[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [New Search]

[T3] READ THIS.


I just want to warn you about a REAL virus.  Please forward the information
to everyone yo0éî This is a very serious virus.

Check out www.zdnet.com if you don't believe it.  Text follows:

the worm e-mails itself out as an attachment with the file name
"zipped_files.exe." The body of the e-mail message hides within an e-mail
correspondence.

How it works
When a user sends an e-mail to an infected desktop, he or she will receive a
response that contains the virus payload. The message header will appear the
same but the text inside will be changed. It will say:

"Hi (Recipient Name)!

I received your email and I shall send you a reply ASAP.

Till then, take a look at the attached zipped docs.

Bye"

Once the attachment is executed, a computer will likely display a fake error
message. The worm then copies itself to the C:\WINDOWS\SYSTEM directory with
the file-name "Explore.exe" and then modifies the WIN.INI file so the
program is executed each time Windows is started.

When it is executed, the worm searches drives C: through Z: of a computer
and selects a series of files to destroy based on file extensions (including
.h, .c, .cpp, .asm, .doc, .xls, .ppt) by making them zero bytes long --
wiping out data.

To get rid of the worm, Symantec advises users to remove the line
run=C:\WINDOWS\SYSTEM\Explore.exe from the WIN.INI file and delete the file
"C:\WINDOWS\SYSTEM\EXPLORE.EXE." If the file is in use, users may need to
reboot first.

Both Symantec and Network Associates have posted anti-virus updates on their
home pages to deal with the new worm.




-------------------------------------------------------------------
Search old messages on the Web!  Visit http://www.vwtype3.org/list/


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [New Search]