Guest guest Posted May 20, 2000 Report Share Posted May 20, 2000 Few simple precautions may be very helpful ... <html> <head> <meta http-equiv= " Content-Type " content= " text/html; charset=iso-8859-1 " > <meta name= " GENERATOR " content= " Mozilla/4.72 [en] (X11; U; Linux 2.2.14 i686) [Netscape] " > <title>Exploits and Hoaxes</title> </head> <body text= " #000000 " bgcolor= " #FFFFFF " link= " #0033CC " vlink= " #00639C " alink= " #47A959 " background= " blackfade.gif " MARGINHEIGHT= " 0 " MARGINWIDTH= " 0 " TOPMARGIN= " 3 " LEFTMARGIN= " 0 " > & nbsp; <table BORDER=0 CELLSPACING=0 CELLPADDING=0 NOSAVE > <tr ALIGN=LEFT VALIGN=TOP NOSAVE> <td ALIGN=LEFT VALIGN=TOP WIDTH= " 100 " BGCOLOR= " #000000 " NOSAVE></td> <td WIDTH= " 6 " > & nbsp;</td> <td ALIGN=LEFT VALIGN=TOP ROWSPAN= " 2 " WIDTH= " 100% " > <center><table CELLSPACING=5 COLS=1 WIDTH= " 98% " BGCOLOR= " #FFFFFF " > <tr> <td><b><font color= " #000000 " >05-18-2000</font></b> <br><font color= " #FF6666 " >VBS/NewLove-A</font> is a Visual Basic Script virus <br>that mutates its appearance in an attempt to avoid detection by <br>anti-virus products. <p>If you are infected by the virus it will do the following: <p>The virus chooses a random filename and attempts to forward a <br>mutated version of itself to everybody in your Microsoft Outlook <br>address book. & nbsp; The name of the file it forwards is determined by <br>randomly choosing one of the filenames in your Windows\Recent <br>folder, appended with " .Vbs " & nbsp; (for instance, EXPENSES.XLS becomes <br>EXPENSES.XLS.Vbs). <br>The message has the subject line: " FW: & lt;filename> " where filename <br>is the name of the file it is forwarding, with the extension <br> " .Vbs " removed. & nbsp; So, if the attached infected file is <br>README.DOC.Vbs then the subject line will be " FW: README.DOC " . <br><a href= " http://www.virusbtn.com/VirusInformation/newlove.html " >MORE INFORMATION</a> <p><b>05-17-2000 </b>(discovered in the wild). <br><font color= " #FF6666 " >W32/SouthPark-A</font> is an email-aware worm that uses <br> & nbsp;Microsoft Outlook to spread itself as an email message <br>attachment. The subject of the message is " Servus Alter " . & nbsp; <br>The message body contains the text " Hier ist das Spiel, <br> & nbsp;das du unbedingt wolltest! :-) " . The attached file name is <br> " South Park.exe " . <p><b>05-04-2000</b> <br><font color= " #FF0000 " >LoveLetter, aka Love Bug ( " ILOVEYOU " ) & nbsp;</font> <br>10's of thousands of E-Mail servers were shutdown, millions of users were <br>affected, and the Financial damage is estimated to exceed 7 Billion. <br>The IPRG network reacted to this threat as a non-event. <p><b>04-01-2000</b> <br><font color= " #FF0000 " >911 virus</font> <br>At 8:00 am on Saturday, April 1 (This is not an April Fool's joke!) <br>the FBI announced it had discovered malicious code wiping out the data on <br>hard drives and dialing 911. & nbsp; This is a vicious virus and needs to <br>be stopped quickly. That can only be done through wide-scale & nbsp; <br>individual action. & nbsp; <p>The FBI Advisory is posted at <a href= " http://www.nipc.gov/nipc/advis00-038.htm " >ht tp://www.nipc.gov/nipc/advis00-038.htm</a> <p><b>03-27-2000</b> <br><font size=-1><font color= " #CC0000 " >Irok-10000 </font>spreads by infecting files, emailing itself and</font> <br><font size=-1>propagating over Internet Relay Chat (IRC). The virus</font> <br><font size=-1>creates a copy of itself named irok.exe in the Windows System</font> <br><font size=-1>directory and a VBScript file named irokrun.vbs in the</font> <br><font size=-1>Programs\Startup program group. This script is used to email the</font> <br><font size=-1>virus to the first 60 entries in your Outlook address book.</font> <br><font size=-1>The subject of the email sent by the virus is " I thought you</font> <br><font size=-1>might like to see this. " </font> <br><font size=-1>The body of the message is " I thought you might like this. I got</font> <br><font size=-1>it from paramount pictures website. It's a startrek screen</font> <br><font size=-1>saver. " </font> <br><font size=-1>The virus is attached to the mail as a file named Irok.exe.</font> <br><font size=-1>When the file is run it will display white dots moving across</font> <br><font size=-1>the screen. If mIRC is installed it will also create a</font> <br><font size=-1>script.ini file in the mIRC & nbsp; directory.</font> <p><b>03-15-2000</b> <br><font size=-1>A prank e-mail is spreading currently around Europe. Our & nbsp;</font> <br><font size=-1>customer services have already received several calls & nbsp;</font> <br><font size=-1>regarding it and it is likely that the e-mail will be & nbsp;</font> <br><font size=-1>forwarded further.</font><font size=-1></font> <p>[This is a chain e-mail stating that Nokia is handing out <br>free phones to people who forward this this e-mail.] & nbsp; <p><b>03-14-2000</b> <br><font size=-1>We have been warned about a new computer virus called <font color= " #CC0000 " >Melting Screen Worm</font></font> <br><font size=-1>(alias W32.Melting.Worm).</font> <br><font size=-1>This worm sends e-mails with an infected attachment called</font> <br><font size=-1> " MeltingScreen.exe " with a subject " Fantastic Screensaver " .</font> <br><font size=-1>The message body is:</font> <br><font size=-1> " Hello my friend! Attached is my newest and funniest Screensaver, Inamed it</font> <br><font size=-1>MeltingScreen. Test it and tell me what you think. Have a nice day my</font> <br><font size=-1>friend.</font> <br><font size=-1>p.s.: Please install the Runtime Library for VB5.0, before you run the</font> <br><font size=-1>ScreenSaver. " </font> <br><font size=-1>This worm renames all EXEs in the Windows directory to BIN. It has a screen</font> <br><font size=-1>saver that indeed 'melts the screen'.</font></td> </tr> </table></center> </td> <td WIDTH= " 6 " > & nbsp;</td> <td ROWSPAN= " 3 " NOSAVE><font color= " #000000 " > & nbsp;</font></td> </tr> <tr NOSAVE> <td VALIGN=TOP BGCOLOR= " #000000 " NOBRK> <center><b><font color= " #FFFFFF " > & nbsp;<font face= " Arial,Helvetica " ><font size=-1>Proactive Virus Detection Gateway</font></font></font></b></center> <p><br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <p> & nbsp;</td> </tr> </table> </body> </html> Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.