This buggy virus infects COM files when they are accessed and tries to hide the size increase of the infected files.
It contains this text:
[Yitzak-Rabin 1.00 (c) made by TorNado in Denmark'96]
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
Nado contains code to activate when the DEL key is pressed on the keyboard. At this time it tries to overwrite the boot sector of the hard drive with the above text. Nado.841 also deletes anti-vir.dat files.
There are several variants, sized between 584 and 841 bytes. Some of these variants overwrite hard drives and corrupt CMOS setup or just delete antivirus program when they are executed. Some of them also infect EXE files instead of COM files. However, the 841 byte variant is the only common variants. Note that the 584 byte variant can not always be succesfully repaired; it corrupts files when infecting.
Nado was confirmed to be in the wild in Denmark in April 1996.
Date Created: -
Date Last Modified: -