SV: New worm behavior ?

From: Peter Kruse (peter.kruseat_private)
Date: Tue Sep 18 2001 - 12:28:30 PDT

  • Next message: Christian Hampson: "RE: New "concept" virus/worm?"

    Hi Owen,
    
    It will drop a hidden file called load.exe to the windows system folder and
    modify system.ini so this file will run upon reboot.
    
    Med venlig hilsen / Best regards
    
    Peter Kruse
    Security- and virusresearch
    Telia Telecom / Telia Security Group
    Søren Frichsvej 34C - DK 8230 Åbyhøj
    Email: pkrat_private - Mobil: +45 2827 9785
    
    
    > -----Oprindelig meddelelse-----
    > Fra: Owen Creger [mailto:OCregerat_private]
    > Sendt: 18. september 2001 21:05
    > Til: 'incidentsat_private'
    > Emne: New worm behavior ?
    >
    >
    > Does anyone know if a reboot will halt this worm?
    > Does it add anything to reload at boot?
    >
    > Owen C. Creger
    > Information Systems Security
    > Creative Solutions Inc.
    > 7322 Newman Blvd.
    > Dexter, MI  48130
    > ph: 734-426-5860 ex. 3787
    > cell: 734-223-6270
    >
    >
    > ------------------------------------------------------------------
    > ----------
    > This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management
    > and tracking system please see: http://aris.securityfocus.com
    >
    >
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Sep 18 2001 - 14:40:31 PDT