Malware type: Elf Executable

Aliases: Virus.Linux.Osf.8759 (Kaspersky), Linux/Osf.8759 (McAfee), Linux.Jac.8759 (Symantec), LINUX/OSF-8759 (Avira), Linux/OSF-A (Sophos),

In the wild: No

Destructive: No

Language: English

Platform: UNIX

Encrypted: No

Overall risk rating:

This is non-destructive ELF executable virus runs only on UNIX platforms. Once executed, it infects all files in the current directory.

For additional information about this threat, see:

Description created: Mar. 10, 2002 5:09:14 PM GMT -0800
Description updated: Mar. 11, 2002 1:36:52 AM GMT -0800


Size of malware: 8,759 Bytes

Initial samples received on: Mar 10, 2002

This non�destructive ELF executable virus runs only on UNIX platforms. Once executed, it searches for and then infects all ELF files in the current directory. To do this, it appends 8,759 Bytes of its virus code to the target file.

It uses the following text string as its infection marker on infected files:



Minimum scan engine version needed: 5.45

Pattern file needed: 1.238.00

Pattern release date: Mar 10, 2002

Important note: The "Minimum scan engine" refers to the earliest Trend Micro scan engine version guaranteed to detect this threat. However, Trend Micro strongly recommends that you update to the latest version in order to get comprehensive protection. Download the latest scan engine here.


Scan your system with Trend Micro antivirus and delete all files detected as ELF_GMON.A. To do this, Trend Micro customers must download the latest pattern file and scan their system.

Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network, small and medium business, mobile device or home PC.