Gippo.901
Description Gippo.901
These are not dangerous encrypted parasitic viruses. They are not memory resident (except "Gippo.1039,1234") and search for .EXE-files and write themselves to the file end. One month after infection these viruses display the message and leave small memory resident trigger routine which hooks INT 08h and "quakes" the screen. They display the message on installation of TSR trigger routine. See "Gippo.1242,1249" also. "Gippo.1039,1234" hook INT 08, 21h and write themselves at the end of EXE-files are executed or opened. "Gippo" viruses display: "Gippo.901": Fit of hysteria offered by G.I.P.Po. "Gippo.944": Wake up SUCKER! Gratuitous alarm by G.I.P.Po "Gippo.1000": Earth is quaking! Public*Domain GIPPo MCMXCIII "Gippo.1030.a": * SunRise * EpidemicWare G.I.P.Po. oct-93 "Gippo.1030.b": SUNRISE * (C)opyItself 93 GIPPo "Gippo.1039": ! Bumpy~ (R) Ghost Player "Gippo.1050": CACOPHONY * EpidemicWare 93 G.I.P.Po. "Gippo.1234": Stunning Blow (R) Ghost Player Italy "Gippo.1242": AntiHeuristic GIPPO EpidemicWare "Gippo.1249": AntiHeuristic GIPPO EpidemicWare (I)
They also contain the internal texts: "Gippo.901": JumpingJack *.e?e *.* smartc*.cps "Gippo.944": cacophony *.e?e *.* smartc*.cps "Gippo.1000": Earthquake *.exe *.* smartchk.cps "Gippo.1030.a,b": sunrise *.exe *.* smartc*.cp? "Gippo.1050": Cacofonia *.EXE *.* smartchk.cp? "Gippo.1242": HAMMER *.exe *.* "Gippo.1249": HAMMER *.exe *.*
Gippo.1242,1249 This virus manifests itself by video effect.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Unhelp
Description Macro.Word97.Unhelp
This virus contains four macros in one module "Helper": AutoOpen, ViewVBCode, FileTemplates, ToolsMacro (stealth). It replicates upon document opening. While infecting, the virus uses export/import functions via the C:STARTUP.LOG file. The virus does not manifest itself in any way.
Macro.Word97.Unseen
Description Macro.Word97.Unseen
This is a very dangerous polymorphic macro-virus. It contains one macro Document_Open and infects documents and global macros area on document opening. Depending on the system time and random counter, the virus corrupts the first two sectors on the C: drive. The virus has quite an unusual stealth routine. When a document is opened, the virus moves its code from the macro area to the documents' variables, and replaces its code with a short macro program Document_Close that moves the virus code back to the macro area from the document's variables when the document is closed. As a result, the virus is invisible by using Word tools - when Word opens a document, the virus hides itself in the variables. When a document is closed, the virus restores its code, and the document on the disk stays infected.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Hepatitis Symptoms Full Moon Dates Single Russian Women Hewlett Packard Printer Driver Pre-teen Boys Short Hairstyles
|