This non-resident virus attacking PE files with extensions EXE and SCR comes from Czech Republic. The virus attacks files in the current directory and in the system directory with Windows. When an infected file is run the virus imports 22 functions from Kernel32.dll. It tests the system time (derived from the Greenwich Time). If the virus is started on Saturday at 7 pm GMT, i.e. 8 pm Central Europe Time, it displays the following notice:

After displaying the notice the virus moved it.

