|
|
GK.769 Viruses Information
| Name: |
GK.769 |
| Category: |
Viruses |
| Description:
|
Details
GK.7697
It is a dangerous memory resident highly polymorphic and stealth multipartite virus. It infects the MBR of the hard drive, boot sector of 1.4Mb floppy disks and writes itself to the end of COM and EXE files that are accessed. The virus uses its polymorphic and stealth abilities for boot sectors as well as for executable files. When ARJ, LHA or PKZIP archivers or CHKDSK utility is active, the virus temporary disables its stealth routines.
To intercept system events the virus hooks INT 13h, 21h, 29h. While installing memory resident and infecting the virus uses several tricks, patches DOS kernel and accesses undocumented internal DOS structures. The virus has bugs and in some cases halts the system while installing memory resident.
The virus infects the MBR of the hard drive only if an infected program is executed for the first time in DOS box under MS Windows. The virus hooks INT 13h and infects floppy disks only after booting from infected hard drive. While infecting the virus stores the original MBR code in second sector on the hard drive and original boot sector on extra formatted track (80th). The virus corrupts the Disk Partition Table in the MBR, so the hard drive will be not available after booting from clean system disk or after repairing with FDISK/MBR.
The virus contains the text:
Unknown (c) 1997 G.K. Poland |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
I-Worm.Mapson.
Chek1.28
BlackAdder.101
OneHalf.Madjid.293
Macro.Word97.Nor
Trojan.Win32.AntiBT
Kipa.108
I-Worm.Halla
Vesna.160
Gotyou.505
|
|