It is a harmless(?) nonmemory resident companion virus. It searches
for NewEXE files, renames them with OVL extension and replases original
files with the virus code. The virus contains the partly encrypted strings:
BOOT SHELL SYSTEM.INI PATH TEMP OVL CHKLIST.CPS *.EXE
NETWARE FILEMAN SCRNSAVE WINPRINT WINDOWS
DeviceSelectedTimeout
LOAD .EXE SYSTEM SYSEDIT.EXE NWPOPUP.EXE