|
Haven’t
seen anything at all from NAI – have you? Steve Clark Clark Systems Support, LLC AVIEN Charter Member “Who's watching your network?” www.clarksupport.com 301-610-9584
voice 240-465-0323
Efax -----Original
Message----- Trend has a def file for
it. 945 It isn't available via
automatic DL yet, but you can DL the ZIP file and manually put it in. -----Original Message----- Subject of email: Fwd:Peace BeTweeN
AmeriCa and IsLaM! Symantec Security Response W32.Vote.A@mm is a mass-mailing worm that
is written in Visual Basic. When executed, it will email itself out to all
email addresses in the Microsoft Outlook address book. The worm will insert two
.vbs files on the system, and it will also attempt to delete files from several
antivirus products. Type: Worm Infection Length: 55,808 Bytes Virus Definitions: September 24, 2001 Threat Assessment: Wild: Number of infections: 0 - 49 Payload: Distribution: Subject of email: Fwd:Peace BeTweeN
AmeriCa and IsLaM! Technical description: W32.Vote.A@mm is a mass-mailing worm
written in the Visual Basic language. It requires the file Msvbvm50.dll to
execute. When executed, the worm will attempt to
email itself to all contacts in the Microsoft Outlook address book. The email
will appear as follows. Subject: Fwd:Peace BeTweeN AmeriCa and
IsLaM! Message: Attachment: WTC.EXE Next, the worm will insert two .vbs files
on the system: \<Windows folder>\ZaCker.vbs In addition, the worm will attempt to
download and execute a file. This file is detected as Backdoor.Trojan by Norton
Antivirus. Finally, the worm will attempt to delete
all files from several folders. These folders appear to be the default
installation folders for several antivirus products. For Norton AntiVirus, this
worm will only attempt to delete the files if Norton Antivirus is located in
C:\Program Files\Norton AntiVirus. What the dropped files do MixDaLaL.vbs AmeRiCa ...Few Days WiLL Show You What We
Can Do !!! It's Our Turn >>> ZaCkEr is So Sorry For You ZaCker.VBS Norton.Thar \Windows\System\ZaCker.vbs is added to the registry key HKEY_LOCAL_MACHINE\Microsoft\ so that the file is executed when you
start Windows. When executed at the next restart, this
file will attempt to delete all files in the \Windows folder. Next, the worm
will create or overwrite the file C:\Autoexec.bat. Inside the file there will
be a command that formats the C drive. The Autoexec.bat file is executed on
Windows 95/98/Me and DOS systems when you start the computer. Finally, the worm will displays the
message The worm does attempt to shut down Windows
after the message has been displayed. However, because the files required for
this event to occur have been deleted from the \Windows folder, the computer
probably will not shut down. Removal instructions: 1. Run LiveUpdate to make sure that you
have the most recent virus definitions. 3. Run a full system scan. 5. If the computer has been rebooted after
the infection, or if the computer seems very unstable, it is recommended that
you reinstall the operating system. Additional information: If the Backdoor.Trojan was successfully
installed on the computer, it is possible that your system has been accessed
remotely by an unauthorized user. For this reason it is impossible to guarantee
the integrity of a system that has had such an infection. The remote user could
have made changes to your system, including but not limited to the following: Stealing or changing passwords or password
files If you need to be certain that your
organization is secure, you must reinstall the operating system, and restore
files from a backup that was made before the infection took place, and change
all passwords that may have been on the infected computers or that were
accessible from it. This is the only way to ensure that your systems are safe.
For more information regarding security in your organization, contact your
system administrator. Write-up by: Neal Hindocha
Ray Zorz http://www.sunbelt-software.com/ntsysadmin_list_charter.htm http://www.sunbelt-software.com/ntsysadmin_list_charter.htm |
Title: Message
- Another F(*&^ virus! RZorz
- RE: Another F(*&^ virus! Danny Iaconetti
- RE: Another F(*&^ virus! Martin Blackstone
- RE: Another F(*&^ virus! Clark, Steve
- RE: Another F(*&^ virus! Danny Iaconetti
- RE: Another F(*&^ virus! Allan Muchmore
- RE: Another F(*&^ virus! Gisler, Johnny
- Re: Another F(*&^ virus! Richard Jones
- RE: Another F(*&^ virus! RZorz
- RE: Another F(*&^ virus! Lagerstrom, Lanette
- RE: Another F(*&^ virus! RZorz
