This is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h, and writes itself to the end of EXE files that are executed.
It was named after text strings in its code:
This virus does not infect the anti-virus programs ADINF, AIDSTEST, and DRWEB. To avoid detection and disinfection by these anti-viruses, the virus deletes the DRWEB.INI file, displays a message in Russian and halts the computer when ADINF is executed. On the 31st, the virus overwrites PAS files with a text in Russian.
|Find out the statistics of the threats spreading in your region|