It is a very dangerous nonmemory resident encrypted parasitic virus. It searches for COM and EXE files, then infects them. The virus writes itself to the end of EXE files and to the beginning of COM files. While infecting a file the virus uses old file access FCB calls.
The virus creates the WSURC.DMA file, searches and tries to execute the C:WIN95WRIVDR.CNF file, depending on the system time and the drive number it overwrites .BAK, .CPP and .C files with the message in Russian.
æp"_¡" "ípá_¿_Ñß_ ¬ áñ¼¿¡¿ß_á_"¶ ßÑ_¿.