|
|
Ginger Famil Viruses Information
| Name: |
Ginger Famil |
| Category: |
Viruses |
| Description:
|
Details
Ginger Family
These are harmless memory resident stealth multipartite viruses. While executing an infected file the viruses infect the MBR sector of the hard drive. While infecting the viruses correct only the physical address of the Active Boot Sector (from which DOS is loaded), the viruses set this address to 0/0/2 (cylinder/head/sector) and write their code and data to that and followed sectors. As a result the viruses correct only three bytes in the MBR. While loading from an infected sector the viruses hook INT 13h, 21h and write themselves to the end of COM and EXE files that are accessed. The viruses contain the text strings, several of them are in use when the viruses infect the files:
"Ginger.2774,2782":
You can't catch the Gingerbread Man!!
Bad Seed - Made in OZ
COMSPEC= COMMAND.COM
CHKDSK MEM
10/23/92
"Ginger.Orsam.2624":
Orsam - Made in OZ
You can't catch the Gingerbread Man!!
COMMAND |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
NoDbf.100
Mirror.413
ShuHard.38
Macro.Word.Har
Kwx.145
Macro.Word.Niknat.
Jorgito.63
NED-based viruse
Tcp.40
Advent.Cookie.223
|
|