| Description:
|
Details
Getto.2000
It is a very dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or accessed by FindFirst/Next DOS calls. On 10th, 20th and 30th of any month, depending on the system timer and its counters the virus deletes the files C:IO.SYS, C:MSDOS.SYS, C:CONFIG.SYS and displays the message:
DOS/4GW Professional Protected Mode Run-time Version 1.95
Copyright (c) Rational Systems, Inc. 1990-1993
Getto Virus Version 1.0 Copyright (C) 1995,96 by Geci Ållat
This Getto requirest 80286 or better processor
Formating Hard Disk #1 [all................]
Formating Hard Disk #2 [...................]
Ready.
gEtTo Always the Best! MS-SUX Destroyer
The virus also contains the text strings:
Tested with F-Prot v2.22 and TBAV700 |