Ghos
Sunday, October 26th, 2008Details
Ghost
It is a dangerous memory resident boot virus. It infects the MBR of the hard drive and boot sector on floppy disks. While infecting the virus saves the original MBR sector on the hard drive at the address 0/0/8 (track/head/sector) and the original boot sector of floppy disks to the last sector of root directory.
On loading from infected disk the virus copies itself into Interrupt Vectors Table and hooks INT 13h. It then infects floppy disks that are accessed. The hard drive MBR gets infection while loading from infected floppy disk.
While loading from infected floppy disk, if the MBR is already infected, the virus disinfects it: restores the original MBR image and fills sector 0/0/8 with zero byte. While disinfecting the virus leaves its “signature” in the last entry in Disk Partition Table: “GHOST”.
The virus uses quite risky anti-debugging trick and as a result halts Pentium computers.