For background information on Word macro viruses, see the description of the WordMacro/Concept virus.
This is a complex Word macro virus. It activates on the 23rd of October. At this date it encrypts accessed Word documents with a random password.
It also might insert the following texts to documents:
NAENBGOURSG Hello from GREECE.
On 24th of October the virus creates a file called PCGURU4.BAT to the current directory. This file contains the following lines:
@echo off Rem PcGuru4 virus by NAENBGOURSG Rem Golden Version 4.3 type PcGuru4.bat >> PcGuru4.bat The virus also contains the following text: 'by NAENBGOURSG 'SO.HT.AI.KS '231076 -- GREECE 'VRD 23-4-1997 'VRP A.U.A
Based on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the detected program or file, or ask you for a desired action.
Find the latest advice in our Community Knowledge Base.
See the manual for your F-Secure product on the Help Center.
Submit a file or URL for further analysis.