Virus Database


Gippo.901

Description Gippo.901

These are not dangerous encrypted parasitic viruses. They are not memory resident (except "Gippo.1039,1234") and search for .EXE-files and write themselves to the file end.
One month after infection these viruses display the message and leave small memory resident trigger routine which hooks INT 08h and "quakes" the screen. They display the message on installation of TSR trigger routine. See "Gippo.1242,1249" also.
"Gippo.1039,1234" hook INT 08, 21h and write themselves at the end of EXE-files are executed or opened.
"Gippo" viruses display:
"Gippo.901": Fit of hysteria offered by G.I.P.Po.
"Gippo.944": Wake up SUCKER! Gratuitous alarm by G.I.P.Po
"Gippo.1000": Earth is quaking! Public*Domain GIPPo MCMXCIII
"Gippo.1030.a": * SunRise * EpidemicWare G.I.P.Po. oct-93
"Gippo.1030.b": SUNRISE * (C)opyItself 93 GIPPo
"Gippo.1039": !  Bumpy~ (R) Ghost Player
"Gippo.1050": CACOPHONY * EpidemicWare 93 G.I.P.Po.
"Gippo.1234": Stunning Blow (R) Ghost Player Italy
"Gippo.1242": AntiHeuristic GIPPO EpidemicWare
"Gippo.1249": AntiHeuristic GIPPO EpidemicWare (I)

They also contain the internal texts:
"Gippo.901": JumpingJack *.e?e *.* smartc*.cps
"Gippo.944": cacophony *.e?e *.* smartc*.cps
"Gippo.1000": Earthquake *.exe *.* smartchk.cps
"Gippo.1030.a,b": sunrise *.exe *.* smartc*.cp?
"Gippo.1050": Cacofonia *.EXE *.* smartchk.cp?
"Gippo.1242": HAMMER *.exe *.*
"Gippo.1249": HAMMER *.exe *.*

Gippo.1242,1249
This virus manifests itself by video effect.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word97.Unhelp

Description Macro.Word97.Unhelp

This virus contains four macros in one module "Helper": AutoOpen, ViewVBCode, FileTemplates, ToolsMacro (stealth). It replicates upon document opening. While infecting, the virus uses export/import functions via the C:STARTUP.LOG file. The virus does not manifest itself in any way.

Macro.Word97.Unseen

Description Macro.Word97.Unseen

This is a very dangerous polymorphic macro-virus. It contains one macro Document_Open and infects documents and global macros area on document opening. Depending on the system time and random counter, the virus corrupts the first two sectors on the C: drive.
The virus has quite an unusual stealth routine. When a document is opened, the virus moves its code from the macro area to the documents' variables, and replaces its code with a short macro program Document_Close that moves the virus code back to the macro area from the document's variables when the document is closed. As a result, the virus is invisible by using Word tools - when Word opens a document, the virus hides itself in the variables. When a document is closed, the virus restores its code, and the document on the disk stays infected.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Hepatitis Symptoms
Full Moon Dates
Single Russian Women
Hewlett Packard Printer Driver
Pre-teen Boys Short Hairstyles

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com