| Description:
|
Details
Win32.Intar
It is not a dangerous nonmemory resident parasitic encrypted Win32 virus. It searches for PE EXE files in subdirectories on current drive, then writes itself to the end of the file.
The virus does not manifest itself in any way except "log" records in WIN.INI file: the virus creates [Temp] section in there and writes to there "Saved=" key with the name of latest infected file, for example:
[Temp]
Saved=C:WINDOWSNOTEPAD.EXE
The virus contains the text string:
[Win9x.Integrator] by Gobleen Warrior//SMF
People can flyall Everything can happen... |