Macro.Word.Hunter.a
Description Macro.Word.Hunter.a
These are encrypted German-specific macro viruses. They contain three macros: AutoOpen, DateiNeu, ExtrasMakro. The viruses do not use any copy-macros function to spread themselves. To infect the system they save an infected document to the Winword startup directory with the name: "Hunter.a": WINWORD.DOT "Hunter.a,b": AutoStrt
The viruses then register that file as "Add-In" template. The viruses infect the documents on DateiNeu (FileNew) call. They create new document, insert the infected Add-In and clean its contents. As a result on creating new file the virus loads already infected clean file (template). The ExtrasMakro (ToolsMacro) macro is used to hide virus macros in infected system. "Hunter.a,b" depending on the system timer display the MessageBox: <HeadHunter V3.0> One - You lock the target Two - You bait the line Three - You slowly spread the net And four - You catch the man
"Hunter.c" depending on the system timer inserts into its macros random selected strings. The virus contains the commented texts, the second line contains different version numbers and dates in viruses: ******************************************************************** *** <HEADHUNTER V3.0> by Neurobasher, 17.10.1995, Germany *** *** Boring experimental Winword virus with minor retro & stealth *** ******************************************************************** *** "I'm looking for a man who knows the rules of the game" *** *** "Who's able to forget them to realize my aim" *** ********************************************************************
Check other viruses! Be aware! Use Antiviral Software
Palma Family
Description Palma Family
These are nonmemory resident parasitic viruses. They search for COM files on disks and infect them. "Palma.247" overwrites the files, other viruses write themselves to the end of the file. The viruses contain the texts: "Palma.503": Palma Ver.2 "Palma.591": Palma Ver.4 C:COMMAND.COM "Palma.642": Palma Ver.3
"Palma.591" depending on the system date deletes the C:COMMAND.COM file. "Palma.642" displays: ____ __ _ __ __ __ _ _ __ _ _ _ _ _ __ _ ___ ____ _ _ _ _ ____ _ _ _ ____ _ _ _ _
Palma5
Description Palma5
It is a harmless memory resident boot virus. It hooks INT 13h and writes itself to the MBR of the hard drive and boot sectors of the floppy disks. While writing to the hard drive the virus uses direct HD port access. The virus contains the ID-text: Palma5.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Karlby Entreprenad Ab Chunk Distribution Ab STOCKHOLM REN AKTIEBOLAG Brogrens Byggservice Brohede Byggkonsult Ab
|