This trojan erases data on a hard drive and attempts to corrupt
Flash BIOS when executed. The trojan itself is a standalone
Windows PE executable. It works under Win95/98 only.
To erase disk data and corrupt Flash BIOS the trojan uses the
routine from 'Win95.CIH' (aka 'Chernobyl') virus. It seems that
trojan code was compiled from the 'Win95.CIH' virus sources,
where all infection routines were removed and only payload
routine was left.
[Analysis: AVP and F-Secure teams]