Security Incidents mailing list archives

SV: New worm behavior ?


From: "Peter Kruse" <peter.kruse () it dk>
Date: Tue, 18 Sep 2001 21:28:30 +0200

Hi Owen,

It will drop a hidden file called load.exe to the windows system folder and
modify system.ini so this file will run upon reboot.

Med venlig hilsen / Best regards

Peter Kruse
Security- and virusresearch
Telia Telecom / Telia Security Group
Søren Frichsvej 34C - DK 8230 Åbyhøj
Email: pkr () telia dk - Mobil: +45 2827 9785


-----Oprindelig meddelelse-----
Fra: Owen Creger [mailto:OCreger () CreativeSolutions com]
Sendt: 18. september 2001 21:05
Til: 'incidents () securityfocus com'
Emne: New worm behavior ?


Does anyone know if a reboot will halt this worm?
Does it add anything to reload at boot?

Owen C. Creger
Information Systems Security
Creative Solutions Inc.
7322 Newman Blvd.
Dexter, MI  48130
ph: 734-426-5860 ex. 3787
cell: 734-223-6270


------------------------------------------------------------------
----------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com




----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: