Virus Database


Arianna.2864

Description Arianna.2864

This is a memory resident multipartite, encrypted and stealth virus. While executing an infected file it infects the MBR of the hard drive. While loading from infected MBR it hooks INT 1Ch, waits for DOS loading, then hooks INT 13h for stealth algorithm while accessing to infected MBR, and INT 21h to infects the files. It writes itself to the end of EXE files that are accessed. When an infected file is opened, the virus disinfects it.
Sometimes the viruses manifest themselves with a video effect and erase the original MBR sector (not first hard drive sector, but the sector containing the original MBR that was saved while infecting a disk). The viruses contain the text strings:
"ARIANNA VIRUS"HAS DONE A RECOVERABLE DAMAGE
GOOD LUCK FRIEND !!
+--------------------------------------------+
| ARIANNA is changing your computer activity |
| If you wish no damage do not turn it off |
| ThanX for diffusion ! |
+--------------------------------------------+
Coded in Bari thanX 2 DOS UNDOCUMENTED

Check other viruses! Be aware! Use Antiviral Software

Manu.4096

Description Manu.4096

It is a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself at the end of COM- and EXE-files that are executed. It contains the internal text strings:
Manu virus Version 1.0
Parity error 0000:F243

The last string can be displayed in future versions of the virus, in that version, the corresponding branch is not activated.

Manuel family

Description Manuel family

These are memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files (except COMMAND.COM) that are executed or opened.
"Manuel.1155" searches for .COM files and infects it on DOS function GetDiskSpace (AH=36h) calls. While executing an infected file the virus infects the files from the list:
C:DOSFORMAT.COM
FORMAT.COM
C:DOSKEYB.COM
KEYB.COM

In some cases while installing the viruses display the messages:
"Manuel.777": Soy un Manuel Virus de tipo G
"Manuel.814": Soy un Manuel Virus de tipo N
"Manuel.840": Soy un Manuel Virus de tipo B
"Manuel.858": Soy un Manuel Virus de tipo L
"Manuel.876": Soy un Manuel Virus de tipo R
"Manuel.937": Soy un Manuel Virus de tipo C
"Manuel.957": Soy un Manuel Virus de tipo C
"Manuel.972": Soy un Manuel Virus de tipo B
"Manuel.995": Soy un Manuel Virus de tipo H
"Manuel.1155": Soy un Manuel Virus de tipo H
"Manuel.1388": Soy un Manuel Virus de tipo M

"Manuel.777,814,876" are not dangerous viruses, they does not manifest themselves in other ways.
"Manuel.840,972" are very dangerous viruses. Depending on their internal counters they delete the files instead of infecting them.
"Manuel.858" is not a dangerous one, depending on its internal counters it hooks INT 8 (timer) and delays on every timer tick.
"Manuel.937,957" erase CMOS memory.
"Manuel.995,1135" corrupt the disk sectors and display the message:
Manuel Virus: to repare HD, rotate rigth the sector (not the bytes)
number 2, head 0, of tracks 0 to length of this message

"Manuel.1388" plays a tune.
Manuel.2209
It is an encrypted virus. It infects both .COM and .EXE files. Depending on the system date the virus beeps with PC speaker. While executing an infected file the virus receives the control and infect the files:
C:DOSCOMMAND.COM
DOSCOMMAND.COM
COMMAND.COM
COMMAND.COM

This virus also contains the text strings:
c:doscommand.COM
Manuel strikes again

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Arvidsson, Marie Yvonne
GrÖna Badrum Ab
Patex StÄdservice
Östersunds Motorstadion Ab
TUNAVALLENS BILSERVICE AKTIEBOLAG

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com