Windoze uninfection details thanks to AVP Australia...

=====
1.  Virus creates a registry key under:
     HKEY_Current_User\Software\OnTheFly

2.  Text of the above registry key is: "Worm made with Vbswg 1.50b".

3.  After sending emails to all users in Outlook address list, the value
     of this registry key is set to "1".  Afterwards, the virus will not send
     any more emails.

4.  Saves virus to C:\%WindowsDirectory%\AnnaKournikova.jpg.vbs

5.  Creates email message and sends to all users on available address
     lists (creates individual emails, not a group send).  Attaches the file
     saved in step 4 above, then deletes
     C:\%WindowsDirectory%\AnnaKournikova.jpg.vbs
     after sending all emails.

6.  On January 26, it opens a browser window with the website
     www.dynabyte.nl



To clean the virus:

1.  Search and destroy all emails with the subject line:
     " Here you have, ;o) "

2.  Delete the registry key mentioned in item 1 above.

3.  Search and destroy all copies of AnnaKournikova.jpg.vbs
=====


-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
More Info: http://slug.org.au/lists/listinfo/slug

Reply via email to