Virus.Win32.Ditex.a
| Alert Level : | High |
| Discovered: | Jan 22 2003 |
| Tag: | Executable File and Boot Viruses |
| Discoverer and Source: | http://www.kaspersky.com/ |
Malware Behavior and Technical Description
Ditex is a memory resident parasitic Win32 virus. It is written in Microsoft Visual C and is about 33KB in size.
The virus infects PE EXE files that have .EXE filename extensions. While infecting the virus encrypts and writes itself to the end of the file. The virus code in infected files has two blocks: dropper and main code.
When an infected file is run the "dropper" gets control. It decrypts itself, decrypts the "main code" and then drops the "main code" into a Win32 PE EXE file under the TDI.SYS name in the Windows directory and runs it.
The main code searches for PE EXE files in directories on local drives and when found infects them.
The virus also contains a {backdoor:Backdoor} routine that opens an Internet connection, waits for its master's (virus author) instructions and then follows them: sends/receives files, executes programs, reports system information...
0
Removal Virus.Win32.Ditex.a instructions:
0
Need help? Live computer support via remote at SupportSpace |

