Jump to content
IndiaDivine.org

Virus Alert !!!

Rate this topic


Guest guest

Recommended Posts

Guest guest

Few simple precautions may be very helpful ...

 

<html>

<head>

<meta http-equiv= " Content-Type " content= " text/html;

charset=iso-8859-1 " >

<meta name= " GENERATOR " content= " Mozilla/4.72 [en] (X11; U; Linux

2.2.14 i686) [Netscape] " >

<title>Exploits and Hoaxes</title>

</head>

<body text= " #000000 " bgcolor= " #FFFFFF " link= " #0033CC " vlink= " #00639C "

alink= " #47A959 " background= " blackfade.gif " MARGINHEIGHT= " 0 "

MARGINWIDTH= " 0 " TOPMARGIN= " 3 " LEFTMARGIN= " 0 " >

& nbsp;

<table BORDER=0 CELLSPACING=0 CELLPADDING=0 NOSAVE >

<tr ALIGN=LEFT VALIGN=TOP NOSAVE>

<td ALIGN=LEFT VALIGN=TOP WIDTH= " 100 " BGCOLOR= " #000000 " NOSAVE></td>

 

<td WIDTH= " 6 " > & nbsp;</td>

 

<td ALIGN=LEFT VALIGN=TOP ROWSPAN= " 2 " WIDTH= " 100% " >

<center><table CELLSPACING=5 COLS=1 WIDTH= " 98% " BGCOLOR= " #FFFFFF " >

<tr>

<td><b><font color= " #000000 " >05-18-2000</font></b>

<br><font color= " #FF6666 " >VBS/NewLove-A</font> is a Visual Basic

Script

virus

<br>that mutates its appearance in an attempt to avoid detection by

<br>anti-virus products.

<p>If you are infected by the virus it will do the following:

<p>The virus chooses a random filename and attempts to forward a

<br>mutated version of itself to everybody in your Microsoft Outlook

<br>address book. & nbsp; The name of the file it forwards is determined

by

<br>randomly choosing one of the filenames in your Windows\Recent

<br>folder, appended with " .Vbs " & nbsp; (for instance, EXPENSES.XLS

becomes

<br>EXPENSES.XLS.Vbs).

<br>The message has the subject line: " FW: & lt;filename> " where

filename

<br>is the name of the file it is forwarding, with the extension

<br> " .Vbs " removed. & nbsp; So, if the attached infected file is

<br>README.DOC.Vbs then the subject line will be " FW: README.DOC " .

<br><a

href= " http://www.virusbtn.com/VirusInformation/newlove.html " >MORE

INFORMATION</a>

<p><b>05-17-2000 </b>(discovered in the wild).

<br><font color= " #FF6666 " >W32/SouthPark-A</font> is an email-aware

worm

that uses

<br> & nbsp;Microsoft Outlook to spread itself as an email message

<br>attachment. The subject of the message is " Servus Alter " . & nbsp;

<br>The message body contains the text " Hier ist das Spiel,

<br> & nbsp;das du unbedingt wolltest! :-) " . The attached file name is

<br> " South Park.exe " .

<p><b>05-04-2000</b>

<br><font color= " #FF0000 " >LoveLetter, aka Love Bug

( " ILOVEYOU " ) & nbsp;</font>

<br>10's of thousands of E-Mail servers were shutdown, millions of

users

were

<br>affected, and the Financial damage is estimated to exceed 7

Billion.

<br>The IPRG network reacted to this threat as a non-event.

<p><b>04-01-2000</b>

<br><font color= " #FF0000 " >911 virus</font>

<br>At 8:00 am on Saturday, April 1 (This is not an April Fool's

joke!)

<br>the FBI announced it had discovered malicious code wiping out the

data

on

<br>hard drives and dialing 911. & nbsp; This is a vicious virus and

needs

to

<br>be stopped quickly. That can only be done through wide-scale & nbsp;

<br>individual action. & nbsp;

<p>The FBI Advisory is posted at <a

href= " http://www.nipc.gov/nipc/advis00-038.htm " >ht

tp://www.nipc.gov/nipc/advis00-038.htm</a>

<p><b>03-27-2000</b>

<br><font size=-1><font color= " #CC0000 " >Irok-10000 </font>spreads by

infecting

files, emailing itself and</font>

<br><font size=-1>propagating over Internet Relay Chat (IRC). The

virus</font>

<br><font size=-1>creates a copy of itself named irok.exe in the

Windows

System</font>

<br><font size=-1>directory and a VBScript file named irokrun.vbs in

the</font>

<br><font size=-1>Programs\Startup program group. This script is used

to

email the</font>

<br><font size=-1>virus to the first 60 entries in your Outlook

address

book.</font>

<br><font size=-1>The subject of the email sent by the virus is " I

thought

you</font>

<br><font size=-1>might like to see this. " </font>

<br><font size=-1>The body of the message is " I thought you might like

this. I got</font>

<br><font size=-1>it from paramount pictures website. It's a startrek

screen</font>

<br><font size=-1>saver. " </font>

<br><font size=-1>The virus is attached to the mail as a file named

Irok.exe.</font>

<br><font size=-1>When the file is run it will display white dots

moving

across</font>

<br><font size=-1>the screen. If mIRC is installed it will also create

a</font>

<br><font size=-1>script.ini file in the mIRC & nbsp; directory.</font>

<p><b>03-15-2000</b>

<br><font size=-1>A prank e-mail is spreading currently around Europe.

Our & nbsp;</font>

<br><font size=-1>customer services have already received several

calls & nbsp;</font>

<br><font size=-1>regarding it and it is likely that the e-mail will

be & nbsp;</font>

<br><font size=-1>forwarded further.</font><font size=-1></font>

<p>[This is a chain e-mail stating that Nokia is handing out

<br>free phones to people who forward this this e-mail.] & nbsp;

<p><b>03-14-2000</b>

<br><font size=-1>We have been warned about a new computer virus

called

<font color= " #CC0000 " >Melting

Screen Worm</font></font>

<br><font size=-1>(alias W32.Melting.Worm).</font>

<br><font size=-1>This worm sends e-mails with an infected attachment

called</font>

<br><font size=-1> " MeltingScreen.exe " with a subject " Fantastic

Screensaver " .</font>

<br><font size=-1>The message body is:</font>

<br><font size=-1> " Hello my friend! Attached is my newest and funniest

Screensaver, Inamed it</font>

<br><font size=-1>MeltingScreen. Test it and tell me what you think.

Have

a nice day my</font>

<br><font size=-1>friend.</font>

<br><font size=-1>p.s.: Please install the Runtime Library for VB5.0,

before

you run the</font>

<br><font size=-1>ScreenSaver. " </font>

<br><font size=-1>This worm renames all EXEs in the Windows directory

to

BIN. It has a screen</font>

<br><font size=-1>saver that indeed 'melts the screen'.</font></td>

</tr>

</table></center>

</td>

 

<td WIDTH= " 6 " > & nbsp;</td>

 

<td ROWSPAN= " 3 " NOSAVE><font color= " #000000 " > & nbsp;</font></td>

</tr>

 

<tr NOSAVE>

<td VALIGN=TOP BGCOLOR= " #000000 " NOBRK>

<center><b><font color= " #FFFFFF " > & nbsp;<font

face= " Arial,Helvetica " ><font size=-1>Proactive

Virus Detection Gateway</font></font></font></b></center>

 

<p><br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<br>

<p> & nbsp;</td>

</tr>

</table>

 

</body>

</html>

Link to comment
Share on other sites

Join the conversation

You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...