There are 4 variants:
When the virus is loaded into memory, it first infects these files:
C:\DOS\DOSKEY.COM C:\DOS\EDIT.COM C:\DOS\FORMAT.COM C:\DOS\KEYB.COM C:\DOS\SYS.COM C:\DOS\UNFORMAT.COM C:\WINDOWS\WIN.COM
After that it hooks INT 21h to infect any DOS executable that is run except COMMAND.COM. After infection, these files may no longer function properly, usually causing a system hang after execution.
The virus behaves stealthy so that no size change can be observed.
The following table shows the memory usage of the variants.
|Variant||Memory usage in bytes|
When an infected program is run on the 1st of any month, the virus displays a demo effect of other DOS virus. The payload demos can be stopped and then return to DOS by pressing ESC key, while the host program would never execute anymore.
This variant displays the payload of the virus Flame, a variant in the family of the boot sector virus Stoned.
This variant tries to display the payload of the virus SillyWilly, but due to some programming faults, it displays gibberish characters instead.
This variant displays the payload of the virus Devil's Dance.
This variant plays a tune of the virus Goodbye.
The virus contains the internal text string:
What??? Truxested??? Me??? c:\dos\doskey.com c:\dos\edit.com c:\dos\format.com c:\dos\keyb.com c:\dos\sys.com c:\dos\unformat.com c:\windows\win.com