When the virus is in memory, it hooks INT 8, 9, 1Ch and 21h to infect any executable file that is run or opened by writing itself to the end of the file.
The virus does not infect programs having their filenames begin with the following strings or overlay programs:
It also does not infect COM files that are smaller than or equal to 1,024 bytes.
The exact memory usage is 6,400 bytes.
After 330 seconds of installation of the virus, it displays a colorful message in Russian at the top of the screen. If the language of the system is not Russian, it displays garbage characters instead.
On issuing CTRL-ALT-DEL the virus displays the message with cycling colors:
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx BERZIN FANS CLUB PRESENT XX XX XX XX XXXXXX XXXXXX XXXXXXX XXX XXX XX XX XX XX XX XX XX XX X X XX XX XXX XX XX XXXXX XX XX XX X XX XX X XX XXXXXX XX XXXXXXX XX XX XXX XX XX XX XX XX XX XX XX XX XX XXXXXX XX XX TEL:(095)434-00-00 OR 03 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Since the keyboard input has been disabled after this, the user must hard reset the computer in order to reboot the system.