I just got this message concerning a new email virus from our computer people at work. Once again, please practice safe computing.
This is the information about the new Vote virus.
This virus arrives with an email message containing the following
information:
Subject: Fwd:Peace BeTweeN AmeriCa And IsLaM !
Body:
Hi
iS iT A waR Against AmeriCa Or IsLaM !?
Let's Vote To Live in Peace!
Attachment: WTC.EXE
When this attachment is run, two VBScript files are dropped,
MixDaLaL.vbs and ZaCker.vbs. MixDaLaL.vbs is saved to the WINDOWS
directory and called immediately. It contains instructions to overwrite
all .HTM and .HTML files on all fixed and network drives with the text:
AmeRiCa ...Few Days WiLL Show You What We Can Do !!! It's Our Turn >>>
ZaCkEr is So Sorry For You .
The hidden file attribute is also set on these files.
ZaCker.vbs is created in the WINDOWS SYSTEM directory and a registry key
is created to run this file at startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run\Norton.Thar=C:\WINDOWS\SYSTEM\ZaCker.vbs
ZaCker.vbs contains instructions to delete all files in the WINDOWS
directory, add a FORMAT C: command to the AUTOEXEC.BAT file, display a
message box containing the text "I promiss We WiLL Rule The World
Again...By The Way,You Are Captured By ZaCker !!!", and exit Windows
The main executable also attempts to delete anti-virus software from
specific directories and to download a trojan from a YAHOO users site,
which is detected as PWS-CT
This is the information about the new Vote virus.
This virus arrives with an email message containing the following
information:
Subject: Fwd:Peace BeTweeN AmeriCa And IsLaM !
Body:
Hi
iS iT A waR Against AmeriCa Or IsLaM !?
Let's Vote To Live in Peace!
Attachment: WTC.EXE
When this attachment is run, two VBScript files are dropped,
MixDaLaL.vbs and ZaCker.vbs. MixDaLaL.vbs is saved to the WINDOWS
directory and called immediately. It contains instructions to overwrite
all .HTM and .HTML files on all fixed and network drives with the text:
AmeRiCa ...Few Days WiLL Show You What We Can Do !!! It's Our Turn >>>
ZaCkEr is So Sorry For You .
The hidden file attribute is also set on these files.
ZaCker.vbs is created in the WINDOWS SYSTEM directory and a registry key
is created to run this file at startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run\Norton.Thar=C:\WINDOWS\SYSTEM\ZaCker.vbs
ZaCker.vbs contains instructions to delete all files in the WINDOWS
directory, add a FORMAT C: command to the AUTOEXEC.BAT file, display a
message box containing the text "I promiss We WiLL Rule The World
Again...By The Way,You Are Captured By ZaCker !!!", and exit Windows
The main executable also attempts to delete anti-virus software from
specific directories and to download a trojan from a YAHOO users site,
which is detected as PWS-CT