Win32/Tvido [Threat Name] go to Threat

Win32/Tvido.B [Threat Variant Name]

Category virus
Aliases Virus.Win32.Tvido.a (Kaspersky)
  W32.Tvido.A (Symantec)
  W32/Tvido.virus (McAfee)
Short description

Win32/Tvido.B is a polymorphic file infector.

Executable file infection

The virus infects executable files.

The virus searches local and network drives for files with one of the following extensions:

  • .exe

Files are infected by adding new sections that contain malicious code.

The host file is modified in a way that causes the virus to be executed prior to running the original code.

The virus avoids infecting files stored on the system drive.

Other information

The virus inserts the following text/marker into the header of the infected executable files:

  • Virus WeeD v1.1 Made in Belarus!

The marker is used to determine whether the file is already infected or not.

