Main Menu
Home
Bookmark
Contact Us



 
Gumbs.358 Viruses Information

Name: Gumbs.358
Category: Viruses
Description: Details
Gumbs.3584

It is not a dangerous memory resident encrypted, stealth multipartite virus. It hooks INT 13h, 1Ch, 21h, infects the C: drive boot sector and writes itself to the end of EXE files on the floppy disks on file accessing.
When an infected file is executed, the virus writes itself to the boot sector of first drive on the hard disk (C: drive) and returns control to the host file. On rebooting the virus starts from affected boot sector, installs itself into DOS memory and hooks INT 13h and INT 21h.
By hooking INT 13h the virus hides its code presence in C: drive sectors (stealth). By hooking INT 21h the virus also runs its stealth routines, as well as infection.
On accesses to EXE files on floppy drives (A: and B:) the virus infects them. The virus does not infect the files AIDS*.EXE and DRWE*.EXE. The virus also runs its stealth routine to hide infected file length growing on floppy disks as well as on the hard drive.
On April 1st in one case of eight the virus intercepts INT 8 (timer) and plays the "Hey Jude" tune (The Beatles).
The virus contains text string in Russian and the text:
Disk I/O error.



Top Viruses Visited Pages:
Invader. - 231 visits
not-a-virus:RiskWare.Tool.RegPatch. - 69 visits
Worm.P2P.Harex. - 63 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 55 visits
Small.58. - 55 visits
Coito.64 - 53 visits
I-Worm.Mapson. - 45 visits
Win32.Hidra - 41 visits
Win16.Klon.1177 - 40 visits
Marine.500 - 34 visits

Random Viruses Pages:
Vofca Famil
Nipple.20
Armagedon.20
Macro.Excel.Soldie
Deicide.35
GoodThursda
Win32.VCell.304
HLLP.Iro
DARV.102
Glew.424


 


© 2006-2008 spyware32.com - Privacy Policy