Threat Description

Angus

Details

Aliases:Angus
Category: Malware
Type:
Platform: W32

Summary



For background information on Word macro viruses, see the description of the WordMacro/Concept virus.

This is a complex Word macro virus. It activates on the 23rd of October. At this date it encrypts accessed Word documents with a random password.

It also might insert the following texts to documents:

NAENBGOURSG
  Hello from GREECE.

On 24th of October the virus creates a file called PCGURU4.BAT to the current directory. This file contains the following lines:

@echo off
  Rem PcGuru4 virus by NAENBGOURSG
  Rem Golden Version 4.3
  type PcGuru4.bat >> PcGuru4.bat
  The virus also contains the following text:
  'by NAENBGOURSG
  'SO.HT.AI.KS
  '231076 -- GREECE
  'VRD 23-4-1997
  'VRP A.U.A


Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.








Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More