

This virus contains two macros in documents (AutoOpen, BieDEMO) and five macros in NORMAL.DOT (AutoNew, AutoOpen, AutoExec, AutoClose, BieDEMO).
It infects the global macros area on opening an infected document (AutoOpen). The documents get infection on AutoNew, AutoOpen, AutoClose.
On October 10th the virus displays the MessageBox:
BieDEMO Macro Virus by WMVH
This is a Demo of Bie's WMVH

The virus contains the comments:
REM Bie's Word Macro Virus Hamburger Ver.beta
REM This Macro Virus Made from Bie's WMVH
REM Bie's E-Mail: bie111@hotmail.com
REM 2/09/1997

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Bra Grafikkort
Cash Advance Loan
Computer Accessories
Techno Mp3
Anton Och Affe

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com