This is a very dangerous nonmemory resident parasitic encrypted virus. The virus searches for COM files then writes itself to the end of the file. The virus do not infects the COMMAND.COM file, but the string comparing utility has a bug, and the virus do not infect C*.COM files. If the virus detects a file that has COM extension and EXE internal format, the virus overwrites that file with a program that displays the message in Russian. Some viruses of that family disinfect the host file before return.
On October 21 the viruses display the message:
HAPPY BIRTHDAY OKSANA
Depending on the generation or counters the virus reads into the system memory and then erases the FAT of the C: drive and displays the message in Russian. Then the virus wait for 3:00am and restores the FAT.
It displays:
CRAZY ! I~m here !