Date Discovered: 2/12/2004
Date Added: 2/12/2004
Origin: Unknown
Length: 17,847 Bytes
Type: Virus
SubType: VbScript
This threat is detected as VBS/Lucave. This VBScript virus code contains errors and some payloads will not be executed. The virus code is encrypted and on executing the infected script, the virus will copy itself to the hard coded directory: c:\windows\alias.jpg.vbs . It will also copy itself to random network drives as [random character]alias.jpg.vbs. Example Falias.jpg.vbs. The virus also attempts to copy itself to random IP sites.
The following registry key will be added:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Gnsys" = C:\windows\alias.jpg.vbs
VBS/Lucave contains mass mailing capabilities, IRC propagation and also utilizing the Windows Management Instrumentation (WMI), but this is not executed due to the error in the virus code.
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101017

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic