Threat Description

Sylvia

Details

Aliases:Sylvia, Holland Girl
Category:Malware
Type:Virus
Platform: W32

Summary



This virus is a bit unusual, to say the least. It contains the following message:

This
  program
is
  infected
 by
a
 HARMLESS
Text-Virus V2.1
 Send a FUNNY postcard to : Sylvia Verkade,
 Duinzoom 36b,
 3235 CD Rockanje
 The Netherlands.
 You might get an ANTIVIRUS program.....

It will display this message when an infected program is executed, but if the above text is tampered with, the following message, (which is stored in an encrypted form) will appear instead:

FUCK YOU LAMER !!!!
system halted...$

Some people have a weird sense of humor...



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Two versions are known, only slightly different - possibly modified to avoid some anti-virus program. When an infected program is run, the virus will seek out up to 5 .COM files to infect. It will search drive C: and the current drive. The three system files, COMMAND.COM, IBMBIO.COM and IBMDOS.COM are not infected. The virus adds 1301 bytes to the beginning of the files it infects (and also 31 bytes to the end), but does no other damage. The girl mentioned above exists, but she says that she has no idea who the author is, although there is a rumor he is her ex-boyfriend.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More