| Description:
|
Details
Win.Tentacle.1958
It is not a dangerous nonmemory resident parasitic virus. It searches for NewEXE-files in current and C:WINDOWS directories, then writes itself to the end of the file. While infecting the virus creates temporary C:TENTACLE.$$$ file, then modifies and copies blocks of original file to temporary one, then copies temporary file to original one, and then deletes temporary file.
From 0:0am till 0:15am the virus checks the just infected file for the Resources, and searches for Icon resource. If such Resource is there, the virus overwrites it with another icon which is contained in the virus body.
The virus contains the internal text string:
C:TENTACLE.$$$ C:WINDOWS*.EXE |