Virus Database


TerraX Family

Description TerraX Family

These are not dangerous memory resident companion viruses. "TerraX.2874" is a polymorphic virus based on the SDFE 1.0 polymorphic engine.
The viruses hook INT 21h and then create companion COM files while executing .EXE files. While executing .COM files the viruses rename them to .EXE extension, and then infect as .EXE files. The viruses check the file name and do not infect the files with the string at the name beginning:
COMMAND IBM ET PC TB CKVI KLVI DEVI BTOOL RTOOL TDISK SCAN CLEAN HUNT F- TR
G Z

On 18th of any month the viruses display:
+-------------------------------+_
¦ " Terra'X " ¦_
¦-------------------------------¦_
¦ Written By Zhuge Jin at TPVO. ¦_
+-------------------------------+_
_________________________________

Check other viruses! Be aware! Use Antiviral Software

Gisela.702

Description Gisela.702

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. While installing memory resident the virus also infects the C:COMMAND.COM file. On January 21th the virus decrypts and displays the message:
Virus GISELA 2.0 By EJECUTOR (Hecho en Argentina)
Feliz cumpleaños Gisela.

GK.7697

Description GK.7697

It is a dangerous memory resident highly polymorphic and stealth multipartite virus. It infects the MBR of the hard drive, boot sector of 1.4Mb floppy disks and writes itself to the end of COM and EXE files that are accessed. The virus uses its polymorphic and stealth abilities for boot sectors as well as for executable files. When ARJ, LHA or PKZIP archivers or CHKDSK utility is active, the virus temporary disables its stealth routines.
To intercept system events the virus hooks INT 13h, 21h, 29h. While installing memory resident and infecting the virus uses several tricks, patches DOS kernel and accesses undocumented internal DOS structures. The virus has bugs and in some cases halts the system while installing memory resident.
The virus infects the MBR of the hard drive only if an infected program is executed for the first time in DOS box under MS Windows. The virus hooks INT 13h and infects floppy disks only after booting from infected hard drive. While infecting the virus stores the original MBR code in second sector on the hard drive and original boot sector on extra formatted track (80th). The virus corrupts the Disk Partition Table in the MBR, so the hard drive will be not available after booting from clean system disk or after repairing with FDISK/MBR.
The virus contains the text:
Unknown (c) 1997 G.K. Poland

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com