02.08.2013 Views

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

Macro Virus Table - Defense Technical Information Center

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

PC<br />

Damage: Corrupts boot<br />

sector<br />

Interferes with a running<br />

application.<br />

Corrupts a program or overlay<br />

files.<br />

MS-DOS/PC-DOS Computer <strong>Virus</strong>es<br />

Interferes with a running application.<br />

Corrupts a program or overlay files.<br />

Size: 2351 See Also:<br />

Notes: Variant of Vienna that puts a patched copy of the Ping Pong virus in the boot of drive A.<br />

It may infect floppy and hard disk boot sectors, sources differ on this.<br />

It contains the following text strings:<br />

GhostBalls, Product of Iceland<br />

Copyright (c) 1989, 4418 and 5F19 Bouncing ball on screen. COM files:<br />

"seconds" field of the timestamp changed to 62, as in the original Vienna virus. Infected files end<br />

in a block of 512 zero bytes. The string "GhostBalls, Product of Iceland" in the virus.<br />

Name: Ginger<br />

Aliases: Ginger, Peanut, Gingerbread man, Rainbow Type: Multipartite.<br />

Disk Location: EXE application.<br />

COM application.<br />

MBR Hard disk master boot record-partition<br />

table.<br />

Features: Corrupts hard disk partition table<br />

Damage: Corrupts hard disk<br />

partition table<br />

Size: See Also:<br />

Notes: This is a family of stealth multipartite fast infecting viruses originating from Australia.<br />

There are at least five variants, sizes ranging from 2 to 3 kB.<br />

One of the variants generates an endless loop to the partition table, making PC crash when it tries<br />

to boot from a clean floppy which has MS-DOS v4.0 - 7.0. To overcome this, use PC-DOS 7.0,<br />

MS-DOS 3.3x or a non-DOS boot floppy.<br />

Note: Rainbow is also an alias for the Word<strong>Macro</strong>/Colors virus.<br />

Name: Girafe<br />

Aliases: Girafe, Trident, TPE Type:<br />

Disk Location: Features:<br />

Damage: Size: See Also: TPE<br />

Notes: Contains the internal string "[ MK / Trident]"<br />

v6-123: TPE.1_0.Girafe Disables Ctrl-Break checking.<br />

Name: Gliss<br />

Aliases: Gliss Type: Program.<br />

Disk Location: COM application. Features: Unknown, not analyzed yet.<br />

Damage: Unknown, not<br />

analyzed yet.<br />

Size: 1247 See Also:<br />

Notes: Demonstration virus that announces its infections of programs.<br />

196 CIAC Computer <strong>Virus</strong> <strong>Information</strong> Update May 21, 1998

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!