Nado

Classification

Malware

Virus

-

Nado

Summary

This buggy virus infects COM files when they are accessed and tries to hide the size increase of the infected files.

It contains this text:

[Yitzak-Rabin 1.00 (c) made by TorNado in Denmark'96]

Removal

Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

Nado contains code to activate when the DEL key is pressed on the keyboard. At this time it tries to overwrite the boot sector of the hard drive with the above text. Nado.841 also deletes anti-vir.dat files.

There are several variants, sized between 584 and 841 bytes. Some of these variants overwrite hard drives and corrupt CMOS setup or just delete antivirus program when they are executed. Some of them also infect EXE files instead of COM files. However, the 841 byte variant is the only common variants. Note that the 584 byte variant can not always be succesfully repaired; it corrupts files when infecting.

Nado was confirmed to be in the wild in Denmark in April 1996.

Date Created: -

Date Last Modified: -