| Description:
|
Details
Beda.883
These are memory resident parasitic stealth viruses. They hook INT 21h and write themselves at the end of the files are executed or closed. On infected file opening the viruses disinfect it, and then hit again on closing. They use BEDAh hexadecimal value as virus ID word for infected files, and on detection of already loaded virus TSR copy.
"Beda.883,1301" hit COM-files only, "Beda.1530" hits both COM- and EXE-files, on infection of EXE-files that virus may corrupt them.
"Beda.883,1301" are not dangerous viruses, depending on their internal counters they manifest themselves with the video effect.
"Beda.1530" is dangerous virus. It deletes the anti-virus programs -V, WEB, AIDSTEST, A-DINF. It hooks INT 09h also, and depending on its internal counter it changes the keys are entered: '?', 'n' and 'N' to 'B', 'y' and 'Y'. |