It is not a dangerous memory resident parasitic virus. It hooks INT 10h, 21h and infects .COM files that are executed. While infecting the virus search for zero bytes are in the file body, and writes itself to there. If there is no such are, the virus does not infect the file. The file length does not grow while infecting.
When the video mode is changed to graphic mode 5 (INT 10h, AX=0005h), the virus draws an image of helicopter.
Check other viruses! Be aware! Use Antiviral Software
This is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h, when any programs are executed, then it searches for .COM files and writes itself to the end of the file. On August 6th, 7th, 8th, 9th and 10th, it corrupts the disk sectors. The virus contains the internal text strings:
It is not a dangerous memory resident boot virus. It infects the MBR of the hard drive and the boot sector of floppy disks. The MBR gets infection on loading from infected floppy disk, the boot on floppy disks gets infection on accessing the disk.
The virus calls Novell Netware function and creates a supervisor object there with the "ANDRISD" name. This object then might be used to login illegal user with supervisor privileges. This object is also invisible for non-supervisor users.
Viruses from A to Z