Threat Description

GhostBalls

Details

Category: Malware
Type: Virus
Platform: W32
Aliases: GhostBalls

Summary


This virus was written in Iceland and first discovered there in October 1989. It contains the following text strings:

     GhostBalls, Product of Iceland        Copyright (c) 1989, 4418 and 5F19  


Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details


Basically it is just the Vienna virus - the variant in the book by Ralf Burger to be specific, with an extra twist. When an infected program is run, the virus will search for other programs to infect, but also try to place a modified copy of the Ping-Pong virus on the diskette in drive A, provided it is a 360K diskette. This Ping-Pong variant has been changed, so that it is not infectious, but it will also work on a '286 machine.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More