This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
|
Minimum DAT
4187 (2002-02-20) Updated DAT4813 (2006-07-24) |
Minimum Engine
5.1.00 File Length12,288 bytes |
Description Added
2002-02-19 Description Modified2002-02-26 |
This is a multifaceted worm. It contains many components and uses different methods to carry out its payloads. This virus was sent to many anti-virus vendors by the virus author. It is not in the wild.
It arrives in an email message containing the following information:
Subject: sounds of sex and other stuffsAttachments: sexsounds.wav (SexSound.exe)
and haiku for you (readme.txt)
and http://www.EcstasyRUs.com (www.EcstasyRUs.com)
and the cool talking screensaver (syra.scr)
Except for the haiku text file, the attachments are all identical copies of the same worm with a different filename. The haiku text file reads as follows:
A Collection of Haiku ------------------ Dried marijuana... And my grandfather's old pipe... Tears in my red eyes... ------------------ Condoms in the bag... A lustful stare from your eyes... In the girl's rest room... ------------------When any of the other attachments are run, this worm infects the local system by performing the following functions:
This worm arrives as an email attachment or via Internet Relay Chat. Once run on the local system documents and applications are overwritten. Such files cannot be repaired. They must be deleted and restored from backup.
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: