0 0
This is a harmless memory resident parasitic Win32 virus. It stays in Windows memory as a hidden application (service process), and in the background permanently scans the current directory and infects PE EXE files in there. When the current directory changes, the virus switches to it and infects files in the new directory. While infecting a file, the virus writes itself to the end of the file.
The virus intends to create its infected "dropper" (the "Greenpeace.exe" file) in the Windows system directory and register it in the auto-run section in the system registry, but fails because of a bug.
The virus does not manifest itself in any way.

Subscribe
Hot Articles