Subject: | |
From: | |
Reply To: | |
Date: | Thu, 10 May 2001 15:06:48 -0400 |
Content-Type: | text/plain |
Parts/Attachments: |
|
|
Please - do NOT open the message or especially the attachment that is titled
Homepage. It is a new computer virus/worm and is quickly going around the
world (and onto this list).
Here's information from McAfee/Symantec about the Homepage worm and how to
remove it (easy, thankfully)
Homepage VBS worm
The virus comes with a Visual Basic attachment, the subject "Homepage" and
the utterly unconvincing message "Hi! You've got to see this page! It's
really cool ;o)." The consensus is that Homepage probably sprang from the
same worm toolkit as the Anna Kournikova virus.
Large scale e-mailing: <http://www.symantec.com/avcenter/refa.html> Sends
Itself to all recipients in the Outlook
The email message has the following characteristics:
Subject: Homepage
Message:
Hi!
You've got to see this page! It's really cool ;O)
Attachment: Homepage.HTML.vbs
Prior to mailing itself out, the worm searches for email messages with the
Subject of Homepage; if found, it deletes them. After mailing, the worm
creates the registry key
HKEY_CURRENT_USER\Software\An\mailed
and sets it equal to "1". The presence of this registry key prevents the
worm from running the email routine more than once.
The worm then randomly selects one of four pornographic Web pages and opens
it.
Removal instructions: <http://www.symantec.com/avcenter/refa.html>
To remove this worm:
1. Run LiveUpdate to make sure that you have the most recent virus
definitions.
2. Start Norton AntiVirus (NAV), and run a full system scan, making
sure that NAV is set to scan all files.
3. Delete any files detected as [log in to unmask]
|
|
|