Virus Database


Win32.Ditex

Description Win32.Ditex

Ditex is a memory resident parasitic Win32 virus. It is written in Microsoft Visual C++ and is about 33KB in size.
The virus infects PE EXE files that have .EXE filename extensions. While infecting the virus encrypts and writes itself to the end of the file. The virus code in infected files has two blocks: dropper and main code.
When an infected file is run the "dropper" gets control. It decrypts itself, decrypts the "main code" and then drops the "main code" into a Win32 PE EXE file under the TDI.SYS name in the Windows directory and runs it.
The main code searches for PE EXE files in directories on local drives and when found infects them.
The virus also contains a {backdoor:Backdoor} routine that opens an Internet connection, waits for its master's (virus author) instructions and then follows them: sends/receives files, executes programs, reports system informationall

Check other viruses! Be aware! Use Antiviral Software

Ko.360

Description Ko.360

These are memory resident parasitic viruses. They copy the TSR-parts into the Interrupt Vectors Table, hook INT 21h, then write themselves to the end of .COM files that are executed. These viruses contain the word "Ko".
"Ko.408" corrupt the files that do not have JMP NEAR (E9h) opcode at the beginning of the file. Sometimes it overwrite the files with RET instruction. On every 33rd infection "Ko.408.b" displays:
Birdie Hop!

On every 50th infection "Ko.407" overwrites the file with the random data.

Kode.145

Description Kode.145

These are not dangerous nonmemory resident parasitic viruses. They search for .COM files in the current directory, then write themselves to the end of the file. Major versions of these viruses check the command line, and if there is the "/?" option, they display the messages:
"Kode.328,329": GRAPHIC CARD UNABLE TO PILOT YOUR FUCKED MONITOR
"Kode.335,336": GRAPHIC CARD UNABLE TO PILOT YOUR STUPID MONITOR

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Business First Aid Kit
Buy Hoodia Gordonii
Voip Service Provider
Bowtrol Reviews
Bolivia Phone Cards

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com