»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 04-26-2004, 11:12 AM   #1 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
new virus or worm? (MoreInfo.CPL)

Quote:
Hello username
I'm a young lady of 20 years old i'd like to find my second part!!!

Attached file will tell you everything.

Sincerely, Annie
Then attached are two files.

image12.jpeg and MoreInfo.CPL

The jpeg is really a picture file. BUt I don't understand the CPL file yet. Normally CPL files are Control Panels related files but I don't know what damage may happen from this. CPLs are not "executable" as is (in W2K anyway).

I'm guessing it's a bad attempt of making another worm/virus. Anyone have more info?

DVNT1 is offline   Reply With Quote
Old 04-26-2004, 11:31 AM   #2 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Seeing more email messages like this but now as JPEG and HTA files.

I know HTA files can be ran via IE and this particular one gets information from your computer (using VB script) and sends it out.

Bad stuff for sure.
DVNT1 is offline   Reply With Quote
Old 04-28-2004, 09:32 PM   #3 (permalink)
Registered User
 
Join Date: Apr 2004
Location: South Carolina
Posts: 2
soundgirl is on a distinguished road
I received one of those today, from Luckycharmsjj@conwaycor.net. I didn't open the message; instead, I deleted it, but how dangerous is this .cpl file (in laymen's terms, please!)?
soundgirl is offline   Reply With Quote
Old 04-28-2004, 09:33 PM   #4 (permalink)
Registered User
 
ArcticFox's Avatar
 
Join Date: Jan 2003
Location: Wilsonville, OR
Posts: 2,220
ArcticFox is on a distinguished road
Send a message via AIM to ArcticFox Send a message via MSN to ArcticFox Send a message via Yahoo to ArcticFox Send a message via Skype™ to ArcticFox
Can I have that picture?

Post 1969 - I feel so....high! As high as the moon...
ArcticFox is offline   Reply With Quote
Old 04-29-2004, 06:09 AM   #5 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
In the samples I've seen, the CPL file is only being used as an executable dropper. This is normally being done with an accompaning script (like pif, html, scr, com, exe) in the email.

My first email with the CPL file did not have an accompanying script or execuatable. But all others since then have had it.
DVNT1 is offline   Reply With Quote
Old 04-29-2004, 02:11 PM   #6 (permalink)
Registered User
 
Join Date: Apr 2004
Location: South Carolina
Posts: 2
soundgirl is on a distinguished road
I received another e-mail from the same sender but with a .com attachment this time. I don't know enough about decoding, or I would check this one out. Do you want to take a look at it and the other one? Or should I just delete them?
soundgirl is offline   Reply With Quote
Old 04-29-2004, 02:19 PM   #7 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
just delete them
DVNT1 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 07:07 PM.