Virus Database


Manuel family

Description Manuel family

These are memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files (except COMMAND.COM) that are executed or opened.
"Manuel.1155" searches for .COM files and infects it on DOS function GetDiskSpace (AH=36h) calls. While executing an infected file the virus infects the files from the list:
C:DOSFORMAT.COM
FORMAT.COM
C:DOSKEYB.COM
KEYB.COM

In some cases while installing the viruses display the messages:
"Manuel.777": Soy un Manuel Virus de tipo G
"Manuel.814": Soy un Manuel Virus de tipo N
"Manuel.840": Soy un Manuel Virus de tipo B
"Manuel.858": Soy un Manuel Virus de tipo L
"Manuel.876": Soy un Manuel Virus de tipo R
"Manuel.937": Soy un Manuel Virus de tipo C
"Manuel.957": Soy un Manuel Virus de tipo C
"Manuel.972": Soy un Manuel Virus de tipo B
"Manuel.995": Soy un Manuel Virus de tipo H
"Manuel.1155": Soy un Manuel Virus de tipo H
"Manuel.1388": Soy un Manuel Virus de tipo M

"Manuel.777,814,876" are not dangerous viruses, they does not manifest themselves in other ways.
"Manuel.840,972" are very dangerous viruses. Depending on their internal counters they delete the files instead of infecting them.
"Manuel.858" is not a dangerous one, depending on its internal counters it hooks INT 8 (timer) and delays on every timer tick.
"Manuel.937,957" erase CMOS memory.
"Manuel.995,1135" corrupt the disk sectors and display the message:
Manuel Virus: to repare HD, rotate rigth the sector (not the bytes)
number 2, head 0, of tracks 0 to length of this message

"Manuel.1388" plays a tune.
Manuel.2209
It is an encrypted virus. It infects both .COM and .EXE files. Depending on the system date the virus beeps with PC speaker. While executing an infected file the virus receives the control and infect the files:
C:DOSCOMMAND.COM
DOSCOMMAND.COM
COMMAND.COM
COMMAND.COM

This virus also contains the text strings:
c:doscommand.COM
Manuel strikes again

Check other viruses! Be aware! Use Antiviral Software

Grozny.999

Description Grozny.999

It's a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are executed. It writes at the end of the file a block of random data of random length before infection, so the length of the file is grown on random value on infection. This virus contains and displays a text in Russian.

Grunt.344

Description Grunt.344

These are dangerous not memory resident encrypted parasitic viruses. They search for .COM-files and write themselves to the file's ends. "Grunt" viruses erase disk sectors or files, they also type messages. These viruses contain the internal text strings:
"Grunt.344,346":
[GRUNT-1] -=> Agent Orange '92 <=- *.com

"Grunt.359":
ALLERBMU NORI+
(C) 1991 by SMAUG in MÜNCHEN, DEUTSCHLAND!

"Grunt.427":
[GRUNT-2] -=> Agent Orange '92 <=- Rock of the Marne, Sir!

"Grunt.473":
[GRUNT-3] -=> Agent Orange '92 <=- This is a hot LZ all Eradicating the Enemy!

"Grunt.529":
[GRUNT-4] *.COM TBFILXXX .. -=> Agent Orange '92 <=-
Nothing like the smell of napalm in the morning!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com