Main Menu
Home
Bookmark
Contact Us



 
GW.120 Viruses Information

Name: GW.120
Category: Viruses
Description: Details
GW.1201

It is a harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or closed. The virus checks file names and does not infect anti-virus programs and files with the names: AIDSTEST, DRWEB, COMMAND, IBM*, AVP.
While infecting the virus uses undocumented System File Tables. The virus also uses other tricks to hide itself in the memory and access system resources: it traces INT 13h to get original INT 13h handler and patches DOS kernel to intercept file accessing calls.
The virus is encrypted in files as well as in the system memory. When needed the virus decrypts routines, executes them and then encrypts.
The virus does not manifest itself in any way. At the beginning of its code it contains a set of instructions that looks like text string:
_GW



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Win32.Yerg.941
Sentinel Famil
Tib famil
HTML.NoWarn.
Backdoor.Subseve
Chameleon Famil
Macro.Word.NOP.
Win32.Benny.3219.
LTS.27
Metall.55


 


© 2006-2008 spyware32.com - Privacy Policy