CLICK4HP Archives

Health Promotion on the Internet

CLICK4HP@YORKU.CA

Options: Use Forum View

Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
"Stirling, Alison" <[log in to unmask]>
Reply To:
Health Promotion on the Internet <[log in to unmask]>
Date:
Thu, 10 May 2001 15:06:48 -0400
Content-Type:
text/plain
Parts/Attachments:
text/plain (45 lines)
Please - do NOT open the message or especially the attachment that is titled
Homepage.  It is a new computer virus/worm and is quickly going around the
world (and onto this list).

Here's information from McAfee/Symantec about the Homepage worm and how to
remove it (easy, thankfully)
Homepage VBS worm


The virus comes with a Visual Basic attachment, the subject "Homepage" and
the utterly unconvincing message "Hi! You've got to see this page! It's
really cool ;o)." The consensus is that Homepage probably sprang from the
same worm toolkit as the Anna Kournikova virus.

Large scale e-mailing: <http://www.symantec.com/avcenter/refa.html> Sends
Itself to all recipients in the Outlook
 The email message has the following characteristics:
Subject: Homepage
Message:
Hi!

You've got to see this page! It's really cool ;O)

Attachment: Homepage.HTML.vbs

Prior to mailing itself out, the worm searches for email messages with the
Subject of Homepage; if found, it deletes them. After mailing, the worm
creates the registry key

HKEY_CURRENT_USER\Software\An\mailed

and sets it equal to "1". The presence of this registry key prevents the
worm from running the email routine more than once.

The worm then randomly selects one of four pornographic Web pages and opens
it.
Removal instructions: <http://www.symantec.com/avcenter/refa.html>

To remove this worm:
        1. Run LiveUpdate to make sure that you have the most recent virus
definitions.
        2. Start Norton AntiVirus (NAV), and run a full system scan, making
sure that NAV is set to scan all files.
        3. Delete any files detected as [log in to unmask]

ATOM RSS1 RSS2