[Exim] Copier.exe is a Worm

Startseite
Nachricht löschen
Nachricht beantworten
Autor: Astro D. Boy
Datum:  
To: exim-users
Betreff: [Exim] Copier.exe is a Worm
I had gotten that same email, so i did a quick security search on it, this
is what i came up with. Also its new enough that a virus scanner prolly
won't come up with it as a virus.

http://www.symantec.com/avcenter/venc/data/worm.newapt.html

W32.NewApt.Worm was discovered on December 14, 1999 in Italy. This worm
will email itself out when receiving email via Microsoft Outlook or
Netscape Navigator. When activated, the worm will display an error dialog
and modify the registry so the worm is reloaded each time the computer is
restarted. The error message box will appear as:



                        When received by email (and if you do not have an
HTML capable email client), the message body will be: 


he, your lame client cant read HTML, haha.
click attachment to see some stunningly HOT
stuff

                        Otherwise, the text will include a reference to a
website and the following message: 



                              Hypercool Happy Year 2000 funny programs and 
                              animations?.
                              We attached our recent animation from this 
                              site in our mail ! Check it out!


 Attached to the message will be one of the
following file names: g-zilla.exe, cooler3.exe, cooler1.exe,
                        copier.exe, video.exe, pirate.exe, goal1.exe,
hog.exe, party.exe, saddam.exe, monica.exe, boss.exe,
                        farter.exe, cheeseburst.exe, panther.exe,
theobbq.exe, goal.exe, baby.exe, bboy.exe, cupid2.exe,
                        fborfw.exe, casper.exe, irnglant.exe, or
gadget.exe 


The worm will add the following registry key:
HKLM/Software/Microsoft/Windows/CurrentVersion/Run/tpanew

                        To remove the worm from memory, remove the above
registry key and then restart. Delete all infected
                        files.