This virus is a remake of original Winsurf virus. It uses the same algorithms and have the same bugs. It has one bug more - it infects a file that is pointed by "load=" instruction in WIN.INI file, but fails to parse file name and infect a file starting from second letter in its name (instead of ABCD.EXE the virus tries to infect BCD.EXE).
This virus has the following text string:
Skim.Poppy.II by VicodinES
oad=indir=win.ini