To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here

WinDrivers Computer Tech Support Forums  

Go Back   WinDrivers Computer Tech Support Forums > For Techs Only > Spyware & Antivirus - Security

Spyware & Antivirus - Security Discuss all system security, spyware, adware and malware issues here.

Reply
 
Thread Tools Search this Thread Display Modes
Old May 2nd, 2001, 10:57 AM   #1
byteme_1997
Guest
 
Posts: n/a
Question Monkey.1

just had a customer come in with this virus on their computer. I was able to successfully clean it from the system, but have been trying to find out any information regarding it. I checked with SARC but haven't been able to find anything. Has anyone out there run across this virus before?

Mike
  Reply With Quote
Old May 2nd, 2001, 11:01 AM   #2
LagMonster
Registered User
 
Join Date: Dec 2000
Location: Circle Pines,MN,USA
Posts: 805
Post

What program did you use to quarentine it. And what was the virus name "monkey.1"?

Is there any other info you can give us?
LagMonster is offline   Reply With Quote
Old May 2nd, 2001, 11:01 AM   #3
King Grover
Most Greaterlyist
 
King Grover's Avatar
 
Join Date: Apr 2001
Location: 12345 Sesame Street.
Posts: 1,680
Post

http://www.cai.com/virusinfo/encyclopedia/


Monkey (Also known as Hemoroid)
Stealth virus that encrypts and hides the original Master Boot Record, overwriting the partition table.

This virus originated in Europe in December 1993 and is based on the Stoned virus. Monkey has no known warhead, but if you boot from an uninfected system disk you will not be able to access the hard drive from DOS.

When Monkey infects a hard disk, it stores the encrypted (XORed with a constant) MBR in cylinder 0, head 0, sector 3 and then copies itself to cylinder 0, head 0, sector 1, overwriting the partition information. Monkey is a stealth virus and when active in memory it hides its presence on disk by returning the original MBR when the user tries to read cylinder 0, head 0, sector 1. The original DOS Boot Sector is hidden in the last sector of the root directory (floppies only) and can therefore cause the loss of up to 16 directory entries. When a new floppy is accessed on an infected system, the chance that Monkey will infect its DOS boot sector are 1 in 4.
__________________
It's good to be the King.
King Grover is offline   Reply With Quote
Old May 2nd, 2001, 01:15 PM   #4
Darren Wilson
Guest
 
Posts: n/a
Post

& heres the SARC version.
http://www.symantec.com/avcenter/ven...re.monkey.html
  Reply With Quote
Old May 2nd, 2001, 01:34 PM   #5
LagMonster
Registered User
 
Join Date: Dec 2000
Location: Circle Pines,MN,USA
Posts: 805
Post

I suck
LagMonster is offline   Reply With Quote
Old May 3rd, 2001, 10:15 PM   #6
i3omberman28
Registered User
 
Join Date: Apr 2001
Posts: 63
Red face

What scanner do you use? and which is the best out of theM?
i3omberman28 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 08:04 PM.



Acceptable Use Policy

internet.comMediabistrojusttechjobs.comGraphics.com

WebMediaBrands Corporate Info


Advertise | Newsletters | Feedback | Submit News

Legal Notices | Licensing | Permissions | Privacy Policy

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.