Virus Name: Raver
V Status: New
Discovery: January, 1995
Symptoms: .EXE file growth
Eff Length: 449 Bytes
Type Code: PNE - Parasitic Non-Resident .EXE Infector
Detection Method: F-Prot, AVTK, IBMAV, ViruScan, Sweep, NAV, NAVDX,
VAlert, PCScan, ChAV,
AVTK/N, IBMAV/N, NShld, Sweep/N, NAV/N, LProt, Innoc 4.0+
Removal Instructions: Delete infected files
The Raver virus was received in January, 1995. Its origin or point
of isolation is unknown. Raver is a non-resident, direct action
infector of .EXE files.
When the first Raver infected program is executed, this virus will
infect all of the .EXE files located in the current directory.
Infected files will have a file length increase of 449 bytes with
the virus being located at the end of the file. The program's date
and time in the DOS disk directory listing will not be altered. The
following text string is encrypted within the viral code in all
".. *.exe DOOM! (c) '93 Raver/Immortal Riot"
It is unknown what the Raver virus does besides replicate.