For background information on Word macro viruses, see the description of the WordMacro/Concept virus.
This is a complex Word macro virus. It activates on the 23rd of October. At this date it encrypts accessed Word documents with a random password.
It also might insert the following texts to documents:
NAENBGOURSG Hello from GREECE.
On 24th of October the virus creates a file called PCGURU4.BAT to the current directory. This file contains the following lines:
@echo off Rem PcGuru4 virus by NAENBGOURSG Rem Golden Version 4.3 type PcGuru4.bat >> PcGuru4.bat The virus also contains the following text: 'by NAENBGOURSG 'SO.HT.AI.KS '231076 -- GREECE 'VRD 23-4-1997 'VRP A.U.A
Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.
More scanning & removal options
More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.
You may also refer to the Knowledge Base on the F-Secure Community site for more information.
Description Details: Mikko Hypponen, F-Secure