Hi Owen, It will drop a hidden file called load.exe to the windows system folder and modify system.ini so this file will run upon reboot. Med venlig hilsen / Best regards Peter Kruse Security- and virusresearch Telia Telecom / Telia Security Group Søren Frichsvej 34C - DK 8230 Åbyhøj Email: pkrat_private - Mobil: +45 2827 9785 > -----Oprindelig meddelelse----- > Fra: Owen Creger [mailto:OCregerat_private] > Sendt: 18. september 2001 21:05 > Til: 'incidentsat_private' > Emne: New worm behavior ? > > > Does anyone know if a reboot will halt this worm? > Does it add anything to reload at boot? > > Owen C. Creger > Information Systems Security > Creative Solutions Inc. > 7322 Newman Blvd. > Dexter, MI 48130 > ph: 734-426-5860 ex. 3787 > cell: 734-223-6270 > > > ------------------------------------------------------------------ > ---------- > This list is provided by the SecurityFocus ARIS analyzer service. > For more information on this free incident handling, management > and tracking system please see: http://aris.securityfocus.com > > ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Tue Sep 18 2001 - 14:40:31 PDT