| |||
|
Here's a freebie from me! I'm an IT professional and just recently was notified of a virus. Consider this a free consultation. ![]() Don't open any email about a new flash movie, and especially don't open the creative.exe attachment! This Internet worm may be received via email in this form: Subject = A great Shockwave flash movie Body = Check out this new flash movie that I downloaded just now ... It's Great Attachment = creative.exe When run, this Internet worm will write a copy of itself to the local system and then send a copy of itself via MAPI email to all users in the address book. As a final note, it sends a note to presumably the author: Author = z14xym432@yahoo.com Subject = Job complete Body = Got yet another idiot Official info: [Only registered and activated users can see links. Either login above or Register Now] Method Of Infection After running the file CREATIVE.EXE, it will seek files of .JPG and .ZIP on the local machine. If any are found, this file is moved to the root of C: with this additional suffix at the end "change atleast now to LINUX". Example: "c:\Notebook.jpgchange at least now to LINUX" A helpful note about this action however, this Internet worm logs the changes to a file named "c:\messageforu.txt". Within this file is the following text: Hi, guess you have got the message. I have kept a list of files that I have infected under this. If you are smart enough just reverse back the process. i could have done far better damage, i could have even completely wiped your harddisk. Remember this is a warning & get it sound and clear... - The Penguin --------------------> For those of you not familiar with Linux, it is another operating system, as Windows is an operating system. The mascot is a penguin. Since the file name changes to "at least now to Linux" and the sender is "The Penguin" I believe this to be an avid Linux fan. (which I am too) But I personally think it's a foreigner because the English is kind of strange. Unless it was a non-foreigner that is pretending to be a foreigner, ha ha! |
| | ||||
| ||||
| |
![]() |
| Thread Tools | |
| Display Modes | |
| |