»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Off Topic Community

Reply
 
LinkBack Thread Tools Display Modes
Old 12-04-2001, 10:59 AM   #11 (permalink)
Registered User
 
Toadman's Avatar
 
Join Date: Oct 2001
Location: Southern California
Posts: 820
Toadman is on a distinguished road
Send a message via ICQ to Toadman
Watch out 4 the screensaver virus tho..

Be careful with e-mailed holiday screensavers, peeps. A nasty little worm is working it's way around and wreaking havoc today.

WORM_GONE.A

In the wild: Yes
Payload 1: Displays Message
Trigger condition 1: Upon execution
Discovered: 1 hour 59 minutes ago
(December 4, 2001 6:40:00 AM GMT -0800)
Language: English
Platform: Windows
Encrypted: No
Size of virus: 38,912 Bytes

Details:
This worm arrives via email as the attachment GONE.SCR. The file is packed using the UPX packer program and is compiled using Visual Basic.

The email details in which this Worm arrives are as follows:

Subject: Hi
Message Body: How are you ?
When I saw this screensaver, I immediately thought about you
I am in a harry, I promise you will love it!
Attachment: GONE.SCR

When executed, it displays a window containing the following:

pentagone

coded by: suid

texted by: ThE_SKuLL and |satan|
greetings to: TraceWar. k9_unit, stef16 ^Reno

greetings also to nonick2 out
there where ever you are

It then copies the worm file to a %System%\GONE.SCR file. It creates the following registry key to auto-execute the copy file
everytime Windows is restarted:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
entVersion\Run\%System%\gone.scr = %System%\gone.scr

It also uses the mIRC application to install a backdoor. It creates
a REMOTE.INI file, which contains a script that loads everytime
the mIRC application is started.

Toadman is offline   Reply With Quote
Old 12-04-2001, 11:03 AM   #12 (permalink)
shahani
Guest
 
Posts: n/a
I got an email exactly like that. How do I clean the virus? The sender was a person I know but he didn't send it.
  Reply With Quote
Old 12-04-2001, 11:48 AM   #13 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Uh, Oregon . . . . y
Posts: 1,441
sharder8 is on a distinguished road
Send a message via ICQ to sharder8
Try going to Free House Call for a free On-line virus scan from Trend.

Harder

P.S. Surreal - I will e-mail it when I get off work, and it will be virus free leaving my computer. Harder
sharder8 is offline   Reply With Quote
Old 12-04-2001, 11:52 AM   #14 (permalink)
shahani
Guest
 
Posts: n/a
Harder: many Thanx.
  Reply With Quote
Old 12-04-2001, 11:55 AM   #15 (permalink)
Registered User
 
korgul's Avatar
 
Join Date: Oct 2001
Location: York, PA.
Posts: 1,326
korgul is on a distinguished road
I read the about the virus here and 10 min later we got it here at work. Thanks for the heads up

korgul
korgul is offline   Reply With Quote
Old 12-04-2001, 12:09 PM   #16 (permalink)
Registered User
 
Toadman's Avatar
 
Join Date: Oct 2001
Location: Southern California
Posts: 820
Toadman is on a distinguished road
Send a message via ICQ to Toadman
Wow.. now classified as an outbreak like the Love Letter virus was. McAfee and Symantec have a patch out at least.
Toadman is offline   Reply With Quote
Old 12-04-2001, 01:40 PM   #17 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Uh, Oregon . . . . y
Posts: 1,441
sharder8 is on a distinguished road
Send a message via ICQ to sharder8
As does Trend's PC-cillin 2000. When I went on-line at 0730, my PC-cillin automatically checked and installed the new def. file for it.

Harder
sharder8 is offline   Reply With Quote
Old 12-04-2001, 01:50 PM   #18 (permalink)
shahani
Guest
 
Posts: n/a
I got mine cleaned with the free online check at trend. I think I will switch from NAV to PC-Cillin.
  Reply With Quote
Old 12-04-2001, 07:12 PM   #19 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Uh, Oregon . . . . y
Posts: 1,441
sharder8 is on a distinguished road
Send a message via ICQ to sharder8
shahani --

Ya' can buy it for $19.99 at Staples. It's their Anti-Virus Protection Plan (PC-cillin 2000). Otherwise, it'll cost ya' $29.99 to download.

If they ask who turned you on to it, tell them Techimo! (I could give you my employee number for credit, but I still, and probably always will, owe the people of Techimo! )

Harder
sharder8 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 12:44 AM.