Threat Description

Joke.Win32.Russ

Details

Category: Malware
Platform: W32
Aliases: Joke.Win32.Jep, Virus game, Russ, Jep, Jep/Russ

Summary


This is not a virus but a joke program written with Delphi.

Joke.Win32.Russ advertises a 3D action computer game called "VIRUS". It does this in a very strange manner - imitating all folders deletion from a hard disk. This is why it is detected - to prevent shocking of computer users.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details


When the program is executed it opens a small window with a yellow smiling face icon and a message:

Please Wait. Initializing...  

Then the Explorer window is opened viewing Windows 95 root folder. Immediately the 'Confirm Folder Delete' dialog is showed asking:

Are you sure you want to delete 'Win95' folder         and all its contents ?  

There's no way the "No" button can be pressed as mouse cursor evades it. After several seconds the joke imitates deletion of Windows 95 folder and then all the rest folders on drive C: are "deleted".

In the end the joke opens the 'Shutdows Windows' dialog with grayed 'No' button, 'Restart the computer?' and 'Close and log as a different user?' options. Shortly after that the computer is 'restarted', the screen goes blank.

After a few seconds the following message is printed in big green letters one by one:

Thank god this is only a game...  

Finally a new 3-D computer game advertisment is shown as two pictures containing its description and distributors addresses. After pressing a key the joke passes control to the system.

We recommend that this joke is deleted instead of passing it around.





Technical Details:Alexey Podrezov, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More