F-Secure Virus Descriptions : Nado
This buggy virus infects COM files when they are accessed and tries
to hide the size increase of the infected files.
It contains this text:
[Yitzak-Rabin 1.00 (c) made by TorNado in Denmark'96]
Nado contains code to activate when the DEL key is pressed on the keyboard.
At this time it tries to overwrite the boot sector of the hard drive with
the above text. Nado.841 also deletes anti-vir.dat files.
There are several variants, sized between 584 and 841 bytes. Some of
these variants overwrite hard drives and corrupt CMOS setup or just
delete antivirus program when they are executed. Some of them also
infect EXE files instead of COM files. However, the 841 byte variant
is the only common variants. Note that the 584 byte variant can not
always be succesfully repaired; it corrupts files when infecting.
Nado was confirmed to be in the wild in Denmark in April 1996.
[Analysis: Mikko Hypponen, F-Secure]
|