View Full Version : VIRUS ALERT.
AquaMan
02-12-2001, 10:56 AM
LAST EDITED ON Feb-12-01 AT 12:58PM (CST)[p]Our offices have been bombarded today with cutomers openning e-mails with the following title:
"Here it is"
"Check this out"
"Pretty Park"
"Anna Cornacova.Jpg" (SP)
These will collect your e-mail addresses and rebrodcast this virus to them. Once that is done the virus will wipe your hard drive of ALL data.
Norton, Mcfee and MS Anti Virus DO NOT have the fix as of today, so BE CAREFULL.
It is spreading with alarming speed and could appear on your system without warning.
AquaMan~~~~~~~~~~~~~
--- "It all begins and ends at the water's edge"
TBO/MN
02-12-2001, 11:26 AM
Just got the same warning over my internal network. Must be the real thing.........
Be careful out there....
Good Fishin'
TBO/MN
T.Ryan
02-12-2001, 01:03 PM
It made it past our virus protection and has hit our entire network. All sites ( 8 ) are now shut down waiting for the fix! I sit right next to our email admin and all she can do is hope the fix comes out soon. The cost for these things just gets high every minute we sit here.
Tim R.
George Eh
02-12-2001, 01:16 PM
Thanks guys, I got caught with the last virus, wasn't paying attention when opening the email and paid the price. I'll be on the alert for it now. Can't wait for spring to wet a line, I haven't done any ice fishing as I have being working for the better half, painting and a little renovating in the house. Better now than in warm weather, here's looking forward to open water.
T-Mac
02-12-2001, 04:30 PM
Thats that "Honey-Do" virus, George, eh?
Jeremy(WI)
02-12-2001, 04:36 PM
The latest norton antivirus definitions, includes this virus, got some downloading to do.
KevinA
02-12-2001, 05:26 PM
Here's the technical scoop:
+++++++++++++++++++++++++
VBS.SST is a VBS email worm that has been encoded with a virus creation kit. The worm arrives as an attachment named AnnaKournikova.jpg.vbs When executed the worm emails itself to everyone in your address book. On January 26, the worm will attempt to spawn the web browser to an Internet address. This worm appears to have originated in the Netherlands
When run the virus creates the registry key
HKCU/Software/OnTheFly/
If the day is January 26, the virus attempts to spawn the Web browser.
Next, the virus checks to see if the mass-mailing routine has been executed. If not, the worm emails everyone in the Outlook address book and creates the registry key HKCU/Software/OnTheFly/mailed
So, the worm does not email every address again. The worm sends the message with the subject
Here you have, ;o)
The message body
Hi:
Check This!
and the attachment AnnaKournikova.jpg.vbs
The worm then remains running and if it is deleted attempts to recreate itself. Due to a bug in the code, the virus instead recreates itself as a zero-byte file.
Removal Instructions:
Delete all found infections. If exists, delete the zero-byte file.
Remove registry keys
Hard liner
02-12-2001, 09:08 PM
I say we nuke the Netherlands.
George Eh
02-12-2001, 10:15 PM
Thats the truth T-Mac and the only way to eradicate the virus is to say 'yes dear' until my work is done. I must confess though I have been slipping down to the basement and getting my fishing equipment ready for the spring opener, have a good day everyone.