Security Incidents mailing list archives
SV: New worm behavior ?
From: "Peter Kruse" <peter.kruse () it dk>
Date: Tue, 18 Sep 2001 21:28:30 +0200
Hi Owen, It will drop a hidden file called load.exe to the windows system folder and modify system.ini so this file will run upon reboot. Med venlig hilsen / Best regards Peter Kruse Security- and virusresearch Telia Telecom / Telia Security Group Søren Frichsvej 34C - DK 8230 Åbyhøj Email: pkr () telia dk - Mobil: +45 2827 9785
-----Oprindelig meddelelse----- Fra: Owen Creger [mailto:OCreger () CreativeSolutions com] Sendt: 18. september 2001 21:05 Til: 'incidents () securityfocus com' Emne: New worm behavior ? Does anyone know if a reboot will halt this worm? Does it add anything to reload at boot? Owen C. Creger Information Systems Security Creative Solutions Inc. 7322 Newman Blvd. Dexter, MI 48130 ph: 734-426-5860 ex. 3787 cell: 734-223-6270 ------------------------------------------------------------------ ---------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- New worm behavior ? Owen Creger (Sep 18)
- SV: New worm behavior ? Peter Kruse (Sep 18)
- <Possible follow-ups>
- New worm behavior ? Owen Creger (Sep 18)