Depending on its counter the virus also hooks INT 21h. While executing a
file the virus searches a disk boot sector image within this file – the
virus scans the file for the “MSDOS” string and checks boot stamp 55AAh. If
such data are found, the virus replaces them with its copy. As a result,
the virus converts disk formatting utilities to virus droppers – while
formatting a disk they will write to the disk boot sector the virus code
instead of original bootstrap routine.