On the first infection it will drop an exported copy of the virus code in an ascii file c:\class.sys. When working with the infected files on the 14TH of the month and the current month is not January through April, a message box like
I Think " (word97 reg. User name) " is a big stupid jerk!
is displayed. Also this virus modifies the RegisteredOwner and RegisteredOrganization values in the registry at the following location-