It is a harmless nonmemory resident parasitic virus. It searches for .COM and .EXE files in the current directory, then checks files' internal format and infects DOS COM and EXE files, as well as Windows PE executable files. While infecting the virus writes itself to the end of the file. The PE infection routine is not correct enough, and infected PE files do not work under WinNT.
The virus code has two segments. The first segment is 16 bits DOS procedure that receives control when an infected DOS file is executed. The second segment is 32 bits routine that is activated when Windows infected executable starts. Both routines in similar way search for COM, EXE and PE files and infect them.
The virus does not manifest itself in any way. It contains the text strings:
[Pyros]
[Ruiner /CIH]