1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Nado SIZE:841 TYPE:Resident COM-files Stealth ORIGIN:Denmark

Summary

This buggy virus infects COM files when they are accessed and tries to hide the size increase of the infected files.

It contains this text:

        [Yitzak-Rabin 1.00 (c) made by TorNado in Denmark'96]

Additional Details

Nado contains code to activate when the DEL key is pressed on the keyboard. At this time it tries to overwrite the boot sector of the hard drive with the above text. Nado.841 also deletes anti-vir.dat files.

There are several variants, sized between 584 and 841 bytes. Some of these variants overwrite hard drives and corrupt CMOS setup or just delete antivirus program when they are executed. Some of them also infect EXE files instead of COM files. However, the 841 byte variant is the only common variants. Note that the 584 byte variant can not always be succesfully repaired; it corrupts files when infecting.

Nado was confirmed to be in the wild in Denmark in April 1996.

[Analysis: Mikko Hypponen, F-Secure]