Virus Encyclopedia

Computer Virus Encyclopedia

Virus.Win32.Ditex.a

Alert Level : High
Discovered: Jan 22 2003
Tag:
Discoverer and Source: http://www.kaspersky.com/

Malware Behavior and Technical Description

Ditex is a memory resident parasitic Win32 virus. It is written in Microsoft Visual C and is about 33KB in size.

The virus infects PE EXE files that have .EXE filename extensions. While infecting the virus encrypts and writes itself to the end of the file. The virus code in infected files has two blocks: dropper and main code.

When an infected file is run the "dropper" gets control. It decrypts itself, decrypts the "main code" and then drops the "main code" into a Win32 PE EXE file under the TDI.SYS name in the Windows directory and runs it.

The main code searches for PE EXE files in directories on local drives and when found infects them.

The virus also contains a {backdoor:Backdoor} routine that opens an Internet connection, waits for its master's (virus author) instructions and then follows them: sends/receives files, executes programs, reports system information...

0

Removal Virus.Win32.Ditex.a instructions:

0

Need help? Live computer support via remote at SupportSpace.Help with printer problems, windows, hardware, software, spyware removal and more. - Go Now!

Site Map
About Us