Skip to main content

Mandragore

Classification

Category:

Malware

Aliases:

  • Mandragore
  • GnutellaMandragore
  • Gnutella worm

Summary

GnutellaMandragore is a worm which spreads through the Gnutella peer-to-peer file sharing system (which is somewhat similar to Napster). If you're not using Gnutella, you're not at risk. Popular programs to access Gnutella include ToadNode and BearShare.

Removal

Technical Details

When a PC gets infected, the worm will connect to the Gnutella network as one node. After that it will monitor what kind of files other people are searching for, and will answer those queries.

For example, if a Gnutella user makes search for "rare pictures of butterflies", the infected node will announce it has available a file called "rare pictures of butterflies.exe", 8kB in size.

If the user downloads and clicks on this file, his machine becomes infected and will start to offer infected files for other users.

Infected nodes easily become overloaded and are unable to answer all requests. So every search does not find infected files although there are infected nodes in the network.

In some cases, infected files are offered without the EXE extension. Such files will fail to execute when doubleclicked but work fine if run from the commandline.

First infected files in the Gnutella network were spotted on Friday the 23rd of February, 2001.

An easy way to avoid infection from this worm is not to download EXE files from the Gnutella network. Some clients (such as BearShare) hide executable files from seach results by default.

For more information, see:

https://www.exocortex.org/gnutella/

F-Secure Anti-Virus detects this virus since Tuesday, 27th of February. The updates are available on our web site:

USA:

https://www.f-secure.com/download-purchase/updates.shtml

Europe:

https://www.europe.f-secure.com/download-purchase/updates.shtml

[Mikko Hypponen, F-Secure Corporation, Feb 27, 2001]

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.