Threat Description

Quandary

Details

Aliases:Quandary, Parity.enc, Parity.Boot.Enc, IHC, Newboot, Newboot_1, WeRSilly, Quandry
Category:Malware
Type:Virus
Platform: W32

Summary



IBM Germany distributed a number of infected original diskettes in January 1996. The program in question was "VoiceType Vokabular". It was shipped on permanently write-protected floppies, which were infected with a boot sector virus.

Since this virus is pretty new, there's still some confusion about the name. F-Secure anti-virus products starting from F-PROT 2.21 detect it as 'Newboot_1', but the CARO name has been decided to be 'Quandary'. Other names for this virus are Parity.Boot.Enc and IHC.

The virus itself is very simple, basic boot sector virus. The only unusual thing about it is that it infects the MBR of all hard drives connected to a system, including the non-bootable slave drives.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.








Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More