Virus Database


Macro.Word.Hunter.a

Description Macro.Word.Hunter.a

These are encrypted German-specific macro viruses. They contain three macros: AutoOpen, DateiNeu, ExtrasMakro. The viruses do not use any copy-macros function to spread themselves. To infect the system they save an infected document to the Winword startup directory with the name:
"Hunter.a": WINWORD.DOT
"Hunter.a,b": AutoStrt

The viruses then register that file as "Add-In" template.
The viruses infect the documents on DateiNeu (FileNew) call. They create new document, insert the infected Add-In and clean its contents. As a result on creating new file the virus loads already infected clean file (template).
The ExtrasMakro (ToolsMacro) macro is used to hide virus macros in infected system.
"Hunter.a,b" depending on the system timer display the MessageBox:
<HeadHunter V3.0>
One - You lock the target
Two - You bait the line
Three - You slowly spread the net
And four - You catch the man

"Hunter.c" depending on the system timer inserts into its macros random selected strings.
The virus contains the commented texts, the second line contains different version numbers and dates in viruses:
********************************************************************
*** <HEADHUNTER V3.0> by Neurobasher, 17.10.1995, Germany ***
*** Boring experimental Winword virus with minor retro & stealth ***
********************************************************************
*** "I'm looking for a man who knows the rules of the game" ***
*** "Who's able to forget them to realize my aim" ***
********************************************************************

Check other viruses! Be aware! Use Antiviral Software

Palma Family

Description Palma Family

These are nonmemory resident parasitic viruses. They search for COM files on disks and infect them. "Palma.247" overwrites the files, other viruses write themselves to the end of the file.
The viruses contain the texts:
"Palma.503": Palma Ver.2
"Palma.591": Palma Ver.4
C:COMMAND.COM
"Palma.642": Palma Ver.3

"Palma.591" depending on the system date deletes the C:COMMAND.COM file. "Palma.642" displays:
____ __ _ __ __ __
_ _ __ _ _ _ _ _ __ _
___ ____ _ _ _ _ ____
_ _ _ ____ _ _ _ _

Palma5

Description Palma5

It is a harmless memory resident boot virus. It hooks INT 13h and writes itself to the MBR of the hard drive and boot sectors of the floppy disks. While writing to the hard drive the virus uses direct HD port access. The virus contains the ID-text:
Palma5.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Karlby Entreprenad Ab
Chunk Distribution Ab
STOCKHOLM REN AKTIEBOLAG
Brogrens Byggservice
Brohede Byggkonsult Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com