Mandra family
Description Mandra family
These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed. Depending on the system timer the viruses display the messages: "Mandra.533": Mandragore for president !!! "Mandra.562": Mandragore'z sPirIt haunts ur computah ! "Mandra.664,669": BEER and TEQUILA forever !'
The viruses also contain the text strings: "Mandra.533": Mandragore [Mdrg v3.7] "Mandra.562": Mandragore [Mdrg v4] "Mandra.664,669": Mandragore [Mdrg v5] Error 8869: processor drunk 8*) Eddy iz still alive somwhere in time all...
Mandra.866,886 These are memory resident encrypted viruses infecting EXE files that are opened or executed. The viruses write themselves to the end of files while infecting them. The viruses use not documented DOS calls, and have a bug in this part of code: these functions are called incorrectly. As a result, if there are several files opened, or a file is executed when some other files are opened, the viruses can use wrong file offsets and corrupt files. The viruses call a video effect - running cow. The viruses also contain the strings: [MAD COW] Mandragore
Check other viruses! Be aware! Use Antiviral Software
Kurgan.919
Description Kurgan.919
These are not dangerous memory resident parasitic viruses. They hook INT 1Ch, 21h and write themselves to the end of COM and EXE files that are executed or opened. The length of COMMAND.COM file does not grow, these viruses write themselves at the zero-bytes area to the end of that file (see Lehigh virus). They contain the text "command". By hooking INT 1Ch they manifest themselves by different manners: "Kurgan.919" changes keyboard flags; "Kurgan.948" alters text symbols on the screen; "Kurgan.1624,1654" drop the letters on the screen as "Cascade" virus does.
Kurt.704
Description Kurt.704
This is a dangerous non-memory resident parasitic virus. It searches for COM files, then writes itself to the end of the file. The virus deletes the CHKLIST.MS and ANTI-VIR.DAT files. On the 5th of April, the virus creates the A:LEER.ME file, writes the text string into there, and displays the same string: KURT COBAIN Virus v0.3 pre_ß testing 1994(w) TruchoSoftware - Argentina
The virus also contains the text strings: chklist.ms anti-vir.dat A:LEER.ME A:
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|