Threat Description

GhostBalls

Details

Aliases:GhostBalls
Category:Malware
Type:Virus
Platform: W32

Summary



This virus was written in Iceland and first discovered there in October 1989. It contains the following text strings:

  GhostBalls, Product of Iceland
 Copyright (c) 1989, 4418 and 5F19


Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Basically it is just the Vienna virus - the variant in the book by Ralf Burger to be specific, with an extra twist. When an infected program is run, the virus will search for other programs to infect, but also try to place a modified copy of the Ping-Pong virus on the diskette in drive A, provided it is a 360K diskette. This Ping-Pong variant has been changed, so that it is not infectious, but it will also work on a '286 machine.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More