Virus Protection > computer-virus-w-page1 > - win32.dite

win32.dite

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
Win32.Ditex

Ditex is a memory resident parasitic Win32 virus. It is written in Microsoft Visual C++ and is about 33KB in size.
The virus infects PE EXE files that have .EXE filename extensions. While infecting the virus encrypts and writes itself to the end of the file. The virus code in infected files has two blocks: dropper and main code.
When an infected file is run the "dropper" gets control. It decrypts itself, decrypts the "main code" and then drops the "main code" into a Win32 PE EXE file under the TDI.SYS name in the Windows directory and runs it.
The main code searches for PE EXE files in directories on local drives and when found infects them.
The virus also contains a {backdoor:Backdoor} routine that opens an Internet connection, waits for its master's (virus author) instructions and then follows them: sends/receives files, executes programs, reports system informationall

Updated: 02/24/2006
Copyright @2006 win32.dite
Webroot Software Inc.