It is not a dangerous nonmemory resident parasitic virus. While installing into the system the virus copies its file to the Windows system directory with the D3F70N3S.COM filename and registers it in the system registry to be run each time any another application starts. The virus does that by creating a new key in the HKEY_CLASSES_ROOT, the key name is exefileshellopencommand and it is associated with the virus copy (with the D3F70N3S.COM file that was created in the Windows system folder). The virus infects all files, which are executed through it. Before executing infected file the virus renames its extension to ".COM".